Skip to content

[AUTO-CHERRYPICK] [High] Patch docker-buildx for CVE-2026-39833 - branch 3.0-dev#17641

Open
CBL-Mariner-Bot wants to merge 3 commits into
3.0-devfrom
cblmargh/cherry-pick-pr-17590-to-3.0-dev
Open

[AUTO-CHERRYPICK] [High] Patch docker-buildx for CVE-2026-39833 - branch 3.0-dev#17641
CBL-Mariner-Bot wants to merge 3 commits into
3.0-devfrom
cblmargh/cherry-pick-pr-17590-to-3.0-dev

Conversation

@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator

This is an auto-generated pull request to cherry-pick commit a983093 to 3.0-dev. Original PR: #17590
In case of no merge conflicts, the PR is merged without approval because it's an automated cherry-pick of an already approved PR.
In case of merge conflicts, an AI-based conflict resolver will attempt to resolve conflicts and might make mistakes. The reviewer must check AI's work before approving.

Co-authored-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com>
(cherry picked from commit a983093)
@CBL-Mariner-Bot CBL-Mariner-Bot added the Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch label Jun 8, 2026
@CBL-Mariner-Bot CBL-Mariner-Bot marked this pull request as ready for review June 8, 2026 14:16
@CBL-Mariner-Bot CBL-Mariner-Bot requested a review from a team as a code owner June 8, 2026 14:16
@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator Author

All conflicts resolved.

@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator Author

Auto Cherry-Pick SPEC Validation Summary

docker-buildx SPEC summary

Source (fasttrack) Target (3.0-dev) Resolved
Version 0.14.0 0.14.0 None
Release 15 14 15
Patches 26 25 26
Conflict Yes

⚠️ Validation issues:

  • Version-release None-15 is not higher than Source 0.14.0-15
  • Version-release None-15 is not higher than Target 0.14.0-14
  • Duplicate changelog entry for 0.14.0-11 (appears 2 times)
  • Changelog out of order: 0.14.0-11 appears before 0.14.0-13
  • Directive present in both Source and Target was dropped: BuildRequires: bash
  • Directive present in both Source and Target was dropped: BuildRequires: golang < 1.25

⚠️ Manual review required — validation found issues that may need correction.

The auto cherry-pick resolver dropped the preamble (Name, Version, License, Group, Vendor, BuildRequires) and reordered the changelog incorrectly (-11 above -13, -12 missing entirely). Since 3.0-dev had no unique changes vs fasttrack pre-merge, the correct merge result is identical to fasttrack/3.0's spec.

Flagged by cherrypick-health check.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch Automatic PR Packaging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants