1. Image: Docker Blog

    moby v25.0.18

    Docker BlogMoby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.

  2. Image: Docker Blog

    moby v29.8.2

    Docker BlogMoby v29.8.2 fixes a Docker Engine security vulnerability involving crafted OCI image indexes with deeply nested or widely fanned-out structures. The release note identifies the issue as CVE-2026-53493.

  3. moby v25.0.17

    Docker BlogMoby 25.0.17 fixes CVE-2026-41568, a symlink escape in mount destination creation, and adds archive decompression before data enters a container. The release includes changes to the Engine API as well as other fixes and enhancements.

  4. moby v29.6.2

    Docker BlogMoby 29.6.2 includes fixes for multiple security vulnerabilities affecting Docker Engine. One listed issue, CVE-2026-15793, involves Git source checkout from a bundle file that could lead to command execution.

  5. moby v29.6.1

    Docker BlogMoby 29.6.1 includes fixes for multiple security vulnerabilities affecting Docker Engine. One issue involves a malicious image supplying a malicious /etc/passwd- or /etc/group-style file.

  6. moby v29.5.1

    Docker BlogMoby 29.5.1 includes fixes for multiple security vulnerabilities affecting Docker Engine. One fix addresses CVE-2026-41567, a vulnerability in `docker cp` involving archive decompression.

  7. moby api/v1.55.0

    Docker BlogMoby API v1.55.0 adds per-device block I/O resource settings to the container-update endpoint. It also adds an image-attestations endpoint that can return in-toto statements, including SLSA provenance and SPDX SBOMs, with filtering and optional retrieval of statement bodies.

  8. moby v29.5.0

    Docker BlogMoby 29.5.0 makes `gvisor-tap-vsock` the default rootless network driver and removes `slirp4netns` from Docker packaging. The release notes say `gvisor-tap-vsock` should be preferred for rootless networking.

  9. moby v29.7.0

    Docker BlogMoby 29.7.0 adds an experimental `embedded-containerd` feature that runs containerd inside the daemon process rather than as a separately managed process. The change concerns Docker daemon architecture and is marked experimental.

  10. moby v29.8.0

    Docker BlogMoby 29.8.0 adds a `HostConfig.Umask` option and a `--umask` flag to `docker create` and `docker run`. The setting controls the umask for a container’s main process, execs, and healthchecks.

  11. Trust Docker for the agents you don’t

    Docker BlogDocker presents Cloud Sandboxes and the open Sandbox Kit specification, and commits to bringing Kits to the CNCF for neutral governance. The announcements concern safe environments for running coding agents and an open framework for those environments.

  12. moby client/0.5.0

    Docker BlogMoby client 0.5.0 adds a GET /images/{name}/attestations endpoint for retrieving in-toto attestation statements attached to an image. It supports platform selection and predicate filtering, and can return verbatim statement bodies with an optional query parameter.

  13. moby v29.7.1

    Docker BlogMoby 29.7.1 fixes a regression that prevented users from pulling images when their layers contain directories without explicit parent-directory entries.

  14. Image: Docker Blog

    moby client/v0.6.1

    Docker BlogMoby client 0.6.1 adds a `WithHTTPRequestHook` option, deprecates `WithResponseHook` in favor of `WithHTTPResponseHook`, and fixes response hooks not being called for hijacked HTTP connections. It also updates `postRaw` to use a consistent argument order.

  15. moby v29.6.0

    Docker BlogMoby 29.6.0 adds per-device block I/O resource settings to the container update API and adds an image attestations endpoint. The release notes also point to Docker CLI and Moby milestones for the full change lists.

  16. moby v29.7.2

    Docker BlogMoby 29.7.2 fixes a panic in docker service create and docker service update when the same environment variable is supplied more than once.

  17. moby api/v1.56.0

    Docker BlogMoby API 1.56.0 adds an annotation filter to `GET /containers/json`, supporting filtering by key or key and value. `POST /containers/create` also gains `HostConfig.Umask` support, which sets the Unix container's initial umask in its OCI process configuration.