COMMITS
May 27, 2026
D
build(deps): bump the actions group across 1 directory with 2 updates (#2327)
dependabot[bot] committed
T
fail with error when read exceeds maximum (#2328)
Tim Ramlot committed
May 21, 2026
D
build(deps): bump github.com/docker/cli (#2312)
dependabot[bot] committed
D
build(deps): bump the actions group across 1 directory with 2 updates (#2311)
dependabot[bot] committed
N
tarball: close layer readers during Write (#2308)
nandbhat committed
May 20, 2026
M
mutate: verify layer digests in Extract and Time (#2303)
Mo'men Elkhouli committed
M
gcrane: honor --platform flag in copy (#2307)
Muhammad Ahsan Gill committed
May 19, 2026
M
tarball: return error instead of panicking on missing rootfs.diff_ids (#2304)
Muhammad Ahsan Gill committed
May 18, 2026
J
Update go version to 1.26.3 (#2300)
Jared committed
M
transport: allow bearer realm at same host:port as registry (#2302)
Muhammad Ahsan Gill committed
M
transport: retry HTTP 429 (Too Many Requests) (#2301)
Muhammad Ahsan Gill committed
May 15, 2026
M
fix: preserve per-occurrence layer identity in Layers() (#2299)
Muhammad Ahsan Gill committed
D
fix(mutate): preserve config blob and layers for non-Docker OCI artifacts (#2286)
Dayna Blackwell committed
A
remote: block SSRF via private-IP Location headers in blob uploads (#2295)
Adil Burak Şen committed
May 14, 2026
E
remote: validate foreign layer URLs to prevent SSRF (fixes #2259) (#2293)
evilgensec committed
J
validate: skip non-layer layers (#2298)
Jason Hall committed
May 13, 2026
May 12, 2026
D
build(deps): bump the go-deps group across 3 directories with 6 updates (#2297)
dependabot[bot] committed
E
fix: limit HTTP response body reads to prevent OOM (#2296)
evilgensec committed
May 7, 2026
D
build(deps): bump aws-actions/configure-aws-credentials (#2289)
dependabot[bot] committed
May 5, 2026
S
experiments: remove deprecated support for estargz (#2288)
Sebastiaan van Stijn committed
April 30, 2026
D
test(mutate): add Extract round-trip test for filesystem object preservation (#2283)
Dayna Blackwell committed
M
transport: block unspecified IPs (0.0.0.0, ::) in validateRealmURL (#2285)
marwan9696 committed
April 29, 2026
D
pkg/name: only treat .localhost as non-HTTPS, not .local (#2281)
Dayna Blackwell committed
M
replace homedir.Dir with os.UserHomeDir (#2282)
Martin Kibera committed
April 28, 2026
D
build(deps): bump the go-deps group across 3 directories with 6 updates (#2280)
dependabot[bot] committed
D
build(deps): bump go.opentelemetry.io/otel from 1.36.0 to 1.41.0 (#2278)
dependabot[bot] committed
D
build(deps): bump goreleaser/goreleaser-action (#2273)
dependabot[bot] committed
A
crane/flatten: preserve image media type when flattening (#2267)
Ali Asghar committed