Atomic-reactor

Latest version: v1.6.26.3

Safety actively analyzes 701583 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 4 of 5

1.6.16

Build JSON API changes
- `koji_promote` will use first unique_image as the pull spec if no primary_images have been set.
- `pulp_sync` will iterate through all images (unique and primary) to determine which pulp repositories must be published.
- `tag_by_labels` takes an additional, optional, parameter `unique_tag_only`. When set, image will only be tagged with unique tag, and not primary tags. Defaults to False.

Bug Fixes

None

Improvements
- Added missing dependencies for tests to spec file
- `koji_promote` will log koji task ID on failure.

1.6.15

Build JSON API changes
- New `delete_from_registry` plugin

Bug Fixes
- errors during 'docker build' phase are no longer suppressed

Improvements

None

1.6.14

Build JSON API changes
- `add_filesystem` plugin now expects the repo URL to be a yum repo file whose baseurl configuration item holds the URL to the install tree

Bug fixes

None

Improvements

None

1.6.13

Build JSON API changes

None

Bug fixes
- `tag_from_config` plugin no longer accepts additional tags containing hyphens

Improvements
- `koji_promote` plugin now includes 'tags' field in build output metadata

1.6.12

Build JSON API changes

None

Bug fixes
- intermediate docker registry links are not set in annotations if `pulp_sync` plugin is enabled
- `bump_release` plugin now takes component version into consideration

Improvements
- API documentation was updated
- Custom repo urls are supported for base images

1.6.11

Build JSON API changes
- pulp_sync: no longer accepts username and password parameters
- pulp_sync: now accepts optional registry_secret_path, insecure_registry, and pulp_repo_prefix parameters, allowing sync from V2 registry that requires authentication -- note: this requires dockpulp > 1.22
- tag_and_push: registries can now include a "secret" key in their description, which is the path to the Kubernetes dockercfg secret required for pushing to the registry
- bump_release: no longer accepts git_ref, author_name, author_email, committer_name, committer_email, commit_message, or push_url
- bump_release: now requires parameters target (Koji build target) and hub (Koji hub URL)
- tag_from_config: new available plugin

Bug fixes
- plugins whose constructors fail are now handled correctly

Improvements
- pulp_sync is now able to ask Pulp to sync from a V2 registry that requires authentication
- bump_release now uses a Koji hub to discover the latest release of the component and uses that to provide a value for the Release label if missing
- new tag_from_config plugin to add additional tags to the image

Page 4 of 5

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.