Skip to content

build(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.2 in /native - #420

Merged
manusa merged 1 commit into
mainfrom
dependabot/go_modules/native/oras.land/oras-go/v2-2.6.2
Aug 31, 2026
Merged

build(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.2 in /native#420
manusa merged 1 commit into
mainfrom
dependabot/go_modules/native/oras.land/oras-go/v2-2.6.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oras.land/oras-go/v2 from 2.6.0 to 2.6.2.

Release notes

Sourced from oras.land/oras-go/v2's releases.

v2.6.2

This is a security patch release addressing advisories in the content and remote layers, plus additional hardening and bug fixes since v2.6.1.

Security Fixes

  • Resolve the hardlink (TypeLink) target before passing it to os.Link, preventing a crafted OCI artifact from hardlinking a file outside the extraction directory via the process CWD (#1232, GHSA-fxhp-mv3v-67qp / CVE-2026-50163)
  • Bound tag and referrer list pagination to prevent a malicious or misbehaving registry from advertising an endless page chain and forcing unbounded client requests (client-side DoS) (#1215)

Bug Fixes

  • Bound content.ReadAll allocation by actual content read rather than the descriptor size, correcting the over-broad 32 MiB cap introduced for GHSA-f36w-mj3v-6jqv so legitimate in-memory Push/FetchAll/FetchBytes are not rejected (#1223)

Other Changes

  • Bump golang.org/x/sync from 0.20.0 to 0.21.0 (#1208)

v2.6.1

This is a security patch release addressing five advisories in the authentication, remote, and content layers, plus accumulated bug fixes and maintenance since v2.6.0.

Security Fixes

  • Drop the Authorization header on cross-origin redirects to prevent origin credentials leaking to a redirect target on a different scheme/port of the same host (GHSA-vh4v-2xq2-g5cg)
  • Validate the bearer realm host before sending credentials to prevent credential exfiltration to an attacker-controlled token service, including TLS downgrades and IP-literal metadata endpoints; adds TrustedRealmHosts (GHSA-28r5-37g7-p6mp, GHSA-xf85-363p-868w)
  • Validate the Location host before blob upload to prevent credentials being forwarded to a cross-host upload endpoint (SSRF / CWE-918) (#1152, GHSA-jxpm-75mh-9fp7)
  • Reject descriptor sizes exceeding 32 MiB in content.ReadAll to prevent a crafted OCI layout from triggering a makeslice panic and crashing the process (#1153, GHSA-f36w-mj3v-6jqv)
  • Resolve symlinks when enforcing the workingDir write boundary in content/file, blocking writes that escape the boundary via a symlinked path component when AllowPathTraversalOnWrite=false

Bug Fixes

  • graph.Memory should use digest as map key (#1095)
  • Fix credentials key for the Docker registry-1 host (#966)
  • Support an empty credentials file (#959)

Other Changes

  • Add GitOps release workflow with goreleaser (#1161)
  • Shift the Go support window to [1.24, 1.25] (#991)
  • Run go modernize (#1005)
  • Sync CODEOWNERS and OWNERS.md from main to v2 (#1122)
  • Remove scripts reference from the Makefile (#960)
  • Bump golang.org/x/sync 0.14.0 → 0.20.0 (#971, #978, #1001, #1037, #1078, #1121)
  • Bump GitHub Actions: actions/checkout 4→5 (#989), actions/setup-go 5→6 (#998), actions/stale 9→10 (#997), github/codeql-action 3→4 (#1016)
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 19, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/native/oras.land/oras-go/v2-2.6.2 branch 2 times, most recently from 581ed7b to 96ed21c Compare August 31, 2026 08:22
manusa added a commit that referenced this pull request Aug 31, 2026
RegistryLogin built its registry client with plainHTTP but never
passed action.WithPlainHTTPLogin to the login action, so the flag
was silently ignored. This worked until oras-go v2.6.1, a security
release that stopped forwarding credentials across an HTTPS->HTTP
downgrade (GHSA-28r5-37g7-p6mp, GHSA-xf85-363p-868w) - the insecure
fallback had been carrying them.

The Go and Java OCI tests relied on that same fallback, so they now
declare plainHttp explicitly against the plain-HTTP test registry.

Also bumps GO_VERSION to 1.26.7: Go 1.25 is out of support and
helm.sh/helm/v3 3.21.4 requires go >= 1.26.0.

Unblocks #419 and #420.

Signed-off-by: Marc Nuri <marc@marcnuri.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@manusa

manusa commented Aug 31, 2026

Copy link
Copy Markdown
Owner

@dependabot recreate

Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) from 2.6.0 to 2.6.2.
- [Release notes](https://github.com/oras-project/oras-go/releases)
- [Changelog](https://github.com/oras-project/oras-go/blob/main/RELEASES.md)
- [Commits](oras-project/oras-go@v2.6.0...v2.6.2)

---
updated-dependencies:
- dependency-name: oras.land/oras-go/v2
  dependency-version: 2.6.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/native/oras.land/oras-go/v2-2.6.2 branch from 96ed21c to adc92e1 Compare August 31, 2026 09:24
@manusa
manusa merged commit 37c6b35 into main Aug 31, 2026
3 checks passed
@manusa
manusa deleted the dependabot/go_modules/native/oras.land/oras-go/v2-2.6.2 branch August 31, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant