[Ruby on Rails] Bump Docker from 29.7.2 to 29.8.0 - #281
Merged
hayat01sh1da merged 1 commit intoSep 15, 2026
Merged
hayat01sh1da merged 1 commit into
hayat01sh1da merged 1 commit into
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
hayat01sh1da
deleted the
hayat01sh1da/no-issue-number/ruby-on-rails/bump-docker-from-29.7.2-to-29.8.0
branch
September 15, 2026 00:04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
1. Overview
This Pull Request bumps the documented Docker Engine version for the Ruby on Rails track from 29.7.2 to 29.8.0.
Unlike the previous bump, this is a single upstream release: 29.8.0 (2026-09-03) follows 29.7.2 (2026-08-05) with no patch releases in between, so the whole delta is one minor release.
Where 29.7.x was dominated by repairing image-pull regressions, 29.8.0 is a genuine feature release — it adds
--umaskfor containers, two hardening measures (a configurable default AppArmor profile template and anAF_VSOCKescape via 32-bitsocketcall(2)closed off), a large batch of Swarm service-discovery and gossip fixes, and it moves every bundled component forward, including a runc minor bump from v1.4.3 to v1.5.1.No CVE is fixed by this release; the security entries are hardening rather than advisories.
Docker Engine is a host-side tool here, used through
docker-compose build/docker-compose up; the change is confined to the environment documentation and nothing in the image definitions or the application moves.2. Key Changes & Differences
2-1. Docker Engine — 29.7.2 → 29.8.0
HostConfig.Umaskwith a--umask <octal>flag ondocker create/docker run, applied to the container process,execs and healthchecks (moby/moby#53463, docker/cli#7108); theawslogsdriver can now attach service names, environments and custom CloudWatch entity attributes to log entries (moby/moby#52632).AF_VSOCKsockets through the 32-bitsocketcall(2)multiplexer, via new AppArmor and SELinux policy rules (moby/moby#53551). Also: checkpoint IDs containing path separators are now rejected, so a checkpoint can no longer address a path outside the container checkpoint directory (moby/moby#53377).docker network inspectfailing to find a healthy Swarm network when a different Swarm network could not be allocated (moby/moby#53325).dockerdno longer hangs when thenftcommand emits enough stderr to fill its pipe (moby/moby#53517).DstNamein theirJoinresponse (moby/moby#52866); the namescontainerandcontainer:are now reserved, so they can no longer be used to create unusable networks (moby/moby#51973).docker image inspectreported a smaller size thandocker image ls, becauseGET /images/{name}/jsonomitted unpacked snapshot usage fromSize(moby/moby#53426); pulls were slowed by repeated registry authentication within a single pull (moby/moby#53497); expected image-signature identity misses were logged as errors (moby/moby#53495).dockerdnow falls back to the embedded containerd when no system containerd service is configured and containerd is not installed (moby/moby#53388) — the feature introduced experimentally in 29.7.0 now has an automatic path. containerd's v2 CRI plugins are also prevented from loading when CRI is disabled (moby/moby#53564).FROM --platform(moby/moby#53503); health checks no longer delayed excessively when the start interval is longer than the start period (moby/moby#52317); the container root directory/is no longer world-writable under thebtrfsstorage driver (moby/moby#53500); mount ordering indocker inspectand container listings is now consistent (moby/moby#53534); NRI container metadata now includes the resolved executable asargv[0]inContainer.Args(moby/moby#53423).DOCKER_HOSTor-Hnames an invalid host (docker/cli#7280);docker pssorts published ports numerically instead of lexicographically (docker/cli#7144); service mount order is preserved during forced updates, avoiding a spurious rollout on the next stack deploy (docker/cli#7227); plugin hook output such as the "What's next:" hint now prints after the command's error message rather than before it (docker/cli#6976).annotationfilter addeddocker ps/GET /containers/jsonaccept anannotationfilter to select containers by their annotations (moby/moby#53538).pestoport driver (DOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pesto; requires thepastanetwork driver, IPv4 only), and fixes--disable-host-loopbacknot being enforced for thepastadriver in rootless mode (moby/moby#53358).docker-compose build.docker/cli, not this repository.2-2. Files Updated in This Repository
ruby-on-rails/README.md3. Summary
ruby-on-rails/README.md(1 file changed, +1 / -1).--umask/HostConfig.Umaskfor containers, anannotationfilter on container listings, and CloudWatch entity attributes for theawslogsdriver; the security entries are hardening (configurable default AppArmor profile template,AF_VSOCK-via-32-bit-socketcall(2)blocked, checkpoint IDs with path separators rejected) with no CVE attached.dockerdhang whennftfills its stderr pipe — none of which this single-host application exercises, alongside containerd-image-store fixes that do affect everyday pulls anddocker image inspectsizes.Dockerfile,Dockerfile.production,docker-compose.ymlor application code is touched.4. References
🤖 Generated with Claude Code