Skip to content

Latest commit

 

History

37 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

BoringCache BuildKit

CI Verify BuildKit Image Sign BuildKit Image

This is the public distribution surface for the managed BuildKit image used by BoringCache.

The repository is intentionally thin. It tracks image tags, signing, verification, and release metadata for the managed image.

Report security issues privately through GitHub private vulnerability reporting.

Image

ghcr.io/boringcache/buildkit:v0.33.0-bc

Tags follow upstream BuildKit versions with a BoringCache patch suffix:

  • v0.33.0-bc.4 is upstream BuildKit v0.33.0 plus BoringCache patch release 4. It retains the managed type=boringcache layer-cache path, concurrent Bake upload coalescing, and opt-in cache-mount and tool-cache support. It also retains the tar extraction containment and dependency security fixes, and fixes a race between solver request cancellation and finalization. Cache-mount archives use stable, readable mount names across workers; archives under previous mount names are not selected by the new names. One daemon-wide limit admits one to four cache-mount archive worker processes from the BuildKit CPU budget and reports active, queued, peak, and wait metrics. Cache mounts can be addressed by their own namespace instead of the layer tag, and a namespaced mount is published merge-safely against the snapshot the publisher merged.
  • v0.33.0-bc is the managed stable channel for the latest signed BoringCache patch release on that upstream base.
  • latest moves only when BoringCache promotes a new managed BuildKit image.

This image is the BoringCache managed builder image used by the BoringCache CLI and boringcache/one.

Releases

Release tags correspond to managed BuildKit images for Linux amd64 and arm64.

Every exact release image is published with provenance/SBOM attestations, scanned for HIGH/CRITICAL vulnerabilities, and signed by digest with Sigstore/cosign. This public repository signs and verifies the exact image digest before promoting v0.33.0-bc and latest to that digest.

The signed Git release tag also records the image tag and immutable digest. The signing and verification workflows compare that signed metadata with GHCR before trusting the image.

Inspect the image:

docker buildx imagetools inspect ghcr.io/boringcache/buildkit:v0.33.0-bc.4

Verify the signature:

digest="$(
  docker buildx imagetools inspect \
    ghcr.io/boringcache/buildkit:v0.33.0-bc.4 \
    --format '{{json .Manifest.Digest}}' |
    jq -r .
)"

cosign verify \
  --certificate-identity 'https://github.com/boringcache/buildkit/.github/workflows/sign-image.yml@refs/heads/main' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  "ghcr.io/boringcache/buildkit@${digest}"

About

Managed BuildKit distribution for the BoringCache Docker build cache backend.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors