Commit Graph

  • c18a4a975d fix(authz): metrics: deny authenticated users not in ACL even with anonymous read (#4131) main Vishwas Rajashekar 2026-06-14 19:59:22 +05:30
  • 6a143cadfa feat: config: validate metrics config (#4130) Vishwas Rajashekar 2026-06-14 18:30:03 +05:30
  • 34f1a10030 build(deps): bump sigs.k8s.io/controller-runtime dependabot/go_modules/go-dependencies-c00f186a85 dependabot[bot] 2026-06-12 00:25:33 +00:00
  • 225e2fb96d chore: fix dependabot alerts (#4126) Ramkumar Chinchani 2026-06-11 17:22:15 -07:00
  • a675ac96b9 fix(storage): treat dedupe-candidate cache miss as no candidates, not an error (#4122) Janko Thyson 2026-06-11 09:24:52 +02:00
  • 66e9cfb01f feat(metrics): anonymous access when enabled in accessControl config (#4110) uaggarwa 2026-06-10 03:19:28 -04:00
  • e20c08c96d sync: cache streaming index sub-manifests copilot/pr-3778-platform-submanifest copilot-swe-agent[bot] 2026-06-09 21:50:49 +00:00
  • 936a60d4f7 feat(storage): add a common blobstore to store all blobs (#3906) refactor/storage Ramkumar Chinchani 2026-06-09 12:13:44 -07:00
  • 273b15364b metadb: add optional fast restart path that skips storage walk when (version + commit + storage config) matches metaDB stamp (#4026) copilot/security-analysis-authentication-authorization copilot/fix-deprecation-warnings copilot/4114-correctness-and-security-review Jacob McSwain 2026-06-09 12:47:20 -05:00
  • d480380ef7 ci: Update GH runner labels (#4121) Andrei Aaron 2026-06-09 12:46:21 +03:00
  • 1dc5c8e51d fix: skip DynamoDB table creation when tables exist (#4120) Andrei Aaron 2026-06-08 04:56:30 +03:00
  • 879fcee3c3 feat: enhance config sanitization to mask sensitive keys in storage a… (#4119) Ramkumar Chinchani 2026-06-06 22:18:20 -07:00
  • 3ff9d6ddc1 fix(cve): prefer cve.org links for AVD references (#4107) copilot/pr-4114-review-security charles-openclaw 2026-06-06 04:10:37 +00:00
  • 60f719400e chore: optimize sanitize field normalization copilot/fix-log-leaks-in-configuration-settings copilot-swe-agent[bot] 2026-06-05 18:48:43 +00:00
  • cea72a4c08 fix: redact sensitive values in sanitized startup config logs copilot-swe-agent[bot] 2026-06-05 18:45:18 +00:00
  • 44894652e3 Initial plan copilot-swe-agent[bot] 2026-06-05 18:30:58 +00:00
  • e8c38a5639 chore: fix dependabot alerts (#4113) Ramkumar Chinchani 2026-06-05 05:12:32 -07:00
  • 2261151508 docs: fix alongside spelling in search docs (#4095) yosinn1-blip 2026-06-01 04:53:06 +09:00
  • 98f220f1cf Tighten signature lint cleanup check and rerun tests copilot/feat-enforce-signatures-on-images copilot-swe-agent[bot] 2026-05-29 17:30:24 +00:00
  • 83adc3c890 Implement signature-lint cleanup and fix lint formatting copilot-swe-agent[bot] 2026-05-29 17:25:42 +00:00
  • c8ddde1794 Add wildcard mandatory signatures unit and blackbox tests copilot-swe-agent[bot] 2026-05-29 16:50:03 +00:00
  • 648408a676 Plan wildcard lint test coverage copilot-swe-agent[bot] 2026-05-29 16:48:35 +00:00
  • 3dba57f642 Document wildcard mandatorySignatures example copilot-swe-agent[bot] 2026-05-29 16:02:24 +00:00
  • c024d0e04e Accept wildcard mandatory signature repositories copilot-swe-agent[bot] 2026-05-29 15:58:51 +00:00
  • 3b8813be6e Plan mandatory signatures wildcard support copilot-swe-agent[bot] 2026-05-29 15:58:13 +00:00
  • e161f9b28d chore: address lint extension review feedback copilot-swe-agent[bot] 2026-05-28 18:20:41 +00:00
  • 9cef15aa13 feat(lint): enforce mandatory image signatures before publish copilot-swe-agent[bot] 2026-05-28 18:16:54 +00:00
  • 904936935c Initial plan copilot-swe-agent[bot] 2026-05-28 17:55:25 +00:00
  • a2d738c575 fix: miscellaneous fixes for ai-reported suggestions (#4101) Ramkumar Chinchani 2026-05-26 14:58:30 -07:00
  • 15cb9ae2ec Rename mixed resolver test scope for clarity copilot/feat-disable-cve-keep-ui-search copilot-swe-agent[bot] 2026-05-26 20:44:03 +00:00
  • fe6203c027 test(search): assert CVEDiffListForImages nil-cve response fields copilot-swe-agent[bot] 2026-05-26 06:45:20 +00:00
  • 8054651abe fix: keep Search.CVE.Enable nil while defaulting enabled behavior copilot-swe-agent[bot] 2026-05-26 06:42:20 +00:00
  • 6024ae47e1 Potential fix for pull request finding Ramkumar Chinchani 2026-05-25 23:38:40 -07:00
  • 3a65087851 Potential fix for pull request finding Ramkumar Chinchani 2026-05-25 23:37:47 -07:00
  • e91b96b81d docs: clarify cve enable config semantics copilot-swe-agent[bot] 2026-05-26 06:12:53 +00:00
  • b419227a92 fix: return empty CVE graphql results when cve disabled copilot-swe-agent[bot] 2026-05-26 06:09:07 +00:00
  • b5ed56f07d feat: allow disabling CVE independently from search copilot-swe-agent[bot] 2026-05-26 05:37:30 +00:00
  • d8a53b7096 Initial plan copilot-swe-agent[bot] 2026-05-26 05:29:13 +00:00
  • f85cce1aeb test: relax brittle TestPeriodicGC substore log assertion copilot/fix-github-actions-job copilot-swe-agent[bot] 2026-05-25 06:29:32 +00:00
  • 0173b38f9f Initial plan copilot-swe-agent[bot] 2026-05-25 06:13:18 +00:00
  • 4e4d00a0a6 feat: add trivy-based sbom artifact generation support (#4088) Ramkumar Chinchani 2026-05-23 23:24:12 -07:00
  • d8fb19819b chore: fix dependabot alerts (#4091) Ramkumar Chinchani 2026-05-22 22:20:08 -07:00
  • 6262cba0d0 feat(sync): increase wait for stream bats Vishwas Rajashekar 2026-05-22 17:39:19 +05:30
  • a6bf024071 feat(sync): add unit tests for routes.go Vishwas Rajashekar 2026-05-22 17:38:41 +05:30
  • f8ef0ae706 feat(sync): fix data race Vishwas Rajashekar 2026-05-20 23:32:08 +05:30
  • 38f0e498ab feat(sync): address review comments Vishwas Rajashekar 2026-05-20 23:15:01 +05:30
  • 09e674f369 feat(sync): increase wait period in BATS, misc Vishwas Rajashekar 2026-05-20 22:40:52 +05:30
  • 7d3dd2b80e feat(sync): add kind BATS test for streaming Vishwas Rajashekar 2026-05-20 22:00:32 +05:30
  • 80b1712b62 feat(sync): fix review comments Vishwas Rajashekar 2026-05-20 08:53:17 +05:30
  • f7444abbd4 feat(sync): use waiting for descriptor fetch Vishwas Rajashekar 2026-05-20 01:12:09 +05:30
  • d93506909c feat(sync): add tests for stream mgr,store Vishwas Rajashekar 2026-05-20 00:21:06 +05:30
  • d4f764c0f0 feat(sync): add tests for ondemand, service Vishwas Rajashekar 2026-05-19 23:56:04 +05:30
  • cf8f02f919 feat(sync): add unit tests, fixes for cbr and copier Vishwas Rajashekar 2026-05-19 22:52:46 +05:30
  • 14cd52e993 feat(sync): move stream from global to per upstream Vishwas Rajashekar 2026-05-19 00:55:07 +05:30
  • 63b7654d50 feat(sync): fix review comments Vishwas Rajashekar 2026-05-18 23:47:18 +05:30
  • b87c18fc09 feat(sync): add bats + remove sync retry Vishwas Rajashekar 2026-05-18 18:57:12 +05:30
  • 7566f525cf feat(sync): update examples Vishwas Rajashekar 2026-05-17 18:45:07 +05:30
  • 4f49cea1a4 feat(sync): rework concurrency, use bytes instead of chunk Vishwas Rajashekar 2026-05-17 18:29:58 +05:30
  • fa39761700 feat(sync): fix review comments + extras Vishwas Rajashekar 2026-05-17 17:01:43 +05:30
  • 3adf36a6c7 feat(sync): fix errors and cleanup code Vishwas Rajashekar 2026-05-16 20:04:21 +05:30
  • 2fb691cd3b feat(sync): additional changes for streaming Vishwas Rajashekar 2026-05-16 18:44:10 +05:30
  • e2aa088e0d feat(sync): initial commit for streaming sync Vishwas Rajashekar 2026-02-08 00:37:45 +05:30
  • a4c55e288c chore: fix dependabot alerts (#4082) Ramkumar Chinchani 2026-05-21 08:50:48 -07:00
  • 1182981b0d fix(api): clarify nolint comment and add fallback doc in bearer_oidc.go copilot/add-oidc-workload-authentication copilot-swe-agent[bot] 2026-05-19 02:02:52 +00:00
  • 4372a3faca fix(sync): remove retry workaround now that root cause is fixed copilot-swe-agent[bot] 2026-05-19 02:01:56 +00:00
  • 569afcc887 fix(sync): eliminate periodic sync race in TestDockerImagesAreSkipped copilot-swe-agent[bot] 2026-05-19 01:59:07 +00:00
  • 873d4a3eeb test(sync): replace cleanup retry magic numbers with constants copilot-swe-agent[bot] 2026-05-19 01:51:09 +00:00
  • 94d6a3e837 test(sync): retry RemoveAll on ENOTEMPTY in flaky extension test copilot-swe-agent[bot] 2026-05-19 01:50:08 +00:00
  • 6237274c0c fix: use c.So() in goroutines in config_reloader_test.go to prevent panic copilot/add-sbom-generation-support copilot-swe-agent[bot] 2026-05-19 01:35:05 +00:00
  • 4bc4261e84 feat(api): gate OIDC basic token auth behind config flag copilot-swe-agent[bot] 2026-05-19 00:33:04 +00:00
  • 55ec84b6ae test: include default trivy SBOM field in CVE config assertion copilot-swe-agent[bot] 2026-05-19 00:27:09 +00:00
  • c372bb1b71 docs(api): clarify swagger-only image descriptor wrapper copilot-swe-agent[bot] 2026-05-18 23:28:12 +00:00
  • b8fcf96335 fix(api): make swagger manifest/index schemas parseable by swag copilot-swe-agent[bot] 2026-05-18 23:24:29 +00:00
  • 01cd3143b9 chore: address review feedback for sbom scanner changes copilot-swe-agent[bot] 2026-05-18 22:49:14 +00:00
  • 4e66891b72 feat: add trivy-based sbom artifact generation support copilot-swe-agent[bot] 2026-05-18 22:45:23 +00:00
  • 6009d768e9 chore: outline plan for SBOM generation support copilot-swe-agent[bot] 2026-05-18 22:42:04 +00:00
  • af99f64534 fix(api): tighten OIDC basic token parsing and error wrapping copilot-swe-agent[bot] 2026-05-18 22:41:05 +00:00
  • 3b040cc6d7 feat(api): support OIDC workload token via HTTP Basic auth copilot-swe-agent[bot] 2026-05-18 22:37:34 +00:00
  • eda8739fb7 Initial plan copilot-swe-agent[bot] 2026-05-18 22:32:33 +00:00
  • 43150f418b Initial plan copilot-swe-agent[bot] 2026-05-18 22:32:14 +00:00
  • 08b26876da chore: bump zui version (#4074) v2.1.17 Ramkumar Chinchani 2026-05-17 22:21:26 -07:00
  • 555a35d3dc chore: fix dependabot alerts (#4072) Ramkumar Chinchani 2026-05-16 23:33:48 -07:00
  • 6c1f1bdd40 feat(metrics): add Prometheus GC metrics (#3863) Benoit Tigeot 2026-05-17 08:03:36 +02:00
  • 4d6bf18825 fix(lint): silence deprecated gomodguard linter warning (#4070) Benoit Tigeot 2026-05-16 20:46:40 +02:00
  • 5087d725e6 chore: fix dependabot alerts (#4059) Ramkumar Chinchani 2026-05-12 00:50:02 -07:00
  • b272e0994e fix: downgrade expected missing-blob HEAD logging from error to debug (#4056) Ramkumar Chinchani 2026-05-11 21:25:44 -07:00
  • 9aff5b8d08 chore: fix dependabot alerts (#4048) Ramkumar Chinchani 2026-05-10 23:29:05 -07:00
  • 9757f7cf41 ci: fix golangci-lint install URL (#4052) Andrei Aaron 2026-05-10 20:35:59 +03:00
  • 5d323c4dd5 ci: sync go 1.26 images to ghcr.io/project-zot/golang (#4049) Andrei Aaron 2026-05-10 08:23:06 +03:00
  • 8a6674f198 feat(authz): introduce conditional access control via CEL (#4040) Matheus Pimenta 2026-05-09 20:43:00 +01:00
  • ddb6279a25 fix(zli config): print help for missing args (#4046) Andrei Aaron 2026-05-08 23:22:15 +03:00
  • c7ddbe2e36 feat(zli): add config list/show/get/set/reset and isolate deprecated syntax (#4037) Andrei Aaron 2026-05-08 20:19:26 +03:00
  • b89d10834c refactor(build): move build metadata to pkg/buildinfo (#4045) Andrei Aaron 2026-05-08 19:37:04 +03:00
  • fa92366009 refactor(zli): add typed ~/.zot config layer and strict validation (#4030) Andrei Aaron 2026-05-05 08:52:59 +03:00
  • 7ec34a9520 feat(api): log session/audit subject from UserAccessControl (#4029) Andrei Aaron 2026-05-01 19:35:22 +03:00
  • fa2960b705 fix(auth): refine OIDC identity handling and claim-mapping logs (#4028) Andrei Aaron 2026-05-01 19:34:48 +03:00
  • 8f27949dcb test: refactor countingReader into partialReaderOpenTracker and partialReaderReadCloser (#4027) Andrei Aaron 2026-05-01 13:51:24 +03:00
  • cb9d682a69 feat(auth): map OpenID groups claim (#3999) Akash Kumar 2026-05-01 14:29:51 +05:30
  • 0b2eaa0f9a feat(cosign): add support for cosign bundle (#4023) Ramkumar Chinchani 2026-05-01 00:21:06 -07:00
  • 993a17f5d0 docs(config): reference generated config schema (#4015) Akash Kumar 2026-04-28 11:59:46 +05:30