# Docker Engine changelog > The container runtime that packages software into portable images. - Vendor: Docker - Category: Developer Tools - Official site: https://www.docker.com - Tracked by: What's New (https://whatsnew.fyi/product/docker) - Harvested from: GitHub (moby/moby) - Entries below: 12 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. ## Releases ### docker-v29.7.0-rc.1 — v29.7.0-rc.1 - Date: 2026-07-28 - Version: docker-v29.7.0-rc.1 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.7.0-rc.1 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.7.0-rc.1 - Labels: Pre-release - **added** — Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process - **added** — Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout - **fixed** — Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored in containerd image store - **fixed** — Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled - **fixed** — Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime - **fixed** — Fix a typo in the docker create --pull flag description - **changed** — Improve the error returned when a container hostname exceeds Linux's 64-byte limit - **changed** — Mount type image is no longer experimental - **fixed** — Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup - **fixed** — Suppress the No such container error when docker rm --force succeeds for a nonexistent container - **changed** — Update Go runtime to 1.26.5 - **changed** — Update BuildKit to v0.32.0-rc2 - **changed** — Update containerd to v2.3.3 - **changed** — Update runc to v1.4.3 - **fixed** — Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener - **fixed** — Keep the cgroup mount for containers with --net=host in rootless mode ##### 29.7.0-rc.1 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.7.0 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.7.0) - [moby/moby, 29.7.0 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.7.0) ###### New - Add an experimental `embedded-containerd` feature that runs containerd inside the daemon process instead of as a separate managed process. [moby/moby#52898](https://github.com/moby/moby/pull/52898) ###### Bug fixes and enhancements - Add the `default-stop-timeout` daemon option to configure the stop timeout assigned to containers without an explicit timeout. [moby/moby#53146](https://github.com/moby/moby/pull/53146) - containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. [moby/moby#53081](https://github.com/moby/moby/pull/53081) - To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0 - Fix `docker cp -a` using the wrong file owner when copying files into containers with user namespace remapping enabled. [moby/moby#53084](https://github.com/moby/moby/pull/53084) - Fix `docker stats` reporting all zeros for running Windows containers when using the containerd runtime. [moby/moby#53101](https://github.com/moby/moby/pull/53101) - Fix a typo in the `docker create --pull` flag description. [docker/cli#7103](https://github.com/docker/cli/pull/7103) - Improve the error returned when a container hostname exceeds Linux's 64-byte limit. [moby/moby#53121](https://github.com/moby/moby/pull/53121) - Mount type `image` is no longer experimental. [moby/moby#52998](https://github.com/moby/moby/pull/52998) - Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. [moby/moby#53115](https://github.com/moby/moby/pull/53115) - Suppress the “No such container” error when `docker rm --force` succeeds for a nonexistent container. [docker/cli#7110](https://github.com/docker/cli/pull/7110) - Update Go runtime to [1.26.5](https://go.dev/doc/devel/release#go1.26.5). [docker/cli#7087](https://github.com/docker/cli/pull/7087) ###### Packaging updates - Update BuildKit to [v0.32.0-rc2](https://github.com/moby/buildkit/releases/tag/v0.32.0-rc2). [moby/moby#53209](https://github.com/moby/moby/pull/53209) - Update containerd (static binaries) to [v2.3.3](https://github.com/containerd/containerd/releases/tag/v2.3.3). [moby/moby#53050](https://github.com/moby/moby/pull/53050) - Update runc (in static binaries) to [v1.4.3](https://github.com/opencontainers/runc/releases/tag/v1.4.3). [moby/moby#50960](https://github.com/moby/moby/pull/50960) ###### Networking - Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. [moby/moby#53022](https://github.com/moby/moby/pull/53022) ###### Rootless - Keep the cgroup mount for containers with `--net=host`. [moby/moby#52318](https://github.com/moby/moby/pull/52318) ### client/v0.5.1 - Date: 2026-07-27 - Version: client/v0.5.1 - Original notes: https://github.com/moby/moby/releases/tag/client/v0.5.1 - Permalink: https://whatsnew.fyi/product/docker/releases/client-v0.5.1 - **fixed** — ServiceCreate and ServiceUpdate: fix duplicate and unknown platforms - **fixed** — ServiceInspect and ContainerCommit: omit optional query args if not set ##### 0.5.1 ###### Changelog - client/pkg/jsonmessage: Display: fix godoc link. [moby/moby#53070](https://github.com/moby/moby/pull/53070) - client: ServiceCreate, ServiceUpdate: fix duplicate and 'unkown' platforms. [moby/moby#53012](https://github.com/moby/moby/pull/53012) - client: ServiceInspect, ContainerCommit: omit optional query args if not set. [moby/moby#53010](https://github.com/moby/moby/pull/53010) - golangci-lint: enable perfsprint linter. [moby/moby#53016](https://github.com/moby/moby/pull/53016) ### docker-v29.6.2 — v29.6.2 - Date: 2026-07-16 - Version: docker-v29.6.2 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.6.2 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.6.2 - **security** — Fix CVE-2026-15793: Git source checkout from a bundle file could lead to command injection - **security** — Fix CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic - **security** — Fix CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the /tmp directory - **security** — Fix CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources - **security** — Fix CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root - **changed** — Update containerd (static binaries) to v2.2.6 - **changed** — Update Go runtime to 1.26.5 - **changed** — Update RootlessKit to v3.0.2 ##### 29.6.2 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.6.2 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.6.2) - [moby/moby, 29.6.2 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.6.2) ###### Security This release includes fixes for multiple security vulnerabilities affecting Docker Engine. - **CVE-2026-15793**: Git source checkout from a bundle file could lead to command injection. [GHSA-hw3h-2gp9-cxpv](https://github.com/moby/buildkit/security/advisories/GHSA-hw3h-2gp9-cxpv) - **CVE-2026-15792**: Incorrect parameters sent from a frontend could cause a panic. [GHSA-qx3x-mv6r-52p6](https://github.com/moby/buildkit/security/advisories/GHSA-qx3x-mv6r-52p6) - **CVE-2026-15791**: An LLB file operation could be tricked into removing the contents of the `/tmp` directory. [GHSA-32pv-7hq5-qhwq](https://github.com/moby/buildkit/security/advisories/GHSA-32pv-7hq5-qhwq) - **CVE-2026-15789**: A malicious client could bypass destination directory validation when uploading local sources. [GHSA-g2h8-426c-7976](https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976) - **CVE-2026-15788**: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root. [GHSA-388v-wmr2-g2v2](https://github.com/moby/buildkit/security/advisories/GHSA-388v-wmr2-g2v2) ###### Packaging updates - Update containerd (static binaries) to [v2.2.6](https://github.com/containerd/containerd/releases/tag/v2.2.6). [moby/moby#53051](https://github.com/moby/moby/pull/53051) - Update Go runtime to [1.26.5](https://go.dev/doc/devel/release#go1.26.5). [moby/moby#53027](https://github.com/moby/moby/pull/53027) ###### Rootless - Update RootlessKit to [v3.0.2](https://github.com/rootless-containers/rootlesskit/releases/tag/v3.0.2). [moby/moby#53054](https://github.com/moby/moby/pull/53054) ### docker-v29.6.1 — v29.6.1 - Date: 2026-06-26 - Version: docker-v29.6.1 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.6.1 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.6.1 - **security** — Fix a vulnerability where a malicious image could supply a malicious /etc/passwd or /etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions - **security** — Fix a vulnerability where a custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement - **changed** — Update containerd (static binaries) to v2.2.5 - **changed** — Update BuildKit to v0.31.1 ##### 29.6.1 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.6.1 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.6.1) - [moby/moby, 29.6.1 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.6.1) ###### Security This release includes fixes for multiple security vulnerabilities affecting Docker Engine. - A malicious image could supply a malicious `/etc/passwd` or `/etc/group`-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. [GHSA-mjcv-p78q-w5fw](https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw), [GHSA-jpcc-p29g-p8mq](https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-72x6-4j93-7w86](https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86) - A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers. [GHSA-7236-3392-c5c6](https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6) ###### Bug fixes and enhancements - Update containerd (static binaries) to [v2.2.5](https://github.com/containerd/containerd/releases/tag/v2.2.5). [moby/moby#52950](https://github.com/moby/moby/pull/52950) ###### Packaging updates - Update BuildKit to [v0.31.1](https://github.com/moby/buildkit/releases/tag/v0.31.1). [moby/moby#52954](https://github.com/moby/moby/pull/52954) ### docker-v29.6.0 — v29.6.0 - Date: 2026-06-18 - Version: docker-v29.6.0 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.6.0 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.6.0 - **added** — POST /containers/{id}/update endpoint now supports per-device blkio resource settings - **added** — Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements such as SLSA provenance and SPDX SBOM attached to an image, with support for optional platform selection, predicate type filtering, and statement query parameter - **fixed** — docker image push now respects NO_COLOR - **fixed** — Fix docker system prune with containerd image store to include unpacked image data when reporting reclaimed space - **fixed** — Fix docker system df image size reporting to count only snapshots directly used by images - **fixed** — Fix registry authentication failures during worker image pulls being reported as misleading 'No such image' error - **fixed** — Fix default BuildKit GC policy to prune reproducible cache types as intended - **fixed** — Fix explicit file modes being filtered by the daemon umask, including COPY --chmod permissions - **fixed** — Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests - **added** — The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin - **changed** — Update runc in static binaries to v1.3.6 - **changed** — Update BuildKit to v0.31.0 - **changed** — Allow the nftables firewall mode to be used with a daemon linked against libnftables when the nft command is not installed on the system - **fixed** — Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports - **fixed** — Fix a race condition in overlay network bulk sync that caused approximately 30 second DNS resolution delays on newly joined swarm nodes - **changed** — Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the nft command instead of linking against libnftables - **fixed** — Silence the spurious warning 'IPv4 forwarding is disabled' in rootless mode - **deprecated** — The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified ##### 29.6.0 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.6.0 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.6.0) - [moby/moby, 29.6.0 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.6.0) ###### New - `POST /containers/{id}/update` now supports per-device blkio resource settings. [moby/moby#52651](https://github.com/moby/moby/pull/52651) - Add `GET /images/{name}/attestations` endpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement query parameter for verbatim statement bodies. ###### Bug fixes and enhancements - `docker image push` now respects `NO_COLOR`. [docker/cli#6957](https://github.com/docker/cli/pull/6957) - containerd image store: Fix `docker system prune` to include unpacked image data when reporting reclaimed space. [moby/moby#52905](https://github.com/moby/moby/pull/52905) - Fix `docker system df` image size reporting to count only snapshots directly used by images. [moby/moby#52901](https://github.com/moby/moby/pull/52901) - Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. [moby/moby#52698](https://github.com/moby/moby/pull/52698) - Fix default BuildKit GC policy to prune reproducible cache types as intended. [moby/moby#52814](https://github.com/moby/moby/pull/52814) - Fix explicit file modes being filtered by the daemon umask, including `COPY --chmod` permissions. [moby/moby#52892](https://github.com/moby/moby/pull/52892) - Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests. [moby/moby#52773](https://github.com/moby/moby/pull/52773) - The `--password` flag on `docker login` now accepts `-` to pass the password through STDIN as alternative to `--password-stdin`. [docker/cli#7029](https://github.com/docker/cli/pull/7029) ###### Packaging updates - Update runc (in static binaries) to [v1.3.6](https://github.com/opencontainers/runc/releases/tag/v1.3.6). [moby/moby#52883](https://github.com/moby/moby/pull/52883) - Update BuildKit to [v0.31.0](https://github.com/moby/buildkit/releases/tag/v0.31.0). [moby/moby#52904](https://github.com/moby/moby/pull/52904) ###### Networking - Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the `nft` command is not installed on the system. [moby/moby#52820](https://github.com/moby/moby/pull/52820) - Don't publish container ports on host ports listed in `net.ipv4.ip_local_reserved_ports` when dynamically allocating ports. [moby/moby#52818](https://github.com/moby/moby/pull/52818) - Fix a race condition in overlay network bulk sync that caused ~30s DNS resolution delays on newly joined swarm nodes. [moby/moby#52862](https://github.com/moby/moby/pull/52862) - Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the `nft` command instead. Users building dockerd from source can opt into linking against libnftables by building with the `libnftables` build tag. [moby/moby#52886](https://github.com/moby/moby/pull/52886) ###### Rootless - Silence the spurious warning "IPv4 forwarding is disabled". [moby/moby#52742](https://github.com/moby/moby/pull/52742) ###### Deprecations - The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. [moby/moby#47427](https://github.com/moby/moby/pull/47427) ### client/v0.5.0 — client/0.5.0 - Date: 2026-06-18 - Version: client/v0.5.0 - Original notes: https://github.com/moby/moby/releases/tag/client/v0.5.0 - Permalink: https://whatsnew.fyi/product/docker/releases/client-v0.5.0 - **added** — New GET /images/{name}/attestations endpoint that returns in-toto attestation statements attached to an image, with optional platform selection, predicate type filtering, and statement query parameter for retrieving verbatim statement bodies ##### 0.5.0 ###### Changelog - The new `GET /images/{name}/attestations` endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in `statement` query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. [moby/moby#52636](https://github.com/moby/moby/pull/52636) ### api/v1.55.0 - Date: 2026-06-18 - Version: api/v1.55.0 - Original notes: https://github.com/moby/moby/releases/tag/api/v1.55.0 - Permalink: https://whatsnew.fyi/product/docker/releases/api-v1.55.0 - **added** — POST /containers/{id}/update now supports per-device blkio resource settings - **added** — Add GET /images/{name}/attestations endpoint to return in-toto attestation statements attached to an image with optional platform selection, predicate type filtering, and statement query parameter ##### 1.55.0 ###### Changelog - `POST /containers/{id}/update` now supports per-device blkio resource settingss. [moby/moby#52651](https://github.com/moby/moby/pull/52651) - The new `GET /images/{name}/attestations` endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in `statement` query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. [moby/moby#52636](https://github.com/moby/moby/pull/52636) - docs: clarify swarm join required fields. [moby/moby#52763](https://github.com/moby/moby/pull/52763) ### docker-v29.6.0-rc.1 — v29.6.0-rc.1 - Date: 2026-06-12 - Version: docker-v29.6.0-rc.1 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.6.0-rc.1 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.6.0-rc.1 - Labels: Pre-release - **added** — Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements such as SLSA provenance and SPDX SBOM attached to an image, with optional platform selection, predicate type filtering, and statement query parameter - **changed** — docker image push now respects NO_COLOR - **changed** — The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin - **changed** — Allow nftables firewall mode to be used with a daemon linked against libnftables when the nft command is not installed - **changed** — Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports - **fixed** — Fix a bug where registry authentication failures during worker image pulls were reported as a misleading "No such image" error - **fixed** — Fix default BuildKit GC policy to prune reproducible cache types as intended - **fixed** — Silence the spurious warning "IPv4 forwarding is disabled" in rootless mode - **deprecated** — The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified ##### 29.6.0-rc.1 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.6.0 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.6.0) - [moby/moby, 29.6.0 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.6.0) ###### New - Add `GET /images/{name}/attestations` endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in `statement` query parameter for retrieving the verbatim statement bodies. Clients can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. [moby/moby#52636](https://github.com/moby/moby/pull/52636) ###### Bug fixes and enhancements - `docker image push` now respects `NO_COLOR`. [docker/cli#6957](https://github.com/docker/cli/pull/6957) - Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. [moby/moby#52698](https://github.com/moby/moby/pull/52698) - Fix default BuildKit GC policy to prune reproducible cache types as intended. [moby/moby#52814](https://github.com/moby/moby/pull/52814) - The `--password` flag on `docker login` now accepts `-` to pass the password through STDIN as alternative to `--password-stdin`. [docker/cli#7029](https://github.com/docker/cli/pull/7029) ###### Packaging updates - Update BuildKit to [v0.31.0-rc2](https://github.com/moby/buildkit/releases/tag/v0.31.0-rc2). [moby/moby#52835](https://github.com/moby/moby/pull/52835) ###### Networking - Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the `nft` command is not installed on the system. [moby/moby#52820](https://github.com/moby/moby/pull/52820) - Don't publish container ports on host ports listed in `net.ipv4.ip_local_reserved_ports` when dynamically allocating ports. [moby/moby#52818](https://github.com/moby/moby/pull/52818) ###### Rootless - Silence the spurious warning "IPv4 forwarding is disabled". [moby/moby#52742](https://github.com/moby/moby/pull/52742) ###### Deprecations - The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. [moby/moby#47427](https://github.com/moby/moby/pull/47427) ### client/v0.5.0-rc.1 - Date: 2026-06-12 - Version: client/v0.5.0-rc.1 - Original notes: https://github.com/moby/moby/releases/tag/client/v0.5.0-rc.1 - Permalink: https://whatsnew.fyi/product/docker/releases/client-v0.5.0-rc.1 - Labels: Pre-release - **added** — Add new GET /images/{name}/attestations endpoint that returns in-toto attestation statements attached to an image, with optional platform selection, predicate type filtering, and statement query parameter for retrieving verbatim statement bodies ##### 0.5.0-rc.1 ###### Changelog - The new `GET /images/{name}/attestations` endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in `statement` query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. [moby/moby#52636](https://github.com/moby/moby/pull/52636) ### api/v1.55.0-rc.1 - Date: 2026-06-12 - Version: api/v1.55.0-rc.1 - Original notes: https://github.com/moby/moby/releases/tag/api/v1.55.0-rc.1 - Permalink: https://whatsnew.fyi/product/docker/releases/api-v1.55.0-rc.1 - Labels: Pre-release - **added** — POST /containers/{id}/update endpoint now supports per-device blkio resource settings - **added** — New GET /images/{name}/attestations endpoint returns in-toto attestation statements attached to an image with optional platform selection, predicate type filtering, and statement query parameter for retrieving verbatim statement bodies ##### 1.55.0-rc.1 ###### Changelog - `POST /containers/{id}/update` now supports per-device blkio resource settingss. [moby/moby#52651](https://github.com/moby/moby/pull/52651) - The new `GET /images/{name}/attestations` endpoint returns in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image, with optional platform selection, predicate type filtering, and an opt-in `statement` query parameter for retrieving the verbatim statement bodies. Tools can now retrieve attestation metadata and content directly from the daemon instead of performing additional registry round-trips. [moby/moby#52636](https://github.com/moby/moby/pull/52636) - docs: clarify swarm join required fields. [moby/moby#52763](https://github.com/moby/moby/pull/52763) ### docker-v29.5.3 — v29.5.3 - Date: 2026-06-03 - Version: docker-v29.5.3 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.5.3 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.5.3 - **fixed** — Reduce docker system df errors when images are pruned at the same time with the containerd image store - **changed** — Update containerd (static binaries only) to v2.2.4 - **changed** — Update Go runtime to 1.26.4 - **changed** — Update RootlessKit to v3.0.1 - **fixed** — Fix AWS IMDS access with gvisor-tap-vsock and UDP port forwarding for non-loopback clients - **fixed** — Fix installation of plugins that require host networking ##### 29.5.3 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.5.3 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.5.3) - [moby/moby, 29.5.3 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.5.3) ###### Bug fixes and enhancements - Reduce `docker system df` errors when images are pruned at the same time with the containerd image store. [moby/moby#52672](https://github.com/moby/moby/pull/52672) ###### Packaging updates - Update containerd (static binaries only) to [v2.2.4](https://github.com/containerd/containerd/releases/tag/v2.2.4). [moby/moby#52683](https://github.com/moby/moby/pull/52683) - Update Go runtime to [1.26.4](https://go.dev/doc/devel/release#go1.26.4). [moby/moby#52753](https://github.com/moby/moby/pull/52753), [docker/cli#7025](https://github.com/docker/cli/pull/7025) - Update RootlessKit to [v3.0.1](https://github.com/rootless-containers/rootlesskit/releases/tag/v3.0.1). [moby/moby#52710](https://github.com/moby/moby/pull/52710) ###### Rootless - Fix AWS IMDS access with `gvisor-tap-vsock` and UDP port forwarding for non-loopback clients. [moby/moby#52710](https://github.com/moby/moby/pull/52710) - Fix installation of plugins that require host networking. [moby/moby#52735](https://github.com/moby/moby/pull/52735) ### docker-v29.5.2 — v29.5.2 - Date: 2026-05-20 - Version: docker-v29.5.2 - Original notes: https://github.com/moby/moby/releases/tag/docker-v29.5.2 - Permalink: https://whatsnew.fyi/product/docker/releases/docker-v29.5.2 - **fixed** — Fix docker cp failing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink ##### 29.5.2 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: - [docker/cli, 29.5.2 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.5.2) - [moby/moby, 29.5.2 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.5.2) ###### Bug fixes and enhancements - Fix `docker cp` failing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink (e.g. `/var/run -> /run`). [moby/moby#52655](https://github.com/moby/moby/pull/52655)