This is the public distribution surface for the managed BuildKit image used by BoringCache.
The repository is intentionally thin. It tracks image tags, signing, verification, and release metadata for the managed image.
Report security issues privately through GitHub private vulnerability reporting.
ghcr.io/boringcache/buildkit:v0.33.0-bc
Tags follow upstream BuildKit versions with a BoringCache patch suffix:
v0.33.0-bc.4is upstream BuildKitv0.33.0plus BoringCache patch release4. It retains the managedtype=boringcachelayer-cache path, concurrent Bake upload coalescing, and opt-in cache-mount and tool-cache support. It also retains the tar extraction containment and dependency security fixes, and fixes a race between solver request cancellation and finalization. Cache-mount archives use stable, readable mount names across workers; archives under previous mount names are not selected by the new names. One daemon-wide limit admits one to four cache-mount archive worker processes from the BuildKit CPU budget and reports active, queued, peak, and wait metrics. Cache mounts can be addressed by their own namespace instead of the layer tag, and a namespaced mount is published merge-safely against the snapshot the publisher merged.v0.33.0-bcis the managed stable channel for the latest signed BoringCache patch release on that upstream base.latestmoves only when BoringCache promotes a new managed BuildKit image.
This image is the BoringCache managed builder image used by the BoringCache CLI
and boringcache/one.
Release tags correspond to managed BuildKit images for Linux amd64 and
arm64.
Every exact release image is published with provenance/SBOM attestations,
scanned for HIGH/CRITICAL vulnerabilities, and signed by digest with
Sigstore/cosign. This public repository signs and verifies the exact image
digest before promoting v0.33.0-bc and latest to that digest.
The signed Git release tag also records the image tag and immutable digest. The signing and verification workflows compare that signed metadata with GHCR before trusting the image.
Inspect the image:
docker buildx imagetools inspect ghcr.io/boringcache/buildkit:v0.33.0-bc.4Verify the signature:
digest="$(
docker buildx imagetools inspect \
ghcr.io/boringcache/buildkit:v0.33.0-bc.4 \
--format '{{json .Manifest.Digest}}' |
jq -r .
)"
cosign verify \
--certificate-identity 'https://github.com/boringcache/buildkit/.github/workflows/sign-image.yml@refs/heads/main' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
"ghcr.io/boringcache/buildkit@${digest}"