github.com/opencontainers/image-spec
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Sep 30, 2016
| Version | Released | |
|---|---|---|
v1.1.1
patch
|
v1.1.1
patch
Dependencies (3)
|
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (4)
|
|
v1.1.0-rc.6
pre
|
v1.1.0-rc.6
pre
Dependencies (4)
|
|
v1.1.0-rc6
pre
|
v1.1.0-rc6
pre
Dependencies (4)
|
|
v1.1.0-rc5
pre
|
v1.1.0-rc5
pre
Dependencies (5)
|
|
v1.1.0-rc4
pre
|
v1.1.0-rc4
pre
Dependencies (5)
|
|
v1.1.0-rc3
pre
|
v1.1.0-rc3
pre
Dependencies (5)
|
|
v1.1.0-rc.3
pre
|
v1.1.0-rc.3
pre
Dependencies (5)
|
|
v1.1.0-rc2
pre
|
v1.1.0-rc2
pre
Dependencies (5)
|
|
v1.1.0-rc1
pre
|
v1.1.0-rc1
pre
Dependencies (5)
|
|
v1.0.2
patch
|
v1.0.2
patch
|
|
v1.0.1
patch
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.1
patch
|
|
v1.0.0
initial
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0
initial
|
|
v1.0.0-rc7
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc7
pre
|
|
v1.0.0-rc6
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc6
pre
|
|
v1.0.0-rc5
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc5
pre
|
|
v1.0.0-rc4
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc4
pre
|
|
v1.0.0-rc3
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc3
pre
|
|
v1.0.0-rc2
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc2
pre
|
|
v1.0.0-rc1
pre
1 CVE
GHSA-77vh-xpmg-72qh
Nov 18, 2021
Clarify `mediaType` handling
3.0
/ 10
Low
Network
High
Low
Required
Changed
None
Low
None
ImpactIn the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index. PatchesThe Image Specification will be updated to recommend that both manifest and index documents contain a WorkaroundsSoftware attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields. Referenceshttps://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc1
pre
|