Pulp-container

Latest version: v2.22.0

Safety actively analyzes 685670 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 5 of 23

2.16.3

Not secure
Bugfixes

- Added `application/vnd.docker.distribution.manifest.v1+prettyjws` to the list of accepted
media types retrieved from a remote registry.
[1444](https://github.com/pulp/pulp_container/issues/1444)

---

2.16.2

Not secure
No significant changes.

---

2.16.1

Not secure
No significant changes.

---

2.16.0

Not secure
Features

- Added OCI artifact support for Helm charts.
[464](https://github.com/pulp/pulp_container/issues/464)
- Added support to serve cosign signatures, SBOMs, and attestations.
[1165](https://github.com/pulp/pulp_container/issues/1165)
- Added support to mirror cosign signatures, SBOMs and attestations.
[1166](https://github.com/pulp/pulp_container/issues/1166)
- Added suport to push cosign signatures, attestations or SBOMs to Pulp Registry.
[1167](https://github.com/pulp/pulp_container/issues/1167)
- Added support for monolithic upload.
[1219](https://github.com/pulp/pulp_container/issues/1219)
- Enabled Pulp registry to support by default some well-known OCI types.
[1232](https://github.com/pulp/pulp_container/issues/1232)
- Added `ADDITIONAL_OCI_ARTIFACT_TYPES` setting to make the list of supported OCI artifact types
configurable.
[1233](https://github.com/pulp/pulp_container/issues/1233)
- Added support for Flatpak index endpoints.
[1315](https://github.com/pulp/pulp_container/issues/1315)

Bugfixes

- Taught the Container Registry to accept docker schema2 sub-manifest types in OCI index.
[1231](https://github.com/pulp/pulp_container/issues/1231)
- Fixed a security issue that allowed users without sufficient permissions to mount blobs.
[1286](https://github.com/pulp/pulp_container/issues/1286)
- Ensured downloader during the repair task contains accept headers for the
manifests to download.
[1303](https://github.com/pulp/pulp_container/issues/1303)
- Disabled TLS validation, if opted out in a remote, when syncing signatures.
[1305](https://github.com/pulp/pulp_container/issues/1305)
- Fixed pulp-to-pulp failing sync with `406 Not Acceptable`.
[1329](https://github.com/pulp/pulp_container/issues/1329)

Improved Documentation

- Took the import/export feature out of tech preview.
[1236](https://github.com/pulp/pulp_container/issues/1236)

---

2.15.6

Not secure
Bugfixes

- Fixed sync failure due to ignored certs during registry signature extentions API check.
[1552](https://github.com/pulp/pulp_container/issues/1552)

---

2.15.5

Not secure
Deprecations and Removals

- Removed the optional "kid" parameter stored inside the signatures' payload generated during
docker manifest v2 schema 1 conversion. This change also removes the `ecdsa` dependency,
which is vulnerable to Minevra timing attacks.
[1485](https://github.com/pulp/pulp_container/issues/1485)

---

Page 5 of 23

© 2024 Safety CLI Cybersecurity Inc. All Rights Reserved.