For AI agents: a markdown representation of this page is available at https://container-registry.com/docs/2.16/release-notes/release-notes-v2.16.0-dev/index.md. The site index is at https://container-registry.com/llms.txt.
Skip to content
Navigation
Searching...
No results found for " "
Try different keywords or check your spelling.
Release notes v2.16.0 (dev) Compare with v2.15.0 .
Features ci: Add Zero CVE Pipeline (#359 )lint: Add Go Quality Linters (#325 )Bug Fixes Address upstream sync review feedback Address Upstream Sync Review Feedback Address Upstream Sync Review Feedback Bound Proxy-Cache Background Goroutines To Prevent Leak (#257 ) build: Stamp version metadata into trivy-adapter and Trivy binaries (#459 )Cache the Scannability Lookups Per Artifact-List Request (#212 ) cache: Defer Cache Eviction Until After Commit And Make Retry Context-Aware (#300 )cache: replace keyMutex with singleflight and avoid canceling cache Save (upstream #23336 ) (#277 )constrain /registries/ping to saved registry settings (#398 ) core: Prevent Core FD/Goroutine Leak When Registry Is Unresponsive (#254 )core: Reduce auth-failure log noise and skip basic auth for non-admin in OIDC/LDAP/UAA (#313 ) — Docs: LDAP/AD Authentication Correct grammar and capitalization inconsistencies across Go source files and docs deps: Bump Harbor Scanner Trivy To v0.38.1 (#415 )deps: Resolve Non-UI CVEs (#374 )Install gh CLI in release workflow Invalid UTF-8 Input Should not Cause HTTP 500 Errors (#321 ) ldap: Use custom orm.ReadOrCreate to prevent LDAP login failure (#323 )max_upstream_conn validation bugs nil deref in StopScanArtifact scan type param Point More Info Link to 8GCR (#293 ) Preserve categorized release notes (#215 ) propagate CSV marshal error in scan data export Push Trivy Adapter Images Without Harbor Prefix (#227 ) release: Track Next Development Version On Main (#360 )Resolve Upstream Sync Review Inconsistencies Restore 0171 Migration For Upstream 2.14.x Upgrade Path (#292 ) Restore Buildable Trivy Adapter Pin Restore Dev Up With Rootless Podman (#401 ) Return 404 For Missing Repository Artifacts (#322 ) scan: Keep SBOM accessory push on the local registry when CORE_URL has no port (#465 )security: avoid audit event panic on nil user data (#402 )ui: remove hardcoded SBOM permission override, closes #23218 Update release-please-config-maintenance.json core: Avoid eager structured-logger build on demoted auth-failure logs (#317 )Upstream 【fix issue 22865】TCR provider adaptor can’t parse intertional secret ID Add ListReferrers API to registry client and update parseScopes Add UI option to enable proxy cache referrer API — Docs: Proxy Cache Projects bump Go version from 1.25.7 to 1.26.3 Bump trivy to v0.71.1 and trivy adapter to v0.37.1-rc.1 Call /v2/auth/token api to get bearer token for dockerhub adapter chore: update Trivy adapter version to v0.37.1 feat(acr): add artifact to supported resource types feat(gc): use human-readable sizes in GC log messages feat(session): prevent background polling from renewing session TTL Fix issue related to scanner API fix: Add i18n keys and missing translations fix: Bump repository update_time on tag and artifact changes fix: correct max_upstream_conn validation and disabled bindings fix: Disallow Empty robot_name_prefix to prevent OIDC CLI login from being blocked — Docs: Changing the Default Robot Accounts Prefix fix: duplicated “by” in beego ORM TableName comments fix: enable chunked blob upload for Azure ACR replication fix: Fix potentional SQLi fix: Fix theoretical timing vulnerability (goharbor/harbor#23433 ) (#378 ) fix: increase access_key column length to 4096 fix: propagate CSV marshal errors in scan data export fix: skip corrupted encrypted config values on decryption failure fix: use validated scan type in StopScanArtifact (#367 ) fix(auditext): add nil guard in manager Create fix(dao): use context-aware methods for database operations in MetaDAO fix(distribution): allow editing instance without credentials fix(ecr): use amazonaws.com.cn domain for AWS China region endpoints fix(gc): redact redis_url_reg from GC extra attrs fix(i18n): localize max upstream connection placeholder fix(portal): remove temporary SBOM permission override fix(scan): use created time from annotations in accessory art fix(security): validate blob-mount source project and reject tokens missing iat fix(ui): Update bindings in Project Policy Config fix(ui): use selected tag for pull command copy Fix/api completeness (goharbor/harbor#23476 ) (#432 ) Harden crypto usage and drop unused SMTP package perf(blob): fix full table scan in unassociation check perf(replication): filter event policies in query refactor(config): centralize registry HTTP client timeout refactor(task): use Redis SET with SPOP for outdate execution status … Replace gopkg.in/yaml.v2 with github.com/goccy/go-yaml Update and improve zh-TW Traditional Chinese locale Update artifact_accessory to add source column to identify accessory update ECR adapter to allow for ecr-public to be mirored — Docs: Endpoints For Replications and Proxy Cache Upgrade harbor go.mod OSS packages Code Refactoring task: use Redis SET with SPOP for outdate execution status refresh