Skip to content

Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - #40

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-github.com-opencontainers-image-spec-vulnerability
Open

Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY]#40
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-github.com-opencontainers-image-spec-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 6, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/opencontainers/image-spec v1.0.1v1.0.2 age confidence

Clarify mediaType handling

GHSA-77vh-xpmg-72qh

More information

Details

Impact

In the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index.

Patches

The Image Specification will be updated to recommend that both manifest and index documents contain a mediaType field to identify the type of document.
Release v1.0.2 includes these updates.

Workarounds

Software attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields.

References

GHSA-mc8v-mgrf-8f4m

For more information

If you have any questions or comments about this advisory:

Severity

  • CVSS Score: 3.0 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

opencontainers/image-spec (github.com/opencontainers/image-spec)

v1.0.2

Compare Source

This release was voted on by the maintainers and PASSED (+5 -0 #​2), to mitigate the CVE-2021-41190 advisory.

This release is rebased directly on the prior tagged release (not including the commits that have occurred on main). Corresponding commits have been added to main, such that main is ready for a future next release.

R


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@stale

stale Bot commented Apr 26, 2025

Copy link
Copy Markdown

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale Bot added the stale label Apr 26, 2025
@renovate renovate Bot changed the title fix(deps): update module github.com/opencontainers/image-spec to v1.0.2 [security] fix(deps): update module github.com/opencontainers/image-spec to v1.0.2 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/go-github.com-opencontainers-image-spec-vulnerability branch March 27, 2026 02:49
@renovate renovate Bot changed the title fix(deps): update module github.com/opencontainers/image-spec to v1.0.2 [security] - autoclosed fix(deps): update module github.com/opencontainers/image-spec to v1.0.2 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/go-github.com-opencontainers-image-spec-vulnerability branch 2 times, most recently from 5dd8c1d to bf5bb9e Compare March 30, 2026 19:07
@renovate renovate Bot changed the title fix(deps): update module github.com/opencontainers/image-spec to v1.0.2 [security] Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Apr 8, 2026
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/go-github.com-opencontainers-image-spec-vulnerability branch 2 times, most recently from bf5bb9e to d32ace1 Compare April 27, 2026 20:06
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Jul 2, 2026
@renovate renovate Bot closed this Jul 2, 2026
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Jul 2, 2026
@renovate renovate Bot reopened this Jul 2, 2026
@renovate
renovate Bot force-pushed the renovate/go-github.com-opencontainers-image-spec-vulnerability branch 2 times, most recently from d32ace1 to 33b5386 Compare July 2, 2026 08:07
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Jul 7, 2026
@renovate renovate Bot closed this Jul 7, 2026
@renovate renovate Bot changed the title Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] - autoclosed Update module github.com/opencontainers/image-spec to v1.0.2 [SECURITY] Jul 8, 2026
@renovate renovate Bot reopened this Jul 8, 2026
@renovate
renovate Bot force-pushed the renovate/go-github.com-opencontainers-image-spec-vulnerability branch 2 times, most recently from 33b5386 to 23be49e Compare July 8, 2026 03:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants