Skip to content

deps(go): bump module oras.land/oras-go/v2 to v2.6.2 - #9583

Merged
olblak merged 3 commits into
mainfrom
updatecli_main_1d2712f911bf78ef2946f7b9c3a03d3a82a36b385a2148641e0f06a6a8903208
Jul 15, 2026
Merged

deps(go): bump module oras.land/oras-go/v2 to v2.6.2#9583
olblak merged 3 commits into
mainfrom
updatecli_main_1d2712f911bf78ef2946f7b9c3a03d3a82a36b385a2148641e0f06a6a8903208

Conversation

@updateclibot

@updateclibot updateclibot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

deps(go): bump module oras.land/oras-go/v2

clean: go mod tidy

ran shell command "go mod tidy"

deps(go): bump module oras.land/oras-go/v2 to v2.6.2

go.mod updated Module path "oras.land/oras-go/v2" version from "v2.6.1" to "v2.6.2"

v2.6.2
This is a security patch release addressing advisories in the content and remote layers, plus additional hardening and bug fixes since v2.6.1.

## Security Fixes

- Resolve the hardlink (`TypeLink`) target before passing it to `os.Link`, preventing a crafted OCI artifact from hardlinking a file outside the extraction directory via the process CWD (#1232, [GHSA-fxhp-mv3v-67qp](https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp) / CVE-2026-50163)
- Bound tag and referrer list pagination to prevent a malicious or misbehaving registry from advertising an endless page chain and forcing unbounded client requests (client-side DoS) (#1215)

## Bug Fixes

- Bound `content.ReadAll` allocation by actual content read rather than the descriptor size, correcting the over-broad 32 MiB cap introduced for GHSA-f36w-mj3v-6jqv so legitimate in-memory `Push`/`FetchAll`/`FetchBytes` are not rejected (#1223)

## Other Changes

- Bump `golang.org/x/sync` from 0.20.0 to 0.21.0 (#1208)


v2.6.1
This is a security patch release addressing five advisories in the authentication, remote, and content layers, plus accumulated bug fixes and maintenance since v2.6.0.

## Security Fixes

- Drop the `Authorization` header on cross-origin redirects to prevent origin credentials leaking to a redirect target on a different scheme/port of the same host ([GHSA-vh4v-2xq2-g5cg](https://github.com/oras-project/oras-go/security/advisories/GHSA-vh4v-2xq2-g5cg))
- Validate the bearer `realm` host before sending credentials to prevent credential exfiltration to an attacker-controlled token service, including TLS downgrades and IP-literal metadata endpoints; adds `TrustedRealmHosts` ([GHSA-28r5-37g7-p6mp](https://github.com/oras-project/oras-go/security/advisories/GHSA-28r5-37g7-p6mp), [GHSA-xf85-363p-868w](https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w))
- Validate the `Location` host before blob upload to prevent credentials being forwarded to a cross-host upload endpoint (SSRF / CWE-918) (#1152, [GHSA-jxpm-75mh-9fp7](https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7))
- Reject descriptor sizes exceeding 32 MiB in `content.ReadAll` to prevent a crafted OCI layout from triggering a `makeslice` panic and crashing the process (#1153, [GHSA-f36w-mj3v-6jqv](https://github.com/oras-project/oras-go/security/advisories/GHSA-f36w-mj3v-6jqv))
- Resolve symlinks when enforcing the `workingDir` write boundary in `content/file`, blocking writes that escape the boundary via a symlinked path component when `AllowPathTraversalOnWrite=false`

## Bug Fixes

- `graph.Memory` should use digest as map key (#1095)
- Fix credentials key for the Docker `registry-1` host (#966)
- Support an empty credentials file (#959)

## Other Changes

- Add GitOps release workflow with goreleaser (#1161)
- Shift the Go support window to [1.24, 1.25] (#991)
- Run `go modernize` (#1005)
- Sync `CODEOWNERS` and `OWNERS.md` from main to v2 (#1122)
- Remove scripts reference from the Makefile (#960)
- Bump `golang.org/x/sync` 0.14.0 → 0.20.0 (#971, #978, #1001, #1037, #1078, #1121)
- Bump GitHub Actions: `actions/checkout` 4→5 (#989), `actions/setup-go` 5→6 (#998), `actions/stale` 9→10 (#997), `github/codeql-action` 3→4 (#1016)

GitHub Action workflow link
Updatecli logo

Created automatically by Updatecli

Options:

Most of Updatecli configuration is done via its manifest(s).

  • If you close this pull request, Updatecli will automatically reopen it, the next time it runs.
  • If you close this pull request and delete the base branch, Updatecli will automatically recreate it, erasing all previous commits made.

Feel free to report any issues at github.com/updatecli/updatecli.
If you find this tool useful, do not hesitate to star our GitHub repository as a sign of appreciation, and/or to tell us directly on our chat!

updateclibot Bot added 2 commits July 14, 2026 08:55
Made with ❤️️ by updatecli
@updateclibot updateclibot Bot added the dependencies Pull requests that update a dependency file label Jul 14, 2026
@olblak
olblak enabled auto-merge (squash) July 15, 2026 05:19
@olblak
olblak merged commit 8838a1c into main Jul 15, 2026
8 of 9 checks passed
@olblak
olblak deleted the updatecli_main_1d2712f911bf78ef2946f7b9c3a03d3a82a36b385a2148641e0f06a6a8903208 branch July 15, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant