Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release/2.7 backport] Change should to must in v2 spec #3495

Merged
merged 1 commit into from Sep 8, 2021

Commits on Sep 8, 2021

  1. Change should to must in v2 spec

    We found some examples of manifests with URLs specififed that did
    not provide a digest or size. This breaks the security model by allowing
    the content to change, as it no longer provides a Merkle tree. This
    was not intended, so explicitly disallow by tightening wording.
    
    Signed-off-by: Justin Cormack <justin.cormack@docker.com>
    (cherry picked from commit 1660df4)
    Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
    justincormack authored and thaJeztah committed Sep 8, 2021
    Copy the full SHA
    19b573a View commit details
    Browse the repository at this point in the history