This release adds 5 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+1 more
Affected surfaces
Summary
AI summaryUpdates span chores, features (Trivy SBOM, metrics ACLs, Azure Blob driver), fixes (storage handling, authz), CI changes, and metadb restart optimizations.
Full changelog
What's Changed
- chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4082
- chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4091
- feat: add trivy-based sbom artifact generation support by @rchincha in https://github.com/project-zot/zot/pull/4088
- fix: miscellaneous fixes for ai-reported suggestions by @rchincha in https://github.com/project-zot/zot/pull/4101
- docs: fix alongside spelling in search docs by @yosinn1-blip in https://github.com/project-zot/zot/pull/4095
- chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4113
- fix(cve): prefer cve.org links for AVD references by @charles-openclaw in https://github.com/project-zot/zot/pull/4107
- feat: enhance config sanitization to mask sensitive keys in storage a… by @rchincha in https://github.com/project-zot/zot/pull/4119
- fix: skip DynamoDB table creation when tables exist by @andaaron in https://github.com/project-zot/zot/pull/4120
- ci: Update GH runner labels by @andaaron in https://github.com/project-zot/zot/pull/4121
- metadb: add optional fast restart path that skips storage walk when (version + commit + storage config) matches metaDB stamp by @USA-RedDragon in https://github.com/project-zot/zot/pull/4026
- feat(metrics): anonymous access when enabled in accessControl config by @uaggarwa in https://github.com/project-zot/zot/pull/4110
- fix(storage): treat dedupe-candidate cache miss as no candidates, not an error by @jankowtf in https://github.com/project-zot/zot/pull/4122
- chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4126
- feat: config: validate metrics config by @vrajashkr in https://github.com/project-zot/zot/pull/4130
- fix(authz): metrics: deny authenticated users not in ACL even with anonymous read by @vrajashkr in https://github.com/project-zot/zot/pull/4131
- fix(storage): release global write lock during blob restore I/O by @shcherbak in https://github.com/project-zot/zot/pull/4089
- refactor(test/blackbox): extract shared push/pull helpers by @andaaron in https://github.com/project-zot/zot/pull/4132
- feat(storage): redirect blob pulls to backend URLs by @rchincha in https://github.com/project-zot/zot/pull/4092
- feat: add authz support for GitHub teams by @rchincha in https://github.com/project-zot/zot/pull/4139
- feat(cli): support default config name by @andaaron in https://github.com/project-zot/zot/pull/4143
- ci: fix conformance test to before the refactor by @rchincha in https://github.com/project-zot/zot/pull/4145
- feat(events): include actor and request metadata in webhook payloads by @cainydev in https://github.com/project-zot/zot/pull/3959
- feat: add Azure Blob Storage driver by @datadot in https://github.com/project-zot/zot/pull/4142
- chore: fix dependabot alerts by @rchincha in https://github.com/project-zot/zot/pull/4157
- ci: pull test images from ghcr mirror by @datadot in https://github.com/project-zot/zot/pull/4156
- fix: map HTTP methods to corresponding scope actions in bearer authen… by @rchincha in https://github.com/project-zot/zot/pull/4161
New Contributors
- @yosinn1-blip made their first contribution in https://github.com/project-zot/zot/pull/4095
- @charles-openclaw made their first contribution in https://github.com/project-zot/zot/pull/4107
- @USA-RedDragon made their first contribution in https://github.com/project-zot/zot/pull/4026
- @uaggarwa made their first contribution in https://github.com/project-zot/zot/pull/4110
- @jankowtf made their first contribution in https://github.com/project-zot/zot/pull/4122
- @shcherbak made their first contribution in https://github.com/project-zot/zot/pull/4089
- @datadot made their first contribution in https://github.com/project-zot/zot/pull/4142
Full Changelog: https://github.com/project-zot/zot/compare/v2.1.17...v2.1.18
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About zot
zot - A scale-out production-ready vendor-neutral OCI-native container image/artifact registry (purely based on OCI Distribution Specification)
Related context
Related tools
Beta — feedback welcome: [email protected]