github.com/deislabs/oras
OCI registry client - managing content like artifacts, images, packages
Activity
- Latest release
- 2w ago
- Total releases
- 49
- Cadence
- ~29 days
- Last 12 months
- 4
Reach
- Stars
- 2.4k
Details
- First release
- Dec 27, 2018
| Version | Released | |
|---|---|---|
v1.3.4
patch
|
v1.3.4
patch
Dependencies (11)
+ 3 more |
|
v1.3.3
patch
|
v1.3.3
patch
Dependencies (12)
+ 4 more |
|
v1.3.2
patch
|
v1.3.2
patch
Dependencies (12)
+ 4 more |
|
v1.3.1
patch
|
v1.3.1
patch
Dependencies (12)
+ 4 more |
|
v1.3.0
minor
|
v1.3.0
minor
Dependencies (12)
+ 4 more |
|
v1.3.0-rc.2
pre
|
v1.3.0-rc.2
pre
Dependencies (12)
+ 4 more |
|
v1.3.0-rc.1
pre
|
v1.3.0-rc.1
pre
Dependencies (12)
+ 4 more |
|
v1.3.0-beta.4
pre
|
v1.3.0-beta.4
pre
Dependencies (12)
+ 4 more |
|
v1.2.3
patch
|
v1.2.3
patch
Dependencies (12)
+ 4 more |
|
v1.3.0-beta.3
pre
|
v1.3.0-beta.3
pre
Dependencies (12)
+ 4 more |
|
v1.3.0-beta.2
pre
|
v1.3.0-beta.2
pre
Dependencies (12)
+ 4 more |
|
v1.2.2
patch
|
v1.2.2
patch
Dependencies (12)
+ 4 more |
|
v1.3.0-beta.1
pre
|
v1.3.0-beta.1
pre
Dependencies (12)
+ 4 more |
|
v1.2.1
patch
|
v1.2.1
patch
Dependencies (12)
+ 4 more |
|
v1.2.0
minor
|
v1.2.0
minor
Dependencies (12)
+ 4 more |
|
v1.2.0-rc.1
pre
|
v1.2.0-rc.1
pre
Dependencies (12)
+ 4 more |
|
v1.2.0-beta.1
pre
|
v1.2.0-beta.1
pre
Dependencies (12)
+ 4 more |
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (9)
+ 1 more |
|
v1.1.0-rc.2
pre
|
v1.1.0-rc.2
pre
Dependencies (9)
+ 1 more |
|
v1.0.1
patch
|
v1.0.1
patch
Dependencies (9)
+ 1 more |
|
v1.1.0-rc.1
pre
|
v1.1.0-rc.1
pre
Dependencies (9)
+ 1 more |
|
v1.0.0
major
|
v1.0.0
major
Dependencies (10)
+ 2 more |
|
v1.0.0-rc.2
pre
|
v1.0.0-rc.2
pre
Dependencies (10)
+ 2 more |
|
v1.0.0-rc.1
pre
|
v1.0.0-rc.1
pre
Dependencies (10)
+ 2 more |
|
v0.16.0
minor
|
v0.16.0
minor
Dependencies (9)
+ 1 more |
|
v0.15.1
patch
|
v0.15.1
patch
Dependencies (10)
+ 2 more |
|
v0.15.0
minor
|
v0.15.0
minor
Dependencies (10)
+ 2 more |
|
v0.14.1
patch
|
v0.14.1
patch
Dependencies (10)
+ 2 more |
|
v0.14.0
minor
|
v0.14.0
minor
Dependencies (10)
+ 2 more |
|
v0.13.0
minor
|
v0.13.0
minor
Dependencies (8)
|
|
v0.2.1-alpha.1
pre
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.2.1-alpha.1
pre
Dependencies (16)
+ 8 more |
|
v0.2.0-alpha.1
pre
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.2.0-alpha.1
pre
Dependencies (15)
+ 7 more |
|
v0.12.0
minor
|
v0.12.0
minor
Dependencies (8)
|
|
v0.11.1
patch
|
v0.11.1
patch
Dependencies (13)
+ 5 more |
|
v0.11.0
minor
|
v0.11.0
minor
Dependencies (13)
+ 5 more |
|
v0.10.0
minor
|
v0.10.0
minor
Dependencies (13)
+ 5 more |
|
v0.9.0
minor
|
v0.9.0
minor
Dependencies (13)
+ 5 more |
|
v0.8.1
patch
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.8.1
patch
Dependencies (13)
+ 5 more |
|
v0.8.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (13)
+ 5 more |
|
v0.7.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (13)
+ 5 more |
|
v0.6.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (12)
+ 4 more |
|
v0.5.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (12)
+ 4 more |
|
v0.4.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.4.0
minor
|
|
v0.3.3
patch
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.3.3
patch
|
|
v0.3.2
patch
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.3.2
patch
|
|
v0.3.1
patch
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.3.1
patch
|
|
v0.3.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.3.0
minor
|
|
v0.2.0
minor
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.2.0
minor
|
|
v0.1.0
initial
1 CVE
CVE-2021-21272
GHSA-g5v4-5x39-vwhx
BIT-oras-2021-21272
GO-2021-0099
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
7.7
/ 10
High
Network
Low
Low
None
Changed
None
High
None
ImpactThe directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs Precisely, the following users of the affected versions are impacted
PatchesThe problem has been patched by the PR linked with this advisory. Users should upgrade their WorkaroundsFor For ReferencesFor more informationIf you have any questions or comments about this advisory:
Fixed in
0.9.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.0
initial
|