Skip to content

dockerClient.getOCIDescriptorContents does not validate the contents against the digest #2687

@mtrmac

Description

@mtrmac

The manifest is registry-controlled anyway (we look it up using a tag, not a digest), so this does not give the registry any new powers, but having code like that laying around is a risk.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugA defect in an existing functionality (or a PR fixing it)

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions