Overview

Request 1086800 accepted

- update to 2.8.2 (bsc#1207705, CVE-2023-2253, bsc#1210428):
* Revert registry/client: set `Accept: identity` header when
getting layers
* Parse `http` forbidden as denied
* Fix CVE-2023-2253 runaway allocation on /v2/_catalog
* Fix panic in inmemory driver
* update to go1.19.9
* Add code to handle pagination of parts. Fixes max layer size
of 10GB bug
* Dockerfile: fix filenames of artifacts
- drop aws-sdk-1.42.27-update.patch (no longer wanted)
- drop 0001-Fix-runaway-allocation-on-v2-_catalog.patch (upstream)

- refresh 0001-Fix-runaway-allocation-on-v2-_catalog.patch to
be more compatible with invalid pagination requests (CVE-2023-2253, bsc#1207705)␣

- add 0001-Fix-runaway-allocation-on-v2-_catalog.patch (CVE-2023-2253, bsc#1207705)

Loading...
Request History
Dirk Mueller's avatar

dirkmueller created request

- update to 2.8.2 (bsc#1207705, CVE-2023-2253, bsc#1210428):
* Revert registry/client: set `Accept: identity` header when
getting layers
* Parse `http` forbidden as denied
* Fix CVE-2023-2253 runaway allocation on /v2/_catalog
* Fix panic in inmemory driver
* update to go1.19.9
* Add code to handle pagination of parts. Fixes max layer size
of 10GB bug
* Dockerfile: fix filenames of artifacts
- drop aws-sdk-1.42.27-update.patch (no longer wanted)
- drop 0001-Fix-runaway-allocation-on-v2-_catalog.patch (upstream)

- refresh 0001-Fix-runaway-allocation-on-v2-_catalog.patch to
be more compatible with invalid pagination requests (CVE-2023-2253, bsc#1207705)␣

- add 0001-Fix-runaway-allocation-on-v2-_catalog.patch (CVE-2023-2253, bsc#1207705)


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Staging Bot's avatar

staging-bot added as a reviewer

Being evaluated by staging project "openSUSE:Factory:Staging:adi:59"


Staging Bot's avatar

staging-bot accepted review

Picked "openSUSE:Factory:Staging:adi:59"


Dominique Leuenberger's avatar

dimstar accepted review


Dominique Leuenberger's avatar

dimstar_suse accepted review

Staging Project openSUSE:Factory:Staging:adi:59 got accepted.


Dominique Leuenberger's avatar

dimstar_suse approved review

Staging Project openSUSE:Factory:Staging:adi:59 got accepted.


Dominique Leuenberger's avatar

dimstar_suse accepted request

Staging Project openSUSE:Factory:Staging:adi:59 got accepted.

openSUSE Build Service is sponsored by