Please do not open a public issue or pull request for a potential security vulnerability.
Email security@boringcache.com or use GitHub's private vulnerability reporting for this repository:
https://github.com/boringcache/buildkit/security/advisories/new
Include the image tag or digest, the workflow/run link if relevant, the impact you believe is possible, and enough reproduction detail for us to verify the report. Do not include live credentials, customer data, or secrets.
This repository supports the current promoted BoringCache managed BuildKit image tags:
ghcr.io/boringcache/buildkit:latestghcr.io/boringcache/buildkit:v0.33.0-bcghcr.io/boringcache/buildkit:v0.33.0-bc.2
Older tags may be superseded by a new promoted image instead of receiving a backport.
Reports for this repository should cover the BoringCache managed BuildKit image distribution surface: image publication, signing, verification, release metadata, attestations, and vulnerabilities present in the published image.
If a report concerns upstream BuildKit itself and is not specific to the BoringCache managed image, please use the upstream BuildKit security process as well.
For service, website, account, Artifact, Registry, or other product reports, use security@boringcache.com or the BoringCache security policy.