---
name: Docker Buildx
slug: docker-buildx-releases
type: github
source_url: https://github.com/docker/buildx
organization: Docker
organization_slug: docker
total_releases: 80
latest_version: v0.38.0
latest_date: 2026-10-07
last_updated: 2026-10-08
tracking_since: 2019-04-25
canonical: https://releases.sh/docker/docker-buildx-releases
organization_url: https://releases.sh/docker
---

<Summary type="rolling" window-days="90" release-count="9">
Buildx shipped two minor versions with a clear focus on policy-driven builds and improved credential handling across distributed operations. The v0.31 cycle introduced experimental Rego-based source policy enforcement, which graduated from experimental to generally available by v0.33.0-rc1, alongside a new `policy test` command and `policy eval` enhancements like stdin input and platform-specific evaluation. Parallel work hardened imagetools auth to match the build command's scoped credentials and fallback logic, and added `--timeout` flags across commands for remote builder reliability. v0.33.0-rc1 also expanded bake with time-handling builtins (`formattimestamp`, `unixtimestampparse`) and let imagetools work directly with OCI layout paths alongside registry references.
</Summary>

<Summary type="monthly" period="February 2026" release-count="2">
Docker Buildx focused on policy enforcement and authentication consistency in February. The rc1 release expanded Rego policy validation to remote sources and unified imagetools auth with build command libraries, adding scoped credential support and Docker Hardened Image registry fallbacks. Rc2 followed with refinements to policy evaluation for recursive provenance materials and filesystem reference lifecycle handling, plus normalized default policy filename resolution from environment configuration.
</Summary>

<Release version="v0.38.0" date="October 7, 2026" published="2026-10-07T23:39:15.000Z" url="https://github.com/docker/buildx/releases/tag/v0.38.0">
buildx 0.38.0

Welcome to the v0.38.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Sebastiaan van Stijn
* Akihiro Suda
* Tomas Perez Molina
* Dean Chen
* MohammadHasan Akbari
* Nicolas De Loof
* Ricardo Branco
* Ryan Bonnell

### Notable Changes

- Bake now supports configuring job execution modes and parallelization limits with `--jobs/-j` flag. New execution modes include `defer-error` to delay cancellation of failed jobs and `defer-output` to wait for all jobs to complete before exporting results. #4044
- New experiment command `docker buildx replay build` allows rebuilding historical builds based on recorded provenance of a distributed artifact or Docker image. This subcommand is expected to be updated with additional features and improvements in future releases. #4122 #3818
- HTTP hosts passed to build policies are now normalized to assist writing accurate policy rules. #4068
- Bake `--set` overrides have now been updated to use singular keys for better consistency and clarity. #4089
- Bake `--set` overrides now support clearing array values with an empty parameter. #4107
- Git advice output can now be controlled with `BUILDKIT_GIT_ADVICE` and `BUILDX_BAKE_GIT_ADVICE`. #4103
- Compose support has been updated to v2.16.1 #4118
- Zstd compressed archives can now be passed as build context. #4104
- Update Kubernetes driver to handle AppArmor profile correctly. #4083
- Improve Kubernetes driver dial retry backoff logic. #4039
- Fix possible issues with builder feature detection using stale cached data. #4085 #4082
- Fix possible panic from result image loading and progress race. #4064
- Fix possible stale node status printed by `inspect --bootstrap` command. #4048
- Fix confusing error messages when encountering undefined variables in bake targets. #4086
- Fix possible incorrect parsing of bake target overrides. #4088
- Fix possible build error with Kubernetes driver and linked targets. #4073
- Fix issue with Kubernetes driver waiting for connection readiness. #4077


### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                                  v1.43.8 -> v1.47.0
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.32.39 -> v1.33.4
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.19.38 -> v1.20.4
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.39 -> v1.20.0
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.39 -> v1.5.3
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.39 -> v2.8.3
* **github.com/aws/aws-sdk-go-v2/internal/v4a**                                     v1.4.40 -> v1.5.3
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.18 -> v1.13.19
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.39 -> v1.14.3
* **github.com/aws/aws-sdk-go-v2/service/signin**                                   v1.5.8 -> v1.10.0
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.33.8 -> v1.38.0
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.38.8 -> v1.43.0
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.45.8 -> v1.50.0
* **github.com/aws/smithy-go**                                                      v1.27.10 -> v1.28.2
* **github.com/clipperhouse/uax29/v2**                                              v2.2.0 -> v2.6.0
* **github.com/compose-spec/compose-go/v2**                                         v2.14.0 -> v2.16.1
* **github.com/containerd/containerd/api**                                          v1.11.1 -> v1.12.0
* **github.com/containerd/containerd/v2**                                           v2.3.6 -> v2.4.1
* **github.com/containerd/log/otel**                                                v0.1.0 **_new_**
* **github.com/containerd/ttrpc**                                                   v1.2.9 -> v1.2.10
* **github.com/decred/dcrd/dcrec/secp256k1/v4**                                     v4.4.0 -> v4.4.1
* **github.com/docker/cli**                                                         v29.7.2 -> v29.8.2
* **github.com/docker/docker-credential-helpers**                                   v0.9.8 -> v0.9.9
* **github.com/docker/go-connections**                                              v0.7.0 -> v0.8.1
* **github.com/fvbommel/sortorder**                                                 v1.1.0 -> v1.2.0
* **github.com/fxamacker/cbor/v2**                                                  v2.9.0 -> v2.9.4
* **github.com/go-openapi/analysis**                                                v0.25.2 -> v0.25.5
* **github.com/go-openapi/jsonpointer**                                             v0.23.1 -> v1.0.0
* **github.com/go-openapi/jsonreference**                                           v0.21.6 -> v1.0.0
* **github.com/go-openapi/loads**                                                   v0.24.0 -> v0.25.0
* **github.com/go-openapi/runtime**                                                 v0.32.4 -> v0.33.0
* **github.com/go-openapi/spec**                                                    v0.22.6 -> v0.22.9
* **github.com/go-openapi/strfmt**                                                  v0.26.4 -> v0.27.0
* **github.com/go-openapi/swag**                                                    v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/cmdutils**                                           v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/conv**                                               v0.27.0 -> v0.28.0
* **github.com/go-openapi/swag/fileutils**                                          v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/jsonutils**                                          v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/loading**                                            v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/mangling**                                           v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/netutils**                                           v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/pools**                                              v0.28.0 **_new_**
* **github.com/go-openapi/swag/stringutils**                                        v0.26.1 -> v0.28.0
* **github.com/go-openapi/swag/typeutils**                                          v0.27.0 -> v0.28.0
* **github.com/go-openapi/swag/yamlutils**                                          v0.26.1 -> v0.28.0
* **github.com/go-openapi/validate**                                                v0.26.0 -> v0.26.1
* **github.com/goccy/go-json**                                                      v0.10.5 -> v0.10.6
* **github.com/gofrs/flock**                                                        v0.13.0 -> v0.13.1
* **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.29.0 -> v2.30.0
* **github.com/klauspost/compress**                                                 v1.19.2 -> v1.20.1
* **github.com/lestrrat-go/dsig**                                                   v1.0.0 -> v1.2.1
* **github.com/lestrrat-go/httprc/v3**                                              v3.0.2 -> v3.0.5
* **github.com/lestrrat-go/jwx/v3**                                                 v3.0.13 -> v3.1.1
* **github.com/mattn/go-runewidth**                                                 v0.0.23 -> v0.0.29
* **github.com/mattn/go-shellwords**                                                v1.0.12 -> v1.0.13
* **github.com/moby/buildkit**                                                      v0.33.1 -> v0.34.0
* **github.com/moby/moby/api**                                                      v1.55.0 -> v1.56.0
* **github.com/moby/moby/client**                                                   v0.5.0 -> v0.6.0
* **github.com/moby/policy-helpers**                                                dd6c5499c491 -> bd98f4747414
* **github.com/open-policy-agent/opa**                                              v1.14.1 -> v1.19.0
* **github.com/package-url/packageurl-go**                                          v0.1.1 -> v0.1.7
* **github.com/santhosh-tekuri/jsonschema/v6**                                      v6.0.1 -> v6.0.3
* **github.com/valyala/fastjson**                                                   v1.6.7 -> v1.6.10
* **github.com/vektah/gqlparser/v2**                                                v2.5.32 -> v2.5.36
* **go.etcd.io/bbolt**                                                              v1.5.0 **_new_**
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.70.0 -> v0.71.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.70.0 -> v0.71.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.70.0 -> v0.71.0
* **go.opentelemetry.io/otel**                                                      v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/exporters/stdout/stdouttrace**                         v1.44.0 -> v1.46.0
* **go.opentelemetry.io/otel/metric**                                               v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/sdk**                                                  v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/sdk/metric**                                           v1.45.0 -> v1.46.0
* **go.opentelemetry.io/otel/trace**                                                v1.45.0 -> v1.46.0
* **google.golang.org/genproto/googleapis/api**                                     6ac0973c030d -> da73d73af1c5
* **google.golang.org/genproto/googleapis/rpc**                                     6ac0973c030d -> da73d73af1c5
* **google.golang.org/grpc**                                                        v1.83.2 -> v1.84.0
* **k8s.io/api**                                                                    v0.36.3 -> v0.37.0
* **k8s.io/apimachinery**                                                           v0.36.3 -> v0.37.0
* **k8s.io/client-go**                                                              v0.36.3 -> v0.37.0
* **k8s.io/kube-openapi**                                                           5883c5ee87b9 -> d427ff9ee9ad
* **k8s.io/streaming**                                                              v0.36.3 -> v0.37.0
* **k8s.io/utils**                                                                  28399d86e0b5 -> be93311217bd
* **sigs.k8s.io/structured-merge-diff/v6**                                          v6.3.3 -> v6.4.2

Previous release can be found at [v0.37.2](https://github.com/docker/buildx/releases/tag/v0.37.2)


</Release>

<Release version="v0.37.2" date="September 30, 2026" published="2026-09-30T17:55:10.000Z" url="https://github.com/docker/buildx/releases/tag/v0.37.2">
Welcome to the v0.37.2 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Sebastiaan van Stijn
* Tõnis Tiigi

### Notable Changes

- Bake with `--progress=rawjson` now rejects ungranted entitlements instead of skipping the consent check. Grant the requested privileges explicitly with `--allow`. https://github.com/docker/buildx/security/advisories/GHSA-gwr2-q96m-6682
- Bake now requires `fs.read` approval for secret files selected by an implicit `id` fallback and for local OCI layout named contexts. https://github.com/docker/buildx/security/advisories/GHSA-p54p-jq4x-rc28

### Dependency Changes

* **github.com/containerd/containerd/v2**  v2.3.4 -> v2.3.6
* **github.com/moby/buildkit**             v0.33.0 -> v0.33.1
* **golang.org/x/crypto**                  v0.55.0 -> v0.56.0

Previous release can be found at [v0.37.1](https://github.com/docker/buildx/releases/tag/v0.37.1)

</Release>

<Release version="v0.37.1" date="September 11, 2026" published="2026-09-11T15:35:46.000Z" url="https://github.com/docker/buildx/releases/tag/v0.37.1">
Welcome to the v0.37.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tomas Perez Molina
* Tõnis Tiigi

### Notable Changes

- Fix failed multi-node image pushes leaving the requested tag pointing to a partial image. #4058
- Fix newly started container builders not getting a full readiness timeout before first use. #4050
- Fix builder removal cleanup being tied to the status timeout. #4072
- Fix linked Bake targets using the Kubernetes driver losing shared clients before the build completes. #4073

### Dependency Changes

This release has no dependency changes

Previous release can be found at [v0.37.0](https://github.com/docker/buildx/releases/tag/v0.37.0)

</Release>

<Release version="v0.37.0" date="September 2, 2026" published="2026-09-02T17:20:14.000Z" url="https://github.com/docker/buildx/releases/tag/v0.37.0">
Welcome to the v0.37.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Sebastiaan van Stijn
* Alberto Garcia Hierro
* Brad Davidson
* Guilhem Charles
* Guillaume Lours

### Notable Changes

- Buildx now supports `cloud` driver builder instances to run builds with [Docker Build Cloud](https://docs.docker.com/build-cloud/usage/) service. No custom version of Buildx binary is needed anymore. #4017
- Newly started container builders now wait for BuildKit readiness before first use. #4027
- Policy evaluation now uses Docker CLI registry auth for image metadata. #4046
- Several consistency issues with handling Windows platform identifiers with OS version have been fixed. #4035 #4034 #4008
- Using the Kubernetes driver now skips terminating pods when choosing a pod. #3997
- Avoid creating temporary files on the host to send builder configuration to remote containers. #3996
- Fix issue where Bake builds could sometimes drop sending build secrets when using linked targets. #4014
- Fix cases where empty source policy sessions were created for some builds, possibly causing confusing progress output. #4028

### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                                  v1.43.0 -> v1.43.8
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.32.31 -> v1.32.39
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.19.30 -> v1.19.38
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.31 -> v1.18.39
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.31 -> v1.4.39
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.31 -> v2.7.39
* **github.com/aws/aws-sdk-go-v2/internal/v4a**                                     v1.4.32 -> v1.4.40
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.13 -> v1.13.18
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.31 -> v1.13.39
* **github.com/aws/aws-sdk-go-v2/service/signin**                                   v1.5.0 -> v1.5.8
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.33.0 -> v1.33.8
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.38.0 -> v1.38.8
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.45.0 -> v1.45.8
* **github.com/aws/smithy-go**                                                      v1.27.4 -> v1.27.10
* **github.com/compose-spec/compose-go/v2**                                         v2.13.0 -> v2.14.0
* **github.com/containerd/containerd/v2**                                           v2.3.3 -> v2.3.4
* **github.com/containerd/platforms**                                               v1.0.0-rc.4 -> v1.0.0-rc.5
* **github.com/docker/cli**                                                         v29.6.2 -> v29.7.2
* **github.com/felixge/httpsnoop**                                                  v1.0.4 -> v1.1.0
* **github.com/go-logr/logr**                                                       v1.4.3 -> v1.4.4
* **github.com/klauspost/compress**                                                 v1.19.1 -> v1.19.2
* **github.com/moby/buildkit**                                                      v0.32.2 -> v0.33.0
* **github.com/moby/go-archive**                                                    v0.2.1 -> v0.2.0
* **github.com/moby/policy-helpers**                                                856be88baec4 -> dd6c5499c491
* **github.com/pelletier/go-toml/v2**                                               v2.3.1 -> v2.4.3
* **github.com/sirupsen/logrus**                                                    v1.9.4 -> v1.10.2
* **github.com/stretchr/testify**                                                   v1.11.1 -> v1.12.1
* **github.com/tonistiigi/fsutil**                                                  6d9dc2ebad62 -> 83cac42c1c52
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.69.0 -> v0.70.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.69.0 -> v0.70.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.69.0 -> v0.70.0
* **go.opentelemetry.io/otel**                                                      v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/metric**                                               v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/sdk**                                                  v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/sdk/metric**                                           v1.44.0 -> v1.45.0
* **go.opentelemetry.io/otel/trace**                                                v1.44.0 -> v1.45.0
* **go.opentelemetry.io/proto/otlp**                                                v1.10.0 -> v1.11.0
* **go.yaml.in/yaml/v3**                                                            v3.0.4 -> v3.0.5
* **golang.org/x/crypto**                                                           v0.54.0 -> v0.55.0
* **golang.org/x/mod**                                                              v0.38.0 -> v0.40.0
* **golang.org/x/net**                                                              v0.57.0 -> v0.58.0
* **golang.org/x/text**                                                             v0.40.0 -> v0.41.0
* **golang.org/x/tools**                                                            v0.47.0 -> v0.49.0
* **google.golang.org/genproto/googleapis/api**                                     3dc84a4a5aaa -> 6ac0973c030d
* **google.golang.org/genproto/googleapis/rpc**                                     3dc84a4a5aaa -> 6ac0973c030d
* **google.golang.org/grpc**                                                        v1.82.1 -> v1.83.2
* **google.golang.org/grpc/cmd/protoc-gen-go-grpc**                                 v1.6.1 -> v1.6.2
* **google.golang.org/protobuf**                                                    f2248ac996af -> v1.36.12
* **k8s.io/api**                                                                    v0.36.0 -> v0.36.3
* **k8s.io/apimachinery**                                                           v0.36.0 -> v0.36.3
* **k8s.io/client-go**                                                              v0.36.0 -> v0.36.3
* **sigs.k8s.io/structured-merge-diff/v6**                                          v6.3.2 -> v6.3.3

Previous release can be found at [v0.36.1](https://github.com/docker/buildx/releases/tag/v0.36.1)

</Release>

<Release version="v0.36.1" date="August 4, 2026" published="2026-08-04T15:50:13.000Z" url="https://github.com/docker/buildx/releases/tag/v0.36.1">
Welcome to the v0.36.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax

### Notable Changes

- Add `BUILDX_NO_DEFAULT_OCI_ARTIFACT` as alternative to `oci-artifact=false` when users have not set it explicitly. #3991

### Dependency Changes

* **github.com/moby/buildkit**  v0.32.0 -> v0.32.2

Previous release can be found at [v0.36.0](https://github.com/docker/buildx/releases/tag/v0.36.0)

</Release>

<Release version="v0.36.0" date="July 29, 2026" published="2026-07-29T20:27:12.000Z" url="https://github.com/docker/buildx/releases/tag/v0.36.0">
Welcome to the v0.36.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Sebastiaan van Stijn
* MohammadHasan Akbari
* Matt Van Horn
* amarkdotdev
* Areeb Ahmed
* Guillaume Lours
* Paweł Gronowski
* Pierre Gimalac
* s3onghyun

### Notables Changes

- Default source policy can now validate the authenticity of BuildKit release images when creating docker-container builder with `docker buildx create` command. #3961
- Bake command now supports overriding declared secret sources. #3962
- Broken builder instances are now correctly handled on removal. #3934
- Bake now supports resolving files relative to the bake file location instead of the current working directory with `BUILDX_BAKE_FILE_RELATIVE_PATHS=true`. #3935
- Source policies now support new `array.flatten` builtin and OPA template strings. #3913
- Imagetools commands now do extra validation of the descriptor inputs from files. #3933
- Windows release binaries are now code-signed, matching the signing coverage already provided for macOS release artifacts. #3978
- Compose compatibility has been updated to v2.13.0. #3929
- Fix source policy support on Windows when loading local files inside policy. #3944
- Fix Kubernetes driver random load balancer support. #3861
- Fix Kubernetes driver builds hanging indefinitely when the remote exec stream ends. #3966
- Fix iidfile for containerd-backed Docker driver. #3952
- Fix authority pseudo-header when using remote driver. #3928
- Fix possible FD leak when using source policies. #3943

### Dependency Changes

* **github.com/Microsoft/go-winio**                                  v0.6.2 -> ad3df93bed29
* **github.com/ProtonMail/go-crypto**                                v1.3.0 -> v1.4.1
* **github.com/aws/aws-sdk-go-v2**                                   v1.42.0 -> v1.43.0
* **github.com/aws/aws-sdk-go-v2/config**                            v1.32.24 -> v1.32.31
* **github.com/aws/aws-sdk-go-v2/credentials**                       v1.19.23 -> v1.19.30
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                  v1.18.29 -> v1.18.31
* **github.com/aws/aws-sdk-go-v2/internal/configsources**            v1.4.29 -> v1.4.31
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**             v2.7.29 -> v2.7.31
* **github.com/aws/aws-sdk-go-v2/internal/v4a**                      v1.4.30 -> v1.4.32
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**  v1.13.12 -> v1.13.13
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**    v1.13.29 -> v1.13.31
* **github.com/aws/aws-sdk-go-v2/service/signin**                    v1.1.5 -> v1.5.0
* **github.com/aws/aws-sdk-go-v2/service/sso**                       v1.31.3 -> v1.33.0
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                   v1.36.6 -> v1.38.0
* **github.com/aws/aws-sdk-go-v2/service/sts**                       v1.43.3 -> v1.45.0
* **github.com/aws/smithy-go**                                       v1.27.2 -> v1.27.4
* **github.com/compose-spec/compose-go/v2**                          v2.10.2 -> v2.13.0
* **github.com/containerd/containerd/api**                           v1.10.0 -> v1.11.1
* **github.com/containerd/containerd/v2**                            v2.2.4 -> v2.3.3
* **github.com/containerd/ttrpc**                                    v1.2.8 -> v1.2.9
* **github.com/docker/cli**                                          v29.5.3 -> v29.6.2
* **github.com/go-openapi/errors**                                   v0.22.7 -> v0.22.8
* **github.com/go-openapi/loads**                                    v0.23.3 -> v0.24.0
* **github.com/go-openapi/runtime**                                  v0.32.3 -> v0.32.4
* **github.com/go-openapi/spec**                                     v0.22.5 -> v0.22.6
* **github.com/go-openapi/strfmt**                                   v0.26.3 -> v0.26.4
* **github.com/go-openapi/swag**                                     v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/cmdutils**                            v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/conv**                                v0.26.0 -> v0.27.0
* **github.com/go-openapi/swag/fileutils**                           v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/jsonname**                            v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/jsonutils**                           v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/loading**                             v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/mangling**                            v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/netutils**                            v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/stringutils**                         v0.26.0 -> v0.26.1
* **github.com/go-openapi/swag/typeutils**                           v0.26.0 -> v0.27.0
* **github.com/go-openapi/swag/yamlutils**                           v0.26.0 -> v0.26.1
* **github.com/go-openapi/validate**                                 v0.25.3 -> v0.26.0
* **github.com/google/go-containerregistry**                         v0.21.6 -> v0.21.7
* **github.com/klauspost/compress**                                  v1.18.6 -> v1.19.1
* **github.com/lestrrat-go/httprc/v3**                               v3.0.1 -> v3.0.2
* **github.com/lestrrat-go/jwx/v3**                                  v3.0.11 -> v3.0.13
* **github.com/moby/buildkit**                                       v0.31.0 -> v0.32.0
* **github.com/moby/go-archive**                                     v0.2.0 -> v0.2.1
* **github.com/moby/moby/api**                                       v1.54.2 -> v1.55.0
* **github.com/moby/moby/client**                                    v0.4.1 -> v0.5.0
* **github.com/moby/policy-helpers**                                 d5411a945cfc -> 856be88baec4
* **github.com/moby/sys/user**                                       v0.4.0 -> v0.4.1
* **github.com/open-policy-agent/opa**                               v1.10.1 -> v1.14.1
* **github.com/segmentio/asm**                                       v1.2.0 -> v1.2.1
* **github.com/sigstore/rekor**                                      v1.5.2 -> v1.5.3
* **github.com/sigstore/rekor-tiles/v2**                             5d098a2b6443 -> v2.3.0
* **github.com/sigstore/sigstore-go**                                v1.2.1 -> v1.2.2
* **github.com/tonistiigi/fsutil**                                   0257b3308df4 -> 6d9dc2ebad62
* **github.com/valyala/fastjson**                                    v1.6.4 -> v1.6.7
* **github.com/vektah/gqlparser/v2**                                 v2.5.30 -> v2.5.32
* **golang.org/x/crypto**                                            v0.52.0 -> v0.54.0
* **golang.org/x/mod**                                               v0.36.0 -> v0.38.0
* **golang.org/x/net**                                               v0.55.0 -> v0.57.0
* **golang.org/x/sync**                                              v0.20.0 -> v0.22.0
* **golang.org/x/sys**                                               v0.45.0 -> v0.47.0
* **golang.org/x/term**                                              v0.43.0 -> v0.45.0
* **golang.org/x/text**                                              v0.37.0 -> v0.40.0
* **golang.org/x/tools**                                             v0.45.0 -> v0.47.0
* **google.golang.org/grpc**                                         v1.81.1 -> v1.82.1
* **google.golang.org/protobuf**                                     v1.36.11 -> f2248ac996af
* **k8s.io/api**                                                     v0.35.4 -> v0.36.0
* **k8s.io/apimachinery**                                            v0.35.4 -> v0.36.0
* **k8s.io/client-go**                                               v0.35.4 -> v0.36.0
* **k8s.io/kube-openapi**                                            589584f1c912 -> 5883c5ee87b9
* **k8s.io/streaming**                                               v0.36.0 **_new_**
* **k8s.io/utils**                                                   bc988d571ff4 -> 28399d86e0b5
* **sigs.k8s.io/structured-merge-diff/v6**                           v6.3.0 -> v6.3.2

Previous release can be found at [v0.35.0](https://github.com/docker/buildx/releases/tag/v0.35.0)
</Release>

<Release version="v0.35.0" date="June 17, 2026" published="2026-06-17T23:18:28.000Z" url="https://github.com/docker/buildx/releases/tag/v0.35.0">
buildx 0.35.0

Welcome to the v0.35.0 release of buildx!

Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Sebastiaan van Stijn
* Areeb Ahmed
* Jiří Moravčík
* Sopho Merkviladze
* Akihiro Suda
* Jonathan A. Sternberg

### Notable Changes

- Local output now supports a `mode=delete` attribute for build and bake commands. This mode replaces the destination directory with the build result instead of merging it. Similar to the `--delete` flag in rsync. For safety, this mode is only allowed if the destination directory is a subdirectory of the working directory. To export to other destinations, `--allow=buildx.local.delete` needs to be provided or the action confirmed by the user in the TUI. When exporting multi-platform results, this mode requires BuildKit v0.31.0+. #3883
- Source policies now support the new exec proxy feature of BuildKit v0.31.0+ that captures the network traffic of your build steps. To opt in to network proxy, your Dockerfile.rego source policy needs to return `caps: { "exec.proxy": true }` in the evaluation decision. After opting in, you can control what network requests are allowed to be made by the run steps with policy rules for regular `input.http` sources, similar to how this was done for direct HTTP build sources before. You can also opt in your whole builder with `--buildkitd-flags '--proxy-network'` in `buildx create`. #3895
- Resource limits can now be set for CPU and memory using the `--resource` flag in `build` and the `resource` key in `bake` commands. This feature requires BuildKit v0.31.0+ and Dockerfile v0.25.0+. #3876 #3900
- Fix possible "closed channel" panic. #3886

### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                                  v1.41.7 -> v1.42.0
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.32.17 -> v1.32.24
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.19.16 -> v1.19.23
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.23 -> v1.18.29
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.23 -> v1.4.29
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.23 -> v2.7.29
* **github.com/aws/aws-sdk-go-v2/internal/v4a**                                     v1.4.24 -> v1.4.30
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.9 -> v1.13.12
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.23 -> v1.13.29
* **github.com/aws/aws-sdk-go-v2/service/signin**                                   v1.0.11 -> v1.1.5
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.30.17 -> v1.31.3
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.35.21 -> v1.36.6
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.42.1 -> v1.43.3
* **github.com/aws/smithy-go**                                                      v1.25.1 -> v1.27.2
* **github.com/containerd/containerd/v2**                                           v2.2.3 -> v2.2.4
* **github.com/containerd/continuity**                                              v0.4.5 -> v0.5.0
* **github.com/containerd/platforms**                                               v1.0.0-rc.2 -> v1.0.0-rc.4
* **github.com/containerd/typeurl/v2**                                              v2.2.3 -> v2.3.0
* **github.com/docker/cli**                                                         v29.4.3 -> v29.5.3
* **github.com/docker/distribution**                                                v2.8.3 **_new_**
* **github.com/docker/docker-credential-helpers**                                   v0.9.5 -> v0.9.8
* **github.com/go-openapi/analysis**                                                v0.24.3 -> v0.25.2
* **github.com/go-openapi/jsonpointer**                                             v0.22.5 -> v0.23.1
* **github.com/go-openapi/jsonreference**                                           v0.21.5 -> v0.21.6
* **github.com/go-openapi/runtime**                                                 v0.29.3 -> v0.32.3
* **github.com/go-openapi/runtime/server-middleware**                               v0.30.0 **_new_**
* **github.com/go-openapi/spec**                                                    v0.22.4 -> v0.22.5
* **github.com/go-openapi/strfmt**                                                  v0.26.1 -> v0.26.3
* **github.com/go-openapi/swag**                                                    v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/cmdutils**                                           v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/conv**                                               v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/fileutils**                                          v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/jsonname**                                           v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/jsonutils**                                          v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/loading**                                            v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/mangling**                                           v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/netutils**                                           v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/stringutils**                                        v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/typeutils**                                          v0.25.5 -> v0.26.0
* **github.com/go-openapi/swag/yamlutils**                                          v0.25.5 -> v0.26.0
* **github.com/go-openapi/validate**                                                v0.25.2 -> v0.25.3
* **github.com/google/certificate-transparency-go**                                 v1.3.2 -> v1.3.3
* **github.com/google/go-containerregistry**                                        v0.20.7 -> v0.21.6
* **github.com/gorilla/mux**                                                        v1.8.1 **_new_**
* **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.28.0 -> v2.29.0
* **github.com/in-toto/attestation**                                                v1.1.2 -> v1.2.0
* **github.com/moby/buildkit**                                                      v0.30.0 -> v0.31.0
* **github.com/moby/policy-helpers**                                                a39d60132186 -> d5411a945cfc
* **github.com/moby/sys/sequential**                                                v0.6.0 -> v0.7.0
* **github.com/pelletier/go-toml/v2**                                               v2.2.4 -> v2.3.1
* **github.com/prometheus/common**                                                  v0.66.1 -> v0.67.5
* **github.com/prometheus/procfs**                                                  v0.17.0 -> v0.20.1
* **github.com/secure-systems-lab/go-securesystemslib**                             v0.10.0 -> v0.11.0
* **github.com/sigstore/protobuf-specs**                                            v0.5.0 -> v0.5.1
* **github.com/sigstore/rekor**                                                     v1.5.0 -> v1.5.2
* **github.com/sigstore/rekor-tiles/v2**                                            v2.0.1 -> 5d098a2b6443
* **github.com/sigstore/sigstore**                                                  v1.10.5 -> v1.10.8
* **github.com/sigstore/sigstore-go**                                               v1.1.4 -> v1.2.1
* **github.com/sigstore/timestamp-authority/v2**                                    v2.0.6 -> v2.1.2
* **github.com/theupdateframework/go-tuf/v2**                                       v2.4.1 -> v2.4.2
* **github.com/tonistiigi/fsutil**                                                  a2aa163d723f -> 0257b3308df4
* **github.com/transparency-dev/formats**                                           404c0d5b696c -> v0.1.1
* **github.com/youmark/pkcs8**                                                      a2c0da244d78 **_new_**
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.68.0 -> v0.69.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.68.0 -> v0.69.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.68.0 -> v0.69.0
* **go.opentelemetry.io/otel**                                                      v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/exporters/stdout/stdouttrace**                         v1.42.0 -> v1.44.0
* **go.opentelemetry.io/otel/metric**                                               v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/sdk**                                                  v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/sdk/metric**                                           v1.43.0 -> v1.44.0
* **go.opentelemetry.io/otel/trace**                                                v1.43.0 -> v1.44.0
* **go.yaml.in/yaml/v2**                                                            v2.4.3 -> v2.4.4
* **google.golang.org/genproto/googleapis/api**                                     6f92a3bedf2d -> 3dc84a4a5aaa
* **google.golang.org/genproto/googleapis/rpc**                                     6f92a3bedf2d -> 3dc84a4a5aaa
* **google.golang.org/grpc**                                                        v1.80.0 -> v1.81.1
* **google.golang.org/grpc/cmd/protoc-gen-go-grpc**                                 v1.5.1 -> v1.6.1
* **k8s.io/klog/v2**                                                                v2.130.1 -> v2.140.0

Previous release can be found at [v0.34.1](https://github.com/docker/buildx/releases/tag/v0.34.1)

</Release>

<Release version="v0.34.1" date="May 19, 2026" published="2026-05-19T18:39:02.000Z" url="https://github.com/docker/buildx/releases/tag/v0.34.1">
buildx 0.34.1

Welcome to the v0.34.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Jonathan A. Sternberg
* Tõnis Tiigi

### Notable Changes

- Fix regression in Bake command when building from Compose files with empty array value #3849 #3852
- Fix possible panic in Kubernetes driver when using statefulset #3853

### Dependency Changes

This release has no dependency changes

Previous release can be found at [v0.34.0](https://github.com/docker/buildx/releases/tag/v0.34.0)

</Release>

<Release version="v0.34.0" date="May 13, 2026" published="2026-05-13T14:51:35.000Z" url="https://github.com/docker/buildx/releases/tag/v0.34.0">
Welcome to the v0.34.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Sebastiaan van Stijn
* Jonathan A. Sternberg
* Guillaume Lours
* Hervé Le Meur
* Mateusz Gozdek

### Notable Changes

- Buildx now supports a default source policy for common build pipeline images that are provided by Docker Inc and signed by [Docker GitHub builder](https://github.com/docker/github-builder). These include `docker/dockerfile` frontend (including `docker/dockerfile-upstream` staging area) and `docker/buildkit-syft-scanner` image used for SBOM generation. These images are cryptographically verified to be authentic releases before they are used in builds. This feature is currently opt-in behind the `BUILDX_DEFAULT_POLICY` environment variable, but the intention is to enable it by default in a future release #3807
- Add `--policy` flag to `bake` command to specify global policy evaluation options. #3832
- Kubernetes driver now supports persistent storage options that change the deployment definition to use a StatefulSet and a persistent volume claim. #3766
- Fix issue where progress policy errors may have been lost in progress output. #3838
- Fix stopping `dial-stdio` command when the builder connection closes #3790
- Fix possible panic in `buildx debug` command when solving fails #3823
- Fix handling of Windows paths in local OCI layout definitions #3825 #3820 #3812
- Fix possible incorrect error when using `rm` commands on Docker context based builders #3817
- Fix possible cache miss due to nondeterministic ordering of extra hosts #3789
- Fix mounting of WSL libraries for GPU devices only on local docker-container endpoints #3784

### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                                  v1.41.4 -> v1.41.7
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.32.12 -> v1.32.17
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.19.12 -> v1.19.16
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.20 -> v1.18.23
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.20 -> v1.4.23
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.20 -> v2.7.23
* **github.com/aws/aws-sdk-go-v2/internal/v4a**                                     v1.4.24 **_new_**
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.7 -> v1.13.9
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.20 -> v1.13.23
* **github.com/aws/aws-sdk-go-v2/service/signin**                                   v1.0.8 -> v1.0.11
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.30.13 -> v1.30.17
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.35.17 -> v1.35.21
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.41.9 -> v1.42.1
* **github.com/aws/smithy-go**                                                      v1.24.2 -> v1.25.1
* **github.com/clipperhouse/uax29/v2**                                              v2.2.0 **_new_**
* **github.com/compose-spec/compose-go/v2**                                         v2.9.1 -> v2.10.2
* **github.com/containerd/containerd/v2**                                           v2.2.2 -> v2.2.3
* **github.com/docker/cli**                                                         v29.3.1 -> v29.4.3
* **github.com/docker/go-connections**                                              v0.6.0 -> v0.7.0
* **github.com/go-openapi/runtime**                                                 v0.29.2 -> v0.29.3
* **github.com/go-openapi/swag**                                                    v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/cmdutils**                                           v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/netutils**                                           v0.25.4 -> v0.25.5
* **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.27.7 -> v2.28.0
* **github.com/in-toto/in-toto-golang**                                             v0.10.0 -> v0.11.0
* **github.com/klauspost/compress**                                                 v1.18.5 -> v1.18.6
* **github.com/mattn/go-runewidth**                                                 v0.0.16 -> v0.0.23
* **github.com/moby/buildkit**                                                      v0.29.0 -> v0.30.0
* **github.com/moby/moby/api**                                                      v1.54.0 -> v1.54.2
* **github.com/moby/moby/client**                                                   v0.3.0 -> v0.4.1
* **github.com/moby/policy-helpers**                                                b7c0b994300b -> a39d60132186
* **github.com/moby/spdystream**                                                    v0.5.0 -> v0.5.1
* **github.com/sigstore/sigstore**                                                  v1.10.4 -> v1.10.5
* **github.com/sigstore/timestamp-authority/v2**                                    v2.0.3 -> v2.0.6
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.63.0 -> v0.68.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.63.0 -> v0.68.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.63.0 -> v0.68.0
* **go.opentelemetry.io/otel**                                                      v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/exporters/stdout/stdouttrace**                         v1.38.0 -> v1.42.0
* **go.opentelemetry.io/otel/metric**                                               v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/sdk**                                                  v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/sdk/metric**                                           v1.40.0 -> v1.43.0
* **go.opentelemetry.io/otel/trace**                                                v1.40.0 -> v1.43.0
* **go.opentelemetry.io/proto/otlp**                                                v1.9.0 -> v1.10.0
* **go.yaml.in/yaml/v4**                                                            v4.0.0-rc.4 **_new_**
* **golang.org/x/crypto**                                                           v0.48.0 -> v0.50.0
* **golang.org/x/mod**                                                              v0.33.0 -> v0.34.0
* **golang.org/x/net**                                                              v0.51.0 -> v0.53.0
* **golang.org/x/oauth2**                                                           v0.34.0 -> v0.36.0
* **golang.org/x/sync**                                                             v0.19.0 -> v0.20.0
* **golang.org/x/sys**                                                              v0.42.0 -> v0.43.0
* **golang.org/x/term**                                                             v0.41.0 -> v0.42.0
* **golang.org/x/text**                                                             v0.34.0 -> v0.36.0
* **golang.org/x/time**                                                             v0.14.0 -> v0.15.0
* **golang.org/x/tools**                                                            v0.41.0 -> v0.43.0
* **google.golang.org/genproto/googleapis/api**                                     8636f8732409 -> 6f92a3bedf2d
* **google.golang.org/genproto/googleapis/rpc**                                     8636f8732409 -> 6f92a3bedf2d
* **google.golang.org/grpc**                                                        v1.79.3 -> v1.80.0
* **k8s.io/api**                                                                    v0.35.2 -> v0.35.4
* **k8s.io/apimachinery**                                                           v0.35.2 -> v0.35.4
* **k8s.io/client-go**                                                              v0.35.2 -> v0.35.4

Previous release can be found at [v0.33.0](https://github.com/docker/buildx/releases/tag/v0.33.0)

</Release>

<Release version="v0.33.0" date="March 31, 2026" published="2026-03-31T15:32:35.000Z" url="https://github.com/docker/buildx/releases/tag/v0.33.0">
Welcome to the v0.33.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Jonathan A. Sternberg
* Sebastiaan van Stijn
* rishabh
* Akihiro Suda

### Notable Changes

- Imagetools `create` and `inspect` commands now support OCI layout paths as source and destination that can be used together with registry references #3721
- Bake command supports new builtin functions `formattimestamp` and `unixtimestampparse` for better handling of time values #3286
- DAP debugger support is now generally available without the need for the experimental features flag #3736
- Policy evaluation now supports verifying HTTP sources with PGP signatures through the `verify_http_pgp_signature` builtin #3677
- `policy eval` command now supports `--platform` flag to specify the platform for evaluated image sources #3738
- `policy eval` can now read policy from stdin when `-f -` is used #3738
- `policy eval` flag `--filename` has been renamed to `--file` for consistency with other commands. The previous flag is deprecated. #3738
- Fix issue where `imagetools create` could in some cases upload the same (attestation) manifest multiple times, possibly causing `400` error in some registries #3731
- Fix rejecting empty string values for `BUILDKIT_SYNTAX` build argument override #3734
- Fix possible inconsistent build context contents when using remote bake builds with a subdirectory in context path #3678
- Fix possible formatting issue in `imagetools inspect` based on whitespace in input #3732
- Fix possible error when finalizing build history traces in multi-node builders #3716 #3717
- Fix possible build errors when linking Bake multi-platform targets with session attributes like build secrets #3696
- Fix remote Bake git contexts to preserve subdirectory paths #3682
- Fix proxy build-arg override detection when argument casing differs #3697
- Fix DAP breakpoints on the entrypoint line being skipped in some cases #3691
- Fix DAP breakpoint detection on case-insensitive filesystems such as Windows #3704
- Fix DAP source path mapping for Dockerfiles outside the context root or in subdirectories #3709
- Fix DAP stepping by skipping internal build context load steps without source locations #3712
- Fix over-eager DAP input evaluation while stepping through builds #3687
- Fix DAP checks for whether an exec command can run successfully #3701
- Fix DAP debugger exit status reporting and output delivery on session shutdown #3735

### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                       v1.41.1 -> v1.41.4
* **github.com/aws/aws-sdk-go-v2/config**                                v1.32.7 -> v1.32.12
* **github.com/aws/aws-sdk-go-v2/credentials**                           v1.19.7 -> v1.19.12
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                      v1.18.17 -> v1.18.20
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                v1.4.17 -> v1.4.20
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                 v2.7.17 -> v2.7.20
* **github.com/aws/aws-sdk-go-v2/internal/ini**                          v1.8.4 -> v1.8.6
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**      v1.13.4 -> v1.13.7
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**        v1.13.17 -> v1.13.20
* **github.com/aws/aws-sdk-go-v2/service/signin**                        v1.0.5 -> v1.0.8
* **github.com/aws/aws-sdk-go-v2/service/sso**                           v1.30.9 -> v1.30.13
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                       v1.35.13 -> v1.35.17
* **github.com/aws/aws-sdk-go-v2/service/sts**                           v1.41.6 -> v1.41.9
* **github.com/aws/smithy-go**                                           v1.24.0 -> v1.24.2
* **github.com/containerd/containerd/v2**                                v2.2.1 -> v2.2.2
* **github.com/containerd/ttrpc**                                        v1.2.7 -> v1.2.8
* **github.com/docker/cli**                                              v29.2.1 -> v29.3.1
* **github.com/go-openapi/analysis**                                     v0.24.1 -> v0.24.3
* **github.com/go-openapi/errors**                                       v0.22.6 -> v0.22.7
* **github.com/go-openapi/jsonpointer**                                  v0.22.4 -> v0.22.5
* **github.com/go-openapi/jsonreference**                                v0.21.4 -> v0.21.5
* **github.com/go-openapi/loads**                                        v0.23.2 -> v0.23.3
* **github.com/go-openapi/spec**                                         v0.22.3 -> v0.22.4
* **github.com/go-openapi/strfmt**                                       v0.25.0 -> v0.26.1
* **github.com/go-openapi/swag/conv**                                    v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/fileutils**                               v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/jsonname**                                v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/jsonutils**                               v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/loading**                                 v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/mangling**                                v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/stringutils**                             v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/typeutils**                               v0.25.4 -> v0.25.5
* **github.com/go-openapi/swag/yamlutils**                               v0.25.4 -> v0.25.5
* **github.com/go-openapi/validate**                                     v0.25.1 -> v0.25.2
* **github.com/grpc-ecosystem/grpc-gateway/v2**                          v2.27.3 -> v2.27.7
* **github.com/klauspost/compress**                                      v1.18.4 -> v1.18.5
* **github.com/moby/buildkit**                                           v0.28.0 -> v0.29.0
* **github.com/moby/moby/api**                                           v1.53.0 -> v1.54.0
* **github.com/moby/moby/client**                                        v0.2.2 -> v0.3.0
* **github.com/moby/patternmatcher**                                     v0.6.0 -> v0.6.1
* **github.com/moby/policy-helpers**                                     824747bfdd3c -> b7c0b994300b
* **github.com/oklog/ulid/v2**                                           v2.1.1 **_new_**
* **go.opentelemetry.io/otel**                                           v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**  v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**  v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                  v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**    v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**    v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/metric**                                    v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/sdk**                                       v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/sdk/metric**                                v1.38.0 -> v1.40.0
* **go.opentelemetry.io/otel/trace**                                     v1.38.0 -> v1.40.0
* **go.opentelemetry.io/proto/otlp**                                     v1.7.1 -> v1.9.0
* **golang.org/x/sys**                                                   v0.41.0 -> v0.42.0
* **golang.org/x/term**                                                  v0.40.0 -> v0.41.0
* **google.golang.org/genproto/googleapis/api**                          ff82c1b0f217 -> 8636f8732409
* **google.golang.org/genproto/googleapis/rpc**                          0a764e51fe1b -> 8636f8732409
* **google.golang.org/grpc**                                             v1.78.0 -> v1.79.3
* **k8s.io/api**                                                         v0.34.1 -> v0.35.2
* **k8s.io/apimachinery**                                                v0.34.1 -> v0.35.2
* **k8s.io/client-go**                                                   v0.34.1 -> v0.35.2
* **k8s.io/kube-openapi**                                                f3f2b991d03b -> 589584f1c912
* **k8s.io/utils**                                                       4c0f3b243397 -> bc988d571ff4
* **sigs.k8s.io/json**                                                   cfa47c3a1cc8 -> 2d320260d730

Previous release can be found at [v0.32.1](https://github.com/docker/buildx/releases/tag/v0.32.1)

</Release>

<Release version="v0.32.1" date="March 4, 2026" published="2026-03-04T20:36:10.000Z" url="https://github.com/docker/buildx/releases/tag/v0.32.1">
buildx 0.32.1

Welcome to the v0.32.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi

### Notable Changes

- Fix possible error when building private Git repositories with secret credentials directly from remote source #3694

### Dependency Changes

This release has no dependency changes

Previous release can be found at [v0.32.0](https://github.com/docker/buildx/releases/tag/v0.32.0)

</Release>

<Release version="v0.32.0" date="March 4, 2026" published="2026-03-04T00:50:32.000Z" url="https://github.com/docker/buildx/releases/tag/v0.32.0">
buildx 0.32.0

Welcome to the v0.32.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Sebastiaan van Stijn
* Jonathan A. Sternberg
* Akhil Manoj
* David Karlsson
* yzewei


### Notable Changes

- Imagetools now supports `--metadata-file` flag to capture properties like descriptor/digest values for the new image. #3638
- Imagetools auth libraries have now been combined with the ones used in `build` commands, enabling previously missing support for scoped credentials and automatic fallbacks for Docker Hardened Image registries. #3627
- Many commands now support `--timeout` flag to configure the timeout for waiting for responses from remote builders. #3665
- Rego Policy now supports validating builds from remote sources (Git, HTTP) #3661
- Rego Policies now include new builtins for validating signed Sigstore bundle attestations of HTTP source artifacts. Attestations can also be automatically fetched from Github API #3657
- Rego policies can now use `input.image.provenance` to write rules validating specific provenance attestation fields. Materials of provenance can be accessed as policy secondary inputs. Requires BuildKit v0.28+ #3652 #3662
- Builds failing due to policy violations now have better error messages with the failing step clearly marked and the last policy logs shown with the error. #3656
- Fix possible passing of incorrect Git auth token for Bake builds when multiple remotes with different hosts exist. #3648
- Fixed policy filesystem reference lifecycle handling to avoid stale policy filesystem state during builds. #3674
- Normalized default policy filename resolution from environment configuration for more consistent behavior. #3675
- Named contexts used in different projects now get unique "shared keys" (previously based on context name) to avoid overwriting destinations of other projects, with reduced performance. This feature requires Dockerfile 1.22+ #3618
- Fix local subdir named context copied with wrong parent directory for remote Bake builds #3678
- Bake builds now capture the original URL information of named contexts sent as inputs in request metadata #3682 #3462
- Additional metrics associated with DAP debugger have been added #3633
- DAP file explorer now gets a more accurate state of the file system via updated BuildKit API #3450
- DAP file explorer source names have been improved #3631
- Improve the output of `-q` used with `--call` #3655


### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                   v1.39.6 -> v1.41.1
* **github.com/aws/aws-sdk-go-v2/config**                            v1.31.20 -> v1.32.7
* **github.com/aws/aws-sdk-go-v2/credentials**                       v1.18.24 -> v1.19.7
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                  v1.18.13 -> v1.18.17
* **github.com/aws/aws-sdk-go-v2/internal/configsources**            v1.4.13 -> v1.4.17
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**             v2.7.13 -> v2.7.17
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**  v1.13.3 -> v1.13.4
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**    v1.13.13 -> v1.13.17
* **github.com/aws/aws-sdk-go-v2/service/signin**                    v1.0.5 **_new_**
* **github.com/aws/aws-sdk-go-v2/service/sso**                       v1.30.3 -> v1.30.9
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                   v1.35.7 -> v1.35.13
* **github.com/aws/aws-sdk-go-v2/service/sts**                       v1.40.2 -> v1.41.6
* **github.com/aws/smithy-go**                                       v1.23.2 -> v1.24.0
* **github.com/cloudflare/circl**                                    v1.6.1 -> v1.6.3
* **github.com/docker/cli**                                          v29.1.5 -> v29.2.1
* **github.com/go-openapi/errors**                                   v0.22.4 -> v0.22.6
* **github.com/go-openapi/jsonpointer**                              v0.22.1 -> v0.22.4
* **github.com/go-openapi/jsonreference**                            v0.21.3 -> v0.21.4
* **github.com/go-openapi/spec**                                     v0.22.1 -> v0.22.3
* **github.com/go-openapi/swag**                                     v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/cmdutils**                            v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/conv**                                v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/fileutils**                           v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/jsonname**                            v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/jsonutils**                           v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/loading**                             v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/mangling**                            v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/netutils**                            v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/stringutils**                         v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/typeutils**                           v0.25.3 -> v0.25.4
* **github.com/go-openapi/swag/yamlutils**                           v0.25.3 -> v0.25.4
* **github.com/go-viper/mapstructure/v2**                            v2.4.0 -> v2.5.0
* **github.com/golang/snappy**                                       v1.0.0 **_new_**
* **github.com/google/go-containerregistry**                         v0.20.6 -> v0.20.7
* **github.com/in-toto/in-toto-golang**                              v0.9.0 -> v0.10.0
* **github.com/klauspost/compress**                                  v1.18.2 -> v1.18.4
* **github.com/moby/buildkit**                                       v0.27.0 -> v0.28.0
* **github.com/moby/moby/api**                                       v1.52.0 -> v1.53.0
* **github.com/moby/moby/client**                                    v0.2.1 -> v0.2.2
* **github.com/moby/policy-helpers**                                 9fcc1a9ec5c9 -> 824747bfdd3c
* **github.com/package-url/packageurl-go**                           v0.1.1 **_new_**
* **github.com/pelletier/go-toml/v2**                                v2.2.4 **_new_**
* **github.com/secure-systems-lab/go-securesystemslib**              v0.9.1 -> v0.10.0
* **github.com/sigstore/rekor**                                      v1.4.3 -> v1.5.0
* **github.com/sigstore/sigstore**                                   v1.10.0 -> v1.10.4
* **github.com/sigstore/sigstore-go**                                b5fe07a5a7d7 -> v1.1.4
* **github.com/sigstore/timestamp-authority/v2**                     v2.0.2 -> v2.0.3
* **github.com/theupdateframework/go-tuf/v2**                        v2.3.0 -> v2.4.1
* **google.golang.org/genproto/googleapis/api**                      f26f9409b101 -> ff82c1b0f217
* **google.golang.org/genproto/googleapis/rpc**                      f26f9409b101 -> 0a764e51fe1b
* **google.golang.org/grpc**                                         v1.76.0 -> v1.78.0

Previous release can be found at [v0.31.1](https://github.com/docker/buildx/releases/tag/v0.31.1)


</Release>

<Release version="v0.31.1" date="January 29, 2026" published="2026-01-29T04:10:34.000Z" url="https://github.com/docker/buildx/releases/tag/v0.31.1">
buildx 0.31.1

Welcome to the v0.31.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi

### Notable Changes

- Fix excessive HTTP requests when using `buildx imagetools create` command #3632

### Dependency Changes

This release has no dependency changes

Previous release can be found at [v0.31.0](https://github.com/docker/buildx/releases/tag/v0.31.0)

</Release>

<Release version="v0.31.0" date="January 22, 2026" published="2026-01-22T00:18:29.000Z" url="https://github.com/docker/buildx/releases/tag/v0.31.0">
buildx 0.31.0

Welcome to the v0.31.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Sebastiaan van Stijn
* Jonathan A. Sternberg
* Justin Chadwell
* Akihiro Suda
* Brian Goff
* David Karlsson
* Paweł Gronowski
* Sergei Khomenkov
* guimove

### Notable Changes

- This is a first version of Buildx with signed artifacts built using [Docker Github Builder](https://github.com/docker/github-builder-experimental)
- This release comes with new experimental support for source policy enforcement during builds using policies written in [Rego](https://www.openpolicyagent.org/docs/policy-language) language. There are some limitations in this release, for example, only builds from the local build context currently load policies. #3593 #3539 #3592 #3611 [docs](https://docs.docker.com/build/policies/)
  - Matching policy for Dockerfile is loaded automatically if one exists, e.g., `Dockerfile.rego` or `app.Dockerfile.rego`.
  - Additional policy configuration can be provided using new `build --policy` flag.
  - Bake also supports automatic policy loading and a new `policy` key in the target configuration.
  - New `buildx policy` command includes subcommands `eval` and `test` to help you write and test your policies.
- Bake command has a new `--var` flag to set variable values from the command line instead of setting environment variables. #3610
- When creating images in Docker image store, they no longer unpack if export was initialized with `--push` or `-o type=registry` #3519
- Add `semvercmp` helper function to Bake stdlib for easier version comparisons #3577
- Retry transient TLS errors when talking to Kubernetes nodes #3493
- Allow disabling Bake env lookups so `bake` can ignore host environment variables #3595
- Add possibility to load Docker configs scoped to specific repos/scopes for finer credential control #3562
- When building images from Docker Hardened Images (dhi.io) and Docker Scout registries, authentication will now automatically fall back to Docker Hub credentials if no specific credentials are found. #3612
- Fix the `--debug` flag issues in standalone mode #3554
- Fix handling `@` characters inside OCI layout paths passed to build #3583
- Surface policy controls `--policy`, policy eval, custom builtins/Regos/gitsign checks so builds can enforce policies #3593 #3549
- Prevent DAP breakpoint overlaps from triggering false positives #3534
- Fix mount input names in DAP run mounts #3579
- Fix DAP breakpoint reason reporting #3581


### Dependency Changes

* **github.com/ProtonMail/go-crypto**                                               v1.3.0 **_new_**
* **github.com/agnivade/levenshtein**                                               v1.2.1 **_new_**
* **github.com/asaskevich/govalidator**                                             a9d515a09cc2 **_new_**
* **github.com/aws/aws-sdk-go-v2**                                                  v1.38.1 -> v1.39.6
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.31.3 -> v1.31.20
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.18.7 -> v1.18.24
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.4 -> v1.18.13
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.4 -> v1.4.13
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.4 -> v2.7.13
* **github.com/aws/aws-sdk-go-v2/internal/ini**                                     v1.8.3 -> v1.8.4
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.0 -> v1.13.3
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.4 -> v1.13.13
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.28.2 -> v1.30.3
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.34.0 -> v1.35.7
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.38.0 -> v1.40.2
* **github.com/aws/smithy-go**                                                      v1.22.5 -> v1.23.2
* **github.com/beorn7/perks**                                                       v1.0.1 **_new_**
* **github.com/blang/semver**                                                       v3.5.1 **_new_**
* **github.com/cespare/xxhash/v2**                                                  v2.3.0 **_new_**
* **github.com/cloudflare/circl**                                                   v1.6.1 **_new_**
* **github.com/containerd/containerd/v2**                                           efd86f2b0bc2 -> v2.2.1
* **github.com/cyberphone/json-canonicalization**                                   19d51d7fe467 **_new_**
* **github.com/davecgh/go-spew**                                                    v1.1.1 -> d8f796af33cc
* **github.com/decred/dcrd/dcrec/secp256k1/v4**                                     v4.4.0 **_new_**
* **github.com/digitorus/pkcs7**                                                    3a137a874352 **_new_**
* **github.com/digitorus/timestamp**                                                220c5c2851b7 **_new_**
* **github.com/docker/cli**                                                         v28.5.1 -> v29.1.5
* **github.com/docker/cli-docs-tool**                                               v0.10.0 -> v0.11.0
* **github.com/docker/docker**                                                      v28.5.1 -> v28.5.2
* **github.com/docker/docker-credential-helpers**                                   v0.9.3 -> v0.9.5
* **github.com/docker/go-connections**                                              v0.5.0 -> v0.6.0
* **github.com/fvbommel/sortorder**                                                 v1.0.1 -> v1.1.0
* **github.com/go-ini/ini**                                                         v1.67.0 **_new_**
* **github.com/go-openapi/analysis**                                                v0.24.1 **_new_**
* **github.com/go-openapi/errors**                                                  v0.22.4 **_new_**
* **github.com/go-openapi/jsonpointer**                                             v0.21.0 -> v0.22.1
* **github.com/go-openapi/jsonreference**                                           v0.20.2 -> v0.21.3
* **github.com/go-openapi/loads**                                                   v0.23.2 **_new_**
* **github.com/go-openapi/runtime**                                                 v0.29.2 **_new_**
* **github.com/go-openapi/spec**                                                    v0.22.1 **_new_**
* **github.com/go-openapi/strfmt**                                                  v0.25.0 **_new_**
* **github.com/go-openapi/swag**                                                    v0.23.0 -> v0.25.3
* **github.com/go-openapi/swag/cmdutils**                                           v0.25.3 **_new_**
* **github.com/go-openapi/swag/conv**                                               v0.25.3 **_new_**
* **github.com/go-openapi/swag/fileutils**                                          v0.25.3 **_new_**
* **github.com/go-openapi/swag/jsonname**                                           v0.25.3 **_new_**
* **github.com/go-openapi/swag/jsonutils**                                          v0.25.3 **_new_**
* **github.com/go-openapi/swag/loading**                                            v0.25.3 **_new_**
* **github.com/go-openapi/swag/mangling**                                           v0.25.3 **_new_**
* **github.com/go-openapi/swag/netutils**                                           v0.25.3 **_new_**
* **github.com/go-openapi/swag/stringutils**                                        v0.25.3 **_new_**
* **github.com/go-openapi/swag/typeutils**                                          v0.25.3 **_new_**
* **github.com/go-openapi/swag/yamlutils**                                          v0.25.3 **_new_**
* **github.com/go-openapi/validate**                                                v0.25.1 **_new_**
* **github.com/gobwas/glob**                                                        v0.2.3 **_new_**
* **github.com/goccy/go-json**                                                      v0.10.5 **_new_**
* **github.com/google/certificate-transparency-go**                                 v1.3.2 **_new_**
* **github.com/google/go-containerregistry**                                        v0.20.6 **_new_**
* **github.com/google/go-dap**                                                      v0.12.0 -> d7a2259b058b
* **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.27.2 -> v2.27.3
* **github.com/hiddeco/sshsig**                                                     v0.2.0 **_new_**
* **github.com/in-toto/attestation**                                                v1.1.2 **_new_**
* **github.com/klauspost/compress**                                                 v1.18.1 -> v1.18.2
* **github.com/lestrrat-go/blackmagic**                                             v1.0.4 **_new_**
* **github.com/lestrrat-go/dsig**                                                   v1.0.0 **_new_**
* **github.com/lestrrat-go/dsig-secp256k1**                                         v1.0.0 **_new_**
* **github.com/lestrrat-go/httpcc**                                                 v1.0.1 **_new_**
* **github.com/lestrrat-go/httprc/v3**                                              v3.0.1 **_new_**
* **github.com/lestrrat-go/jwx/v3**                                                 v3.0.11 **_new_**
* **github.com/lestrrat-go/option**                                                 v1.0.1 **_new_**
* **github.com/lestrrat-go/option/v2**                                              v2.0.0 **_new_**
* **github.com/moby/buildkit**                                                      v0.26.1 -> v0.27.0
* **github.com/moby/go-archive**                                                    v0.1.0 -> v0.2.0
* **github.com/moby/moby/api**                                                      v1.52.0 **_new_**
* **github.com/moby/moby/client**                                                   v0.2.1 **_new_**
* **github.com/moby/policy-helpers**                                                9fcc1a9ec5c9 **_new_**
* **github.com/morikuni/aec**                                                       v1.0.0 -> v1.1.0
* **github.com/oklog/ulid**                                                         v1.3.1 **_new_**
* **github.com/open-policy-agent/opa**                                              v1.10.1 **_new_**
* **github.com/pmezard/go-difflib**                                                 v1.0.0 -> 5d4384ee4fb2
* **github.com/prometheus/client_golang**                                           v1.23.2 **_new_**
* **github.com/prometheus/client_model**                                            v0.6.2 **_new_**
* **github.com/prometheus/common**                                                  v0.66.1 **_new_**
* **github.com/prometheus/procfs**                                                  v0.17.0 **_new_**
* **github.com/rcrowley/go-metrics**                                                65e299d6c5c9 **_new_**
* **github.com/rivo/uniseg**                                                        v0.2.0 -> v0.4.7
* **github.com/segmentio/asm**                                                      v1.2.0 **_new_**
* **github.com/sigstore/protobuf-specs**                                            v0.5.0 **_new_**
* **github.com/sigstore/rekor**                                                     v1.4.3 **_new_**
* **github.com/sigstore/rekor-tiles/v2**                                            v2.0.1 **_new_**
* **github.com/sigstore/sigstore**                                                  v1.10.0 **_new_**
* **github.com/sigstore/sigstore-go**                                               b5fe07a5a7d7 **_new_**
* **github.com/sigstore/timestamp-authority/v2**                                    v2.0.2 **_new_**
* **github.com/sirupsen/logrus**                                                    v1.9.3 -> v1.9.4
* **github.com/spf13/cobra**                                                        v1.10.1 -> v1.10.2
* **github.com/tchap/go-patricia/v2**                                               v2.3.3 **_new_**
* **github.com/theupdateframework/go-tuf/v2**                                       v2.3.0 **_new_**
* **github.com/tonistiigi/fsutil**                                                  586307ad452f -> a2aa163d723f
* **github.com/transparency-dev/formats**                                           404c0d5b696c **_new_**
* **github.com/transparency-dev/merkle**                                            v0.0.2 **_new_**
* **github.com/valyala/fastjson**                                                   v1.6.4 **_new_**
* **github.com/vektah/gqlparser/v2**                                                v2.5.30 **_new_**
* **github.com/xeipuuv/gojsonpointer**                                              02993c407bfb **_new_**
* **github.com/xeipuuv/gojsonreference**                                            bd5ef7bd5415 **_new_**
* **github.com/yashtewari/glob-intersection**                                       v0.2.0 **_new_**
* **go.mongodb.org/mongo-driver**                                                   v1.17.6 **_new_**
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.61.0 -> v0.63.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.61.0 -> v0.63.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.61.0 -> v0.63.0
* **go.opentelemetry.io/otel/exporters/stdout/stdouttrace**                         v1.31.0 -> v1.38.0
* **go.yaml.in/yaml/v2**                                                            v2.4.2 -> v2.4.3
* **google.golang.org/genproto/googleapis/api**                                     c5933d9347a5 -> f26f9409b101
* **google.golang.org/genproto/googleapis/rpc**                                     c5933d9347a5 -> f26f9409b101

Previous release can be found at [v0.30.1](https://github.com/docker/buildx/releases/tag/v0.30.1)


</Release>

<Release version="v0.30.1" date="November 17, 2025" published="2025-11-17T17:50:47.000Z" url="https://github.com/docker/buildx/releases/tag/v0.30.1">
Welcome to the v0.30.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Jonathan A. Sternberg

### Notable Changes

- Fix concurrent map write panic. #3524
- Fix possible excessive chunking when fetching blobs. #3529

### Dependency Changes

* **github.com/containerd/containerd/v2**  v2.2.0 -> efd86f2b0bc2
* **github.com/moby/buildkit**             v0.26.0 -> v0.26.1

Previous release can be found at [v0.30.0](https://github.com/docker/buildx/releases/tag/v0.30.0)

</Release>

<Release version="v0.30.0" date="November 12, 2025" published="2025-11-12T21:13:10.000Z" url="https://github.com/docker/buildx/releases/tag/v0.30.0">
buildx 0.30.0

Welcome to the v0.30.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Jonathan A. Sternberg
* Remy Suen
* Sebastiaan van Stijn
* aevesdocker
* Akihiro Suda
* Guillaume Lours
* Ricardo Branco
* Roberto Castellotti
* Roberto Villarreal

### Notable Changes

- Tar exporter output will now automatically create parent directories. #3478
- Deprecate `docker buildx install` and `docker buildx uninstall` in favor of using `docker buildx` directly without relying on the `docker builder` aliases. #3472
- Clarify CLI help for the `--tag` option to give more guidance on a valid argument. #3454
- Bake: Ensure typed variables with no value still carry type to prevent a panic. #3463
- `imagetools create` now persists attestation manifest and any manifest cosign-based signatures when creating new images. #3433
- Add option to `docker-container` driver to write github actions payload for provenance with `--driver-opt=provenance-add-gha=true`. #3453
- Avoid concurrent map write panic with `imagetools create`. #3510
- Avoid panic when linking a nil target to another build in Bake. #3511
- DAP: Next, step in, and step out requests now respect breakpoints. #3488
- DAP: Verify breakpoints when `stopOnEntry` is used. #3488
- DAP: Support `runInTerminal` reverse request when `buildx dap` is run in standalone mode. #3471
- DAP: Stop sending null in `setBreakpoints` response when the breakpoints are cleared to conform to the specification. #3481
- DAP: `exec` command now works when suspended on a `COPY` line. #3469
- DAP: Debugger now ensures that all inputs are properly executed when suspended on a line. #3469
- DAP: Debugger now pauses on `COPY` lines when there is a non-existent file. #3437
- Compose support has been updated to v2.9.1. #3494

### Dependency Changes

* **github.com/aws/aws-sdk-go-v2**                                                  v1.30.3 -> v1.38.1
* **github.com/aws/aws-sdk-go-v2/config**                                           v1.27.27 -> v1.31.3
* **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.17.27 -> v1.18.7
* **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.16.11 -> v1.18.4
* **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.3.15 -> v1.4.4
* **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.6.15 -> v2.7.4
* **github.com/aws/aws-sdk-go-v2/internal/ini**                                     v1.8.0 -> v1.8.3
* **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.11.3 -> v1.13.0
* **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.11.17 -> v1.13.4
* **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.22.4 -> v1.28.2
* **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.26.4 -> v1.34.0
* **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.30.3 -> v1.38.0
* **github.com/aws/smithy-go**                                                      v1.20.3 -> v1.22.5
* **github.com/cenkalti/backoff/v5**                                                v5.0.3 **_new_**
* **github.com/compose-spec/compose-go/v2**                                         v2.9.0 -> v2.9.1
* **github.com/containerd/containerd/api**                                          v1.9.0 -> v1.10.0
* **github.com/containerd/containerd/v2**                                           v2.1.4 -> v2.2.0
* **github.com/containerd/platforms**                                               v1.0.0-rc.1 -> v1.0.0-rc.2
* **github.com/docker/cli**                                                         v28.4.0 -> v28.5.1
* **github.com/docker/docker**                                                      v28.4.0 -> v28.5.1
* **github.com/emicklei/go-restful/v3**                                             v3.11.0 -> v3.13.0
* **github.com/fxamacker/cbor/v2**                                                  v2.7.0 -> v2.9.0
* **github.com/go-logr/logr**                                                       v1.4.2 -> v1.4.3
* **github.com/gofrs/flock**                                                        v0.12.1 -> v0.13.0
* **github.com/google/gnostic-models**                                              v0.6.8 -> v0.7.0
* **github.com/gorilla/websocket**                                                  v1.5.0 -> e064f32e3674
* **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.26.1 -> v2.27.2
* **github.com/klauspost/compress**                                                 v1.18.0 -> v1.18.1
* **github.com/moby/buildkit**                                                      v0.25.0 -> v0.26.0
* **github.com/modern-go/reflect2**                                                 v1.0.2 -> 35a7c28c31ee
* **github.com/secure-systems-lab/go-securesystemslib**                             v0.6.0 -> v0.9.1
* **github.com/stretchr/testify**                                                   v1.11.0 -> v1.11.1
* **go.opentelemetry.io/auto/sdk**                                                  v1.1.0 -> v1.2.1
* **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.60.0 -> v0.61.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.60.0 -> v0.61.0
* **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.60.0 -> v0.61.0
* **go.opentelemetry.io/otel**                                                      v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/metric**                                               v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/sdk**                                                  v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/sdk/metric**                                           v1.35.0 -> v1.38.0
* **go.opentelemetry.io/otel/trace**                                                v1.35.0 -> v1.38.0
* **go.opentelemetry.io/proto/otlp**                                                v1.5.0 -> v1.7.1
* **go.yaml.in/yaml/v2**                                                            v2.4.2 **_new_**
* **golang.org/x/crypto**                                                           v0.38.0 -> v0.42.0
* **golang.org/x/mod**                                                              v0.24.0 -> v0.29.0
* **golang.org/x/net**                                                              v0.39.0 -> v0.44.0
* **golang.org/x/oauth2**                                                           v0.29.0 -> v0.30.0
* **golang.org/x/sync**                                                             v0.16.0 -> v0.17.0
* **golang.org/x/sys**                                                              v0.33.0 -> v0.37.0
* **golang.org/x/term**                                                             v0.32.0 -> v0.35.0
* **golang.org/x/text**                                                             v0.25.0 -> v0.29.0
* **golang.org/x/time**                                                             v0.11.0 -> v0.14.0
* **golang.org/x/tools**                                                            v0.32.0 -> v0.37.0
* **google.golang.org/genproto/googleapis/api**                                     56aae31c358a -> c5933d9347a5
* **google.golang.org/genproto/googleapis/rpc**                                     56aae31c358a -> c5933d9347a5
* **google.golang.org/grpc**                                                        v1.72.2 -> v1.76.0
* **google.golang.org/protobuf**                                                    v1.36.9 -> v1.36.10
* **k8s.io/api**                                                                    v0.32.3 -> v0.34.1
* **k8s.io/apimachinery**                                                           v0.32.3 -> v0.34.1
* **k8s.io/client-go**                                                              v0.32.3 -> v0.34.1
* **k8s.io/kube-openapi**                                                           32ad38e42d3f -> f3f2b991d03b
* **k8s.io/utils**                                                                  3ea5e8cea738 -> 4c0f3b243397
* **sigs.k8s.io/json**                                                              9aa6b5e7a4b3 -> cfa47c3a1cc8
* **sigs.k8s.io/randfill**                                                          v1.0.0 **_new_**
* **sigs.k8s.io/structured-merge-diff/v6**                                          v6.3.0 **_new_**
* **sigs.k8s.io/yaml**                                                              v1.4.0 -> v1.6.0

Previous release can be found at [v0.29.1](https://github.com/docker/buildx/releases/tag/v0.29.1)

</Release>

<Release version="v0.29.1" date="October 3, 2025" published="2025-10-03T12:33:06.000Z" url="https://github.com/docker/buildx/releases/tag/v0.29.1">
Welcome to the v0.29.1 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax

### Notable Changes

- imagetools: fix possible broken chain copy on create. #3447
- imagetools: silence warning for empty-type mediatype used in artifacts. #3448

### Dependency Changes

This release has no dependency changes

Previous release can be found at [v0.29.0](https://github.com/docker/buildx/releases/tag/v0.29.0)

</Release>

<Release version="v0.29.0" date="September 30, 2025" published="2025-09-30T20:09:12.000Z" url="https://github.com/docker/buildx/releases/tag/v0.29.0">
buildx 0.29.0

Welcome to the v0.29.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Jonathan A. Sternberg
* Sebastiaan van Stijn
* aevesdocker
* Akihiro Suda
* Guillaume Lours

### Notable Changes

- `imagetools create` command now supports `--platform` option to create final image only for specified platforms. The inline attestation for the specified platforms are also kept in the final image. #3430
- DAP debugger can now show the correct file explorer data when the debugger stops because of a build error. #3410 
- New `--progress=none` option has been added. This is similar to `--progress=quiet`, but it does not print the image ID after image result export. #3431
- When building from a Git URL, buildx now optionally supports resolution of the context data on the client side. Git repository is still cloned on the server side, but this can help in cases where one can't be sure what version of Git URL resolution the server side supports. #3415 
- Fix DAP debugger location resolution when there are multiple build steps with the same BuildKit digest. #3408
- Compose support has been updated to v2.9.0

### Dependency Changes

* **github.com/compose-spec/compose-go/v2**  v2.8.1 -> v2.9.0
* **github.com/docker/cli**                  v28.3.3 -> v28.4.0
* **github.com/docker/docker**               v28.3.3 -> v28.4.0
* **github.com/go-viper/mapstructure/v2**    v2.3.0 -> v2.4.0
* **github.com/hashicorp/go-cty-funcs**      dda779884a9f -> 6aab67130928
* **github.com/hashicorp/hcl/v2**            v2.23.0 -> v2.24.0
* **github.com/mitchellh/go-wordwrap**       ad45545899c7 -> v1.0.1
* **github.com/moby/buildkit**               v0.24.0 -> v0.25.0
* **github.com/spf13/cobra**                 v1.9.1 -> v1.10.1
* **github.com/spf13/pflag**                 v1.0.7 -> v1.0.10
* **github.com/zclconf/go-cty**              v1.16.2 -> v1.17.0
* **golang.org/x/crypto**                    v0.37.0 -> v0.38.0
* **golang.org/x/term**                      v0.31.0 -> v0.32.0
* **golang.org/x/text**                      v0.24.0 -> v0.25.0
* **google.golang.org/protobuf**             v1.36.6 -> v1.36.9

Previous release can be found at [v0.28.0](https://github.com/docker/buildx/releases/tag/v0.28.0)

</Release>

<Release version="v0.28.0" date="September 4, 2025" published="2025-09-04T00:06:50.000Z" url="https://github.com/docker/buildx/releases/tag/v0.28.0">
Welcome to the v0.28.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* Tõnis Tiigi
* CrazyMax
* Akihiro Suda
* Dan Duvall
* Jonathan A. Sternberg
* Sebastiaan van Stijn
* Will Nonnemaker

### Notable Changes

- When building with Dockerfile 1.18.0+ frontend (BuildKit v0.24) you can now use new Git URLs with query options for build context and named contexts in `build` and `bake` command. [More info](https://github.com/moby/buildkit/releases/tag/dockerfile%2F1.18.0) [moby/buildkit#6183](https://github.com/moby/buildkit/pull/6183)
- Add formatting options to the `buildx du` command for custom and machine-readable output. #3377
- Kubernetes driver now supports `env.<key>` driver opts. #3373
- Add support for `BUILDKIT_SYNTAX` build argument when BuildKit has Dockerfile frontend disabled. #3385
- Fix failing early when trying to export index annotations with moby exporter. #3384
- Fix possible errors on Windows from symlink handling. #3386


### Dependency Changes

* **github.com/cpuguy83/go-md2man/v2**  v2.0.6 -> v2.0.7
* **github.com/moby/buildkit**          955c2b2f7d01 -> v0.24.0
* **github.com/spf13/pflag**            v1.0.6 -> v1.0.7
* **github.com/stretchr/testify**       v1.10.0 -> v1.11.0

Previous release can be found at [v0.27.0](https://github.com/docker/buildx/releases/tag/v0.27.0)

</Release>

<Release version="v0.27.0" date="August 20, 2025" published="2025-08-20T09:46:53.000Z" url="https://github.com/docker/buildx/releases/tag/v0.27.0">
Welcome to the v0.27.0 release of buildx!



Please try out the release binaries and report any issues at
https://github.com/docker/buildx/issues.

### Contributors

* CrazyMax
* Tõnis Tiigi
* Jonathan A. Sternberg
* Sebastiaan van Stijn
* Guillaume Lours
* Nicolas De Loof

### Notable Changes

* Experimental: DAP: Exec shell now restarts with the new container when execution resumes and pauses again. #3341
* Experimental: DAP: Add `File Explorer` section to variables to inspect filesystem state. #3327
* Experimental: DAP: Change Dockerfile step order to match more closely with user expectations. #3325
* Experimental: DAP: Improve determination of the proper parent. #3366
* Experimental: DAP: Dockerfile nested in the context is now supported. #3371
* Build name shown in history can now be overridden with `BUILDKIT_BUILD_NAME` build argument. #3330
* Bake now supports `homedir()` function. #3351
* Bake default for empty Dockerfile defaults to `Dockerfile` to match the behavior of `build` command. #3347
* Bake supports `pull` and `no_cache` fields for compose files. #3352
* Sanitize the names of `additional_contexts` from compose files when building with Bake. #3361
* Compose compatibility has been updated to v2.8.1. #3337
* Fix missing WSL libraries in `docker-container` driver when GPU device is requested. #3320

### Dependency Changes

* **github.com/compose-spec/compose-go/v2**  891fce532a51 -> v2.8.1
* **github.com/containerd/containerd/v2**    v2.1.3 -> v2.1.4
* **github.com/docker/cli**                  v28.3.2 -> v28.3.3
* **github.com/docker/docker**               v28.3.2 -> v28.3.3
* **github.com/moby/buildkit**               9b91d20367db -> 955c2b2f7d01
* **go.yaml.in/yaml/v3**                     v3.0.4 **_new_**

Previous release can be found at [v0.26.1](https://github.com/docker/buildx/releases/tag/v0.26.1)

</Release>

<Pagination cursor="2025-08-20T09:46:53.000Z|2026-03-31T14:12:42.306Z|rel_a8eIAX85hJE3eJimZgScs" next="https://releases.sh/docker/docker-buildx-releases.md?cursor=2025-08-20T09%3A46%3A53.000Z%7C2026-03-31T14%3A12%3A42.306Z%7Crel_a8eIAX85hJE3eJimZgScs&limit=20" />
