releases.shpreview
Home/Docker
Docker

Docker

New reconciliation algorithm; loopback registry proxy bypassed

This release2 featuresNew capabilities1 enhancementImprovements to existing features6 fixesBug fixesAI-tallied from the release notes

Introduces a new reconciliation algorithm between observed and expected state, which may affect existing Compose workloads. Adds rawsetenv message type for provider plugins. Fixes include bypassing Docker Desktop proxy for loopback registries, honoring env_file required: false on publish, and skipping remote URL contexts from bake fs.read allowlist.

Read more →

New reconciliation algorithm; plugin rawsetenv support

This release2 featuresNew capabilities3 fixesBug fixesAI-tallied from the release notes
Docker Compose · v5.2.0

Introduced a new reconciliation algorithm between observed and expected container state, and added rawsetenv message type for provider plugins. Fixed TTY auto-detection via stderr, publish env_file handling with missing optional files, and skip validation when extracting config variables.

Read more →

Local output delete mode; resource limits; network proxy via source policies

This release3 featuresNew capabilities1 fixBug fixesAI-tallied from the release notes
Docker Buildx · v0.35.0

Local output now supports a mode=delete attribute that replaces the destination directory with the build result, restricted to subdirectories of the working directory by default. Resource limits for CPU and memory can be set via the --resource flag. Source policies support the BuildKit exec proxy feature for controlling build-step network traffic. Also fixes a possible closed channel panic.

Read more →
Docker Buildx · v0.34.0

Buildx now supports a default source policy for Docker-provided build images (docker/dockerfile and docker/buildkit-syft-scanner) that are cryptographically verified before use, currently opt-in via the BUILDX_DEFAULT_POLICY environment variable with intent to enable by default in a future release. Kubernetes driver now supports persistent storage options using StatefulSet and persistent volume claims. Multiple fixes address progress policy error handling, dial-stdio connection closure, panic in debug command, Windows path handling in OCI layouts, cache misses from nondeterministic host ordering, and WSL GPU library mounting.

Read more →

Fixed CVE-2026-31431 ("copy.fail"), a privilege escalation vulnerability that allowed unprivileged container users to gain root access via the host VM page cache. Also fixed bugs where transient network errors during sign-in would unexpectedly sign users out instead of retrying, and where users were signed out mid-flow when signing in via docker login with OAuth. The Logs view is now generally available, and new Windows installations can choose between per-user (Beta) or all-user installs.

Read more →
Last Checked
7m ago
Category
Tracking since Aug 31, 2017