Skip to content

zot

v2.1.18 Feature

This release adds 5 notable features for engineering teams evaluating rollout.

Published 1mo Artifact Management
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

distribution-spec helm kubernetes containers oci-distribution opencontainers
+1 more
zot

Affected surfaces

auth rbac

Summary

AI summary

Updates span chores, features (Trivy SBOM, metrics ACLs, Azure Blob driver), fixes (storage handling, authz), CI changes, and metadb restart optimizations.

Full changelog

What's Changed

  • chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4082
  • chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4091
  • feat: add trivy-based sbom artifact generation support by @rchincha in https://github.com/project-zot/zot/pull/4088
  • fix: miscellaneous fixes for ai-reported suggestions by @rchincha in https://github.com/project-zot/zot/pull/4101
  • docs: fix alongside spelling in search docs by @yosinn1-blip in https://github.com/project-zot/zot/pull/4095
  • chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4113
  • fix(cve): prefer cve.org links for AVD references by @charles-openclaw in https://github.com/project-zot/zot/pull/4107
  • feat: enhance config sanitization to mask sensitive keys in storage a… by @rchincha in https://github.com/project-zot/zot/pull/4119
  • fix: skip DynamoDB table creation when tables exist by @andaaron in https://github.com/project-zot/zot/pull/4120
  • ci: Update GH runner labels by @andaaron in https://github.com/project-zot/zot/pull/4121
  • metadb: add optional fast restart path that skips storage walk when (version + commit + storage config) matches metaDB stamp by @USA-RedDragon in https://github.com/project-zot/zot/pull/4026
  • feat(metrics): anonymous access when enabled in accessControl config by @uaggarwa in https://github.com/project-zot/zot/pull/4110
  • fix(storage): treat dedupe-candidate cache miss as no candidates, not an error by @jankowtf in https://github.com/project-zot/zot/pull/4122
  • chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4126
  • feat: config: validate metrics config by @vrajashkr in https://github.com/project-zot/zot/pull/4130
  • fix(authz): metrics: deny authenticated users not in ACL even with anonymous read by @vrajashkr in https://github.com/project-zot/zot/pull/4131
  • fix(storage): release global write lock during blob restore I/O by @shcherbak in https://github.com/project-zot/zot/pull/4089
  • refactor(test/blackbox): extract shared push/pull helpers by @andaaron in https://github.com/project-zot/zot/pull/4132
  • feat(storage): redirect blob pulls to backend URLs by @rchincha in https://github.com/project-zot/zot/pull/4092
  • feat: add authz support for GitHub teams by @rchincha in https://github.com/project-zot/zot/pull/4139
  • feat(cli): support default config name by @andaaron in https://github.com/project-zot/zot/pull/4143
  • ci: fix conformance test to before the refactor by @rchincha in https://github.com/project-zot/zot/pull/4145
  • feat(events): include actor and request metadata in webhook payloads by @cainydev in https://github.com/project-zot/zot/pull/3959
  • feat: add Azure Blob Storage driver by @datadot in https://github.com/project-zot/zot/pull/4142
  • chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4157
  • ci: pull test images from ghcr mirror by @datadot in https://github.com/project-zot/zot/pull/4156
  • fix: map HTTP methods to corresponding scope actions in bearer authen… by @rchincha in https://github.com/project-zot/zot/pull/4161

New Contributors

  • @yosinn1-blip made their first contribution in https://github.com/project-zot/zot/pull/4095
  • @charles-openclaw made their first contribution in https://github.com/project-zot/zot/pull/4107
  • @USA-RedDragon made their first contribution in https://github.com/project-zot/zot/pull/4026
  • @uaggarwa made their first contribution in https://github.com/project-zot/zot/pull/4110
  • @jankowtf made their first contribution in https://github.com/project-zot/zot/pull/4122
  • @shcherbak made their first contribution in https://github.com/project-zot/zot/pull/4089
  • @datadot made their first contribution in https://github.com/project-zot/zot/pull/4142

Full Changelog: https://github.com/project-zot/zot/compare/v2.1.17...v2.1.18

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zot

Get notified when new releases ship.

Sign up free

About zot

zot - A scale-out production-ready vendor-neutral OCI-native container image/artifact registry (purely based on OCI Distribution Specification)

All releases →

Related context

Beta — feedback welcome: [email protected]