Skip to content

Update registry Docker tag to v3.1.2 - #2115

Open
renovate-bot wants to merge 1 commit into
backube:mainfrom
renovate-bot:renovate/registry-3.x
Open

renovate-bot wants to merge 1 commit into
backube:mainfrom
renovate-bot:renovate/registry-3.x

Conversation

@renovate-bot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
registry (source) service patch 3.1.1 → 3.1.2

Release Notes

distribution/distribution (registry)

v3.1.2

Compare Source

Welcome to the v3.1.2 release of registry!

This is a stable release

This patch release includes security fixes, storage and pagination fixes, and dependency updates.

Please try out the release binaries and report any issues at
https://github.com/distribution/distribution/issues.

Notable Changes
  • Verify manifest and blob content against the requested digest in the registry client, protecting digest-pinned requests and pull-through caches (CVE-2026-85747 / GHSA-685w-q87j-wqw3).
  • Update security-sensitive dependencies, including gRPC, OpenTelemetry, and golang.org/x/crypto (#​4912, #​4963, #​4965, #​4968). The OTLP gRPC log exporter now honors TLS certificates configured through environment variables.
  • Fix S3 tag pagination and catalog listing when one name is a prefix of another (#​4898, #​4904), and return an empty tag array after the final pagination marker (#​4931).
  • Fix Azure blob type migration and a concurrent append-write race (#​4871, #​4888).
  • Check the storage backend directly when writing blobs to avoid stale descriptor-cache entries (#​4868).
  • Reject malformed manifest digests and out-of-order final upload chunks correctly (#​4945), accept unknown total sizes in Content-Range (#​4892), and preserve upstream error codes (#​4917).
  • Stop the upload purger during registry shutdown (#​4956).
  • Validate S3 redirect endpoints at driver initialization (#​4870).
  • Remove the logrus-logstash-hook dependency while retaining the logstash formatter option (#​4970).
Build Updates
  • Building from source now requires Go 1.26 or newer (#​4961).
  • Container images now use Alpine Linux 3.24 (#​4966).

See the changelog below for the full list of changes.

What's Changed
New Contributors

Full Changelog: distribution/distribution@v3.1.1...v3.1.2


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 03:00 AM and 06:59 AM, Monday through Friday (* 3-6 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate Bot added the dependencies Pull requests that update a dependency file label Sep 29, 2026
@openshift-ci

openshift-ci Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: renovate-bot
Once this PR has been reviewed and has the lgtm label, please assign jnpacker for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Hi @renovate-bot. Thanks for your PR.

I'm waiting for a backube member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 68.8%. Comparing base (e3e67f1) to head (6460f9b).

Additional details and impacted files
@@          Coverage Diff          @@
##            main   #2115   +/-   ##
=====================================
  Coverage   68.7%   68.8%           
=====================================
  Files         58      58           
  Lines       6076    6076           
=====================================
+ Hits        4178    4184    +6     
+ Misses      1585    1582    -3     
+ Partials     313     310    -3     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Signed-off-by: Mend Renovate <bot@renovateapp.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file needs-ok-to-test size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant