Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 29, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/docker/compose/v2 v2.35.0 -> v2.40.2 age confidence

GitHub Vulnerability Alerts

CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there.

Impact

This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected.
An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps.

Patches

v2.40.2

Workarounds

NA


Release Notes

docker/compose (github.com/docker/compose/v2)

v2.40.2

Compare Source

What's Changed

🐛 Fixes
  • Compose can't create a tar with adequate uid:gid ownership by @​ndeloof in #​13299
  • Test digest or canonical reference, not only tag, when checking if an image is already present by @​glours in #​13302
🔧 Internal

Full Changelog: docker/compose@v2.40.1...v2.40.2

v2.40.1

Compare Source

What's Changed

🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.40.0...v2.40.1

v2.40.0

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies
  • build(deps): bump github.com/docker/docker, docker/cli v28.5.0-rc.1 by @​thaJeztah in #​13241
  • build(deps): bump github.com/docker/docker from 28.5.0-rc.1+incompatible to 28.5.0+incompatible by @​dependabot[bot] in #​13260
  • build(deps): bump github.com/docker/cli from 28.5.0-rc.1+incompatible to 28.5.0+incompatible by @​dependabot[bot] in #​13261

Full Changelog: docker/compose@v2.39.4...v2.40.0

v2.39.4

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.39.3...v2.39.4

v2.39.3

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.39.2...v2.39.3

v2.39.2

Compare Source

What's Changed

🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.39.1...v2.39.2

v2.39.1

Compare Source

What's Changed

🔧 Internal

⚙️ Dependencies

Full Changelog: docker/compose@v2.39.0...v2.39.1

v2.39.0

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.38.2...v2.39.0

v2.38.2

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.38.1...v2.38.2

v2.38.1

Compare Source

What's Changed

✨ Improvements
⚙️ Dependencies

Full Changelog: docker/compose@v2.38.0...v2.38.1

v2.38.0

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
⚙️ Dependencies
  • build(deps): bump github.com/docker/cli from 28.2.2+incompatible to 28.3.0+incompatible by @​dependabot in #​12974
  • build(deps): bump github.com/docker/docker from 28.2.2+incompatible to 28.3.0+incompatible by @​dependabot in #​12975

New Contributors

Full Changelog: docker/compose@v2.37.3...v2.38.0

v2.37.3

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

Full Changelog: docker/compose@v2.37.2...v2.37.3

v2.37.2

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

Full Changelog: docker/compose@v2.37.1...v2.37.2

v2.37.1

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.37.0...v2.37.1

v2.37.0

Compare Source

What's Changed

ℹ️ bake is now used as the default images builder, if you don't want to use it you could opt-out by setting the COMPOSE_BAKE env variable to false

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

New Contributors

Full Changelog: docker/compose@v2.36.2...v2.37.0

v2.36.2

Compare Source

What's Changed

🐛 Fixes
🔧 Internal
⚙️ Dependencies

Full Changelog: docker/compose@v2.36.1...v2.36.2

v2.36.1

Compare Source

What's Changed

✨ Improvements
🐛 Fixes
🔧 Internal
⚙️ Dependencies

Full Changelog: docker/compose@v2.36.0...v2.36.1

v2.36.0

Compare Source

What's Changed

🎉 You can now use external binaries as service provider to extend Compose behaviour. For more information about creating your own plugin check the documentation

✨ Improvements
🐛 Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Oct 29, 2025
@renovate renovate bot requested review from a team as code owners October 29, 2025 02:03
@renovate
Copy link
Contributor Author

renovate bot commented Oct 29, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: providers/flagd/go.sum
Command failed: go get -t ./...
go: module github.com/docker/compose/[email protected] requires go >= 1.24.9; switching to go1.24.9
go: downloading go1.24.9 (linux/amd64)
go: download go1.24.9: golang.org/[email protected]: verifying module: checksum database disabled by GOSUMDB=off

@renovate renovate bot added the renovate label Oct 29, 2025
@renovate renovate bot force-pushed the renovate/vulnerability-updates branch 8 times, most recently from 18dc1c2 to ea8b473 Compare November 1, 2025 02:36
@renovate renovate bot force-pushed the renovate/vulnerability-updates branch from ea8b473 to b39ba81 Compare November 1, 2025 21:06
@renovate renovate bot enabled auto-merge (squash) November 2, 2025 01:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants