Zum Inhalt springen

Distribution Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution Version 3.1.2 behebt Sicherheitslücke CVE-2026-85747

Das Patch-Release v3.1.2 der Distribution-Registry behebt eine Sicherheitslücke (CVE-2026-85747), indem der Registry-Client Manifest- und Blob-Inhalte gegen den angefragten Digest prüft, aktualisiert sicherheitsrelevante Abhängigkeiten wie gRPC, OpenTelemetry und golang.org/x/crypto und korrigiert mehrere Fehler bei S3- und Azure-Speicher, Paginierung und Uploads.

Welcome to the v3.1.2 release of registry!

This is a stable release

This patch release includes security fixes, storage and pagination fixes, and dependency updates.

Please try out the release binaries and report any issues at https://github.com/distribution/distribution/issues.

Notable Changes

  • Verify manifest and blob content against the requested digest in the registry client, protecting digest-pinned requests and pull-through caches (CVE-2026-85747 / GHSA-685w-q87j-wqw3).
  • Update security-sensitive dependencies, including gRPC, OpenTelemetry, and golang.org/x/crypto (#4912, #4963, #4965, #4968). The OTLP gRPC log exporter now honors TLS certificates configured through environment variables.
  • Fix S3 tag pagination and catalog listing when one name is a prefix of another (#4898, #4904), and return an empty tag array after the final pagination marker (#4931).
  • Fix Azure blob type migration and a concurrent append-write race (#4871, #4888).
  • Check the storage backend directly when writing blobs to avoid stale descriptor-cache entries (#4868).
  • Reject malformed manifest digests and out-of-order final upload chunks correctly (#4945), accept unknown total sizes in Content-Range (#4892), and preserve upstream error codes (#4917).
  • Stop the upload purger during registry shutdown (#4956).
  • Validate S3 redirect endpoints at driver initialization (#4870). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution (registry) Version 3.1.1

Version 3.1.1 behebt CVE-2026-41888, ergänzt Bounds-Checks in PurgeUploads, unterstützt S3 Express One Zone im S3-Storage-Driver und korrigiert den Tag-List-Endpoint sowie den Umgang mit zu großen n-Parametern im Proxy-Modus.

Welcome to the v3.1.1 release of registry!

This is a stable release

Please try out the release binaries and report any issues at https://github.com/distribution/distribution/issues.

Notable Changes

  • Fixes CVE-2026-41888
  • Bounds-check the file basename in PurgeUploads Walk callback
  • Add S3 Express One Zone support to the S3 storage driver (#4858)
  • Fix tag list endpoint in proxy mode (#4846)
  • Clamp oversized n query parameter in proxy mode instead of returning 400 (#4856)

See the full changelog below for the full list of changes.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.1.0: Sicherheitsfixes und Tag-Pagination

Version 3.1.0 behebt CVE-2026-35172 und CVE-2026-33540, ergänzt Unterstützung für Tag-Pagination, korrigiert die Default-Credentials im Azure-Storage-Provider und stellt auf go1.25 um, wobei go1.23 und go1.24 nicht mehr unterstützt werden.

Welcome to the v3.1.0 release of registry!

This is a stable release

Please try out the release binaries and report any issues at https://github.com/distribution/distribution/issues.

Notable Changes

  • Fixes CVE-2026-35172
  • Fixes CVE-2026-33540
  • Adds support for tag pagination (#4360, #4353)
  • Fixes default credentials in Azure storage provider (#4619)
  • Drops support for go1.23 and go1.24 and updates to go1.25

See the full changelog below for the full list of changes.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0: Erste stabile v3-Version

Version 3.0.0 ist die erste stabile v3-Version seit v2.8.3 und entfernt unter anderem die Storage-Treiber oss und swift, ersetzt docker/libtrust durch go-jose/go-jose und ändert den Standard-Konfigurationspfad auf /etc/distribution/config.yml.

Welcome to the v3.0.0 release of registry!

This is the first v3 stable release since v2.8.3 which is a culmination of years of hard work of the container community and registry maintainers!

If you are upgrading from v2.x and have never used any of the release candidates, please familiarise yourselves with the v2.x deprecations properly.

Deprecations

Changes since the last release candidate

Changes

<details><summary>7 commits</summary> <p> …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-rc.4: MD5-Prüfung für GCS, Azure-Retry-Fix

Der vierte Release Candidate aktiviert die MD5-Prüfung im GCS-Treiber, behebt den Retry-Mechanismus im Azure-Treiber, ergänzt eine Option zum Unterdrücken der GC-Ausgabe und korrigiert die Signaturalgorithmus-Konfiguration bei der Token-Authentifizierung.

Welcome to the v3.0.0-rc.4 release of registry!

This is the fourth stable release candidate!

See the changelog below for a full list of changes.

Notable changes

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-rc.3: Sicherheitsfix CVE-2025-24976

Der dritte Release Candidate behebt CVE-2025-24976 (einen Fehler bei der Token-Authentifizierung) und aktualisiert das Go-Modul golang.org/x/net sowie die Go-Version.

Welcome to the v3.0.0-rc.3 release of registry!

This is the third stable release candidate!

See the changelog below for a full list of changes.

Notable changes

What's Changed

Full Changelog: https://github.com/distribution/distribution/compare/v3.0.0-rc.2...v3.0.0-rc.3

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-rc.2: mTLS-Authentifizierung und Updates

Der zweite Release Candidate ergänzt Unterstützung für mTLS-Authentifizierung, aktualisiert Go OpenTelemetry sowie die Go-Laufzeit und das Alpine-Image.

Welcome to the v3.0.0-rc.2 release of registry!

This is the second release candidate of registry!

See the changelog below for a full list of changes.

Notable changes

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-rc.1: Erster Release Candidate

Der erste Release Candidate von v3 verbessert den S3-Treiber (HeadObject bei Stat, einheitliche Multipart-Chunk-Größe), baut Artefakte für linux/riscv64, behebt die Token-Verifikationskette und unterstützt im Proxy-Modus einen exec-basierten Credential Helper.

Welcome to the v3.0.0-rc.1 release of registry!

This is the the first release candidate of registry!

See the changelog below for full list of changes.

Deprecated

  • ManifestBuilder interface 3886
  • Versioned in favor of oci.Versioned 3887

Notable Changes

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-beta.1: Sparse Indexes und OpenTelemetry

Die Beta 1 bringt Unterstützung für Sparse Indexes, OpenTelemetry-Tracing, Redis-Cache-Clustering mit eigener TLS-Konfiguration sowie Verbesserungen bei Caching-Proxy und Garbage Collection und ändert den Standard-Konfigurationspfad auf /etc/distribution/config.yml.

Welcome to the 3.0.0-beta.1 release of registry!

This is the last major pre-release of registry.

See the changelog below for full list of changes.

Deprecated

  • the default configuration path has changed to /etc/distribution/config.yml

Notable Changes

  • Support for sparse indexes enables selective mirroring of platform images
  • Auth config now requires explicit declaration of token signing algorithms if using an unsupported signing algorithm
  • Support for OpenTelemetry tracing has been added
  • Redis cache now supports clustering and custom TLS config
  • Caching proxy bug fixes and minor improvements
  • Garbage collection fixes and improvements
  • Documentation has received several updates

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v3.0.0-alpha.1: Erste v3-Vorabversion

Die erste v3-Alpha bringt deutliche Performance-Verbesserungen bei allen Storage-Treibern, verschiebt das reference-Paket in ein eigenes Repository, ändert das Go-Modul auf distribution/distribution/v3 und entfernt unter anderem Image Manifest v2 Schema v1 sowie die Treiber oss und swift.

This is the first major release in years!

It's an accumulation of effort that's bringing major improvements in performance, security and general code quality!

See the abridged changelog below and the full release log here.

Deprecations

  • Image Manifest v2 Schema v1
  • oss and swift storage drivers
  • docker/libtrust has been replaced with go-jose/go-jose
  • reference package has been moved to a dedicated repository (see here)
  • client is no longer supported as a standalone package

Notable Changes

  • reference package has been moved to its own dedicated repository
  • Go module has changed from docker/distribution to distribution/distribution/v3
  • Major performance improvements across all supported storage drivers
  • Major dependencies updates (see the full list below)
  • Online documentation is available at https://distribution.github.io/distribution/

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.3

Version 2.8.3 ergänzt Unterstützung für Go-Build-Tags, setzt den Content-Type-Header im Registry-Client, parst Fehler nur bei JSON-Content-Type als JSON, schließt den HTTP-Request-Body im Handler nicht mehr und markiert das reference- und das digestset-Paket als veraltet.

What's Changed

New Contributors

Full Changelog: https://github.com/distribution/distribution/compare/v2.8.2...v2.8.3

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.2: Sicherheitsfixes und Fehlerbehebungen

Version 2.8.2 behebt CVE-2022-28391 und CVE-2023-2253, einen Panic im inmemory-Treiber sowie den Fehler mit der maximalen Layer-Größe von 10 GB im S3-Treiber durch Paginierung der Parts.

What's Changed

Full Changelog: https://github.com/distribution/distribution/compare/v2.8.1...v2.8.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.2-beta.2

Die Beta 2 von 2.8.2 behebt CVE-2022-28391 und CVE-2023-2253, einen Panic im inmemory-Treiber sowie den 10-GB-Layer-Größenfehler durch Paginierung der Parts und aktualisiert die Go-Version.

What's Changed

Full Changelog: https://github.com/distribution/distribution/compare/v2.8.1...v2.8.2-beta.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.2-beta.1 (Pre-Release ohne Artefakte)

Diese Vorabversion ohne Artefakte behebt unkontrollierte Speicherallokation bei /v2/_catalog, CVE-2022-28391 und einen Panic im inmemory-Treiber sowie den 10-GB-Layer-Größenfehler.

NOTE: This is a pre-release that does not contain any artifacts!

What's Changed

Full Changelog: https://github.com/distribution/distribution/compare/v2.8.1...v2.8.2-beta.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.1: Korrektur der Go-Modul-Probleme

Version 2.8.1 behebt die in v2.8.0 aufgetretenen Go-Modul-Probleme, wobei sich an den Binärdateien außer der aktualisierten Go-Laufzeit nichts ändert.

Welcome to the v2.8.1 release of registry!

The 2.8.1 registry release fixes the Go module issues that have popped up in the v2.8.0

There have been no changes made in the released binaries other than the bump of the Go runtime.

See the changelog below for a full list of changes.

CI

  • ci: use proper git ref for versioning #3595
  • Go: make Go version explicit and pin it to the latest 1.16 release #3604

Contributors

  • CrazyMax
  • Milos Gajdos

Changes

<details><summary>6 commits</summary> <p>
  • 96cc1fdb FIx typo
  • e744906f Update 2.8.1. release notes
  • Prepare for v2.8.1 release (#3596)
  • [2.8 backport] ci: use proper git ref for versioning (#3595)
    • 80acbdf0 ci: use proper git ref for versioning
</p> </details>

Dependency Changes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.0: Sicherheitsfix und kleinere Verbesserungen

Version 2.8.0 enthält einen Sicherheitsfix, schließt den io.ReadCloser des Storage-Treibers, entfernt den leeren Content-Type-Header, macht ipfilteredby in der CloudFront-Middleware optional und ergänzt reference.ParseDockerRef.

registry 2.8.0

Welcome to the v2.8.0 release of registry!

The 2.8.0 registry release has been a long time overdue. This is the first step towards the last 2.x release. No further active development will continue on 2.x branch. Security vulnerability patches to 2.x might be considered, but all active development will be focussed on v3 release due in 2022. This release includes a security vulnerability fix along with a few minor bug fixes and improvemnts in documentation and CI.

See changelog below for full list of changes.

Bugfixes

  • Close the io.ReadCloser from storage driver #3370
  • Remove empty Content-Type header #3297
  • Make ipfilteredby not required in cloudfront storage middleware #3088

Features

  • Add reference.ParseDockerRef utility function #3002

CI build

  • First draft of actions based ci #3347
  • Fix vndr and check #3001
  • Improve code quality by adding linter checks #3385

Documentation

  • Add redirect for old URL #3197 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Distribution v2.8.0-beta.1

Die Beta von 2.8.0 enthält einen Sicherheitsfix, schließt den io.ReadCloser des Storage-Treibers, entfernt den leeren Content-Type-Header, macht ipfilteredby in der CloudFront-Middleware optional und ergänzt reference.ParseDockerRef.

Welcome to the v2.8.0-beta.1 release of registry!

The 2.8.0 registry release has been a long time overdue. This is the first step towards the last 2.x release. No further active development will continue on 2.x branch. Security vulnerability patches to 2.x might be considered, but all active development will be focussed on v3 release due in 2022. This beta release includes a security vulnerability fix along with a few minor bug fixes and improvemnts in documentation and CI.

See changelog below for full list of changes.

Bugfixes

  • Close the io.ReadCloser from storage driver #3370
  • Remove empty Content-Type header #3297
  • Make ipfilteredby not required in cloudfront storage middleware #3088

Features

  • Add reference.ParseDockerRef utility function #3002

CI build

  • First draft of actions based ci #3347
  • Fix vndr and check #3001
  • Improve code quality by adding linter checks #3385

Documentation

  • Add redirect for old URL #3197 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Registry 2.7.1: Upgrade-Problem bei älteren Konfigurationen behoben

Version 2.7.1 setzt einen Standardwert für die neue Option autoredirect, um Startfehler beim Upgrade von Konfigurationen aus 2.6 oder älter zu vermeiden, und nimmt den GCS-Treiber in die Binary-Builds über das Dockerfile auf.

Welcome to the v2.7.1 release of registry!

The first patch release of 2.7 addresses an upgrade issue when using configurations from pre-2.7 registries. When upgrading from 2.6 or earlier use this patch release or newer to avoid a failure on startup from not updating the configuration file.

  • Set default for new autoredirect option
  • GCS driver is now included in binary builds using Dockerfile

Please try out the release binaries and report any issues at https://github.com/docker/distribution/issues.

Contributors

  • Derek McGowan
  • Ryan Abrams
  • David Wu

Changes

  • 2461543d Merge pull request #2824 from dmcgowan/update-version-file-2.7.1
  • 5b98226a Update version file for 2.7.1
  • 2eab12df Merge pull request #2805 from dmcgowan/release-2.7.1
  • 445ef068 Release notes for 2.7.1 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Registry 2.7.0: OCI-Unterstützung

Version 2.7.0 erlaubt Push und Pull von OCI-Images ohne Konvertierung, verlagert Spezifikationsänderungen zur OCI distribution-spec und bringt unter anderem Go 1.11, ein Multi-Stage-Dockerfile, Prometheus-Metriken und schnellere Health Checks.

Welcome to the v2.7.0 release of registry!

The 2.7 registry release has been a long time coming and represents both a long gap since the previous release and a renewed effort to release regularly. The maintainers were committed to get OCI support into the next release and thanks to much effort in the community that has been accomplished.

OCI Support

Push and Pull of OCI Images

The registry now allows pushing and pulling OCI images. OCI images will always be preserved exactly without conversion to older types. With this change, clients which implement OCI can feel comfortable creating OCI images as part of their container image build process.

Specification Donation

The Distribution specification which has had 4 years of review, implementation, and production use is now part of OCI. As part of that move, specification changes will no longer be accepted in the open source registry and should instead go to OCI's distribution-spec.

Bug Fixes and Improvements

General

  • Update Go version to 1.11
  • Switch to multi-stage Dockerfile
  • Validations enabled by default with new disabled config option
  • Optimize health check performance
  • Create separate permission for deleting objects in a repo
  • Fix storage driver error propagation for manifest GETs
  • Fix forwarded header resolution
  • Add prometheus metrics …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Distribution

Registry 2.7.0-rc.0: OCI-Unterstützung als Vorabversion

Die Vorabversion 2.7.0-rc.0 ermöglicht Push und Pull von OCI-Images ohne Konvertierung, verlagert Spezifikationsänderungen zur OCI distribution-spec und enthält zahlreiche Fehlerbehebungen und Verbesserungen.

Welcome to the v2.7.0-rc.0 release of registry! This is a pre-release of registry

The 2.7 registry release has been a long time coming and represents both a long gap since the previous release and a renewed effort to release regularly. The maintainers were committed to get OCI support into the next release and thanks to much effort in the community that has been accomplished.

OCI Support

Push and Pull of OCI Images

The registry now allows pushing and pulling OCI images. OCI images will always be preserved exactly without conversion to older types. With this change, clients which implement OCI can feel comfortable creating OCI images as part of their container image build process.

Specification Donation

The Distribution specification which has had 4 years of review, implementation, and production use is now part of OCI. As part of that move, specification changes will no longer be accepted in the open source registry and should instead go to OCI's distribution-spec.

Bug fixes

Many many fixes and improvements, see the change log below

Please try out the release binaries and report any issues at https://github.com/docker/distribution/issues.

Contributors

  • Derek McGowan
  • Stephen J Day
  • Olivier Gambier
  • Mike Brown
  • Aaron Lehmann
  • David Wu
  • Manish Tomar
  • Misty Stanley-Jones
  • Sargun Dhillon
  • fate-grand-order
  • Huu Nguyen
  • Yu Wang …

Originalquelle(öffnet in neuem Tab)Problem melden