Skip to content

v2.13.6

Choose a tag to compare

@Vad1mo Vad1mo released this 06 Oct 15:48
4efe985

Warning

Breaking change: webhooks to internal addresses are blocked by default

The fix for GHSA-2phj-cp9f-qq6w blocks webhook and Slack delivery to private, loopback, link-local and other non-public addresses. That includes hostnames that resolve to them, such as *.svc.cluster.local. After you upgrade, existing webhooks to internal endpoints fail to deliver, and new ones are rejected.

To allow them again, set the opt-out on both core and jobservice:

  • harbor.yml: network.allow_private_network_access: true, then ./prepare and restart
  • Helm: add {name: HARBOR_ALLOW_PRIVATE_NETWORK_ACCESS, value: "true"} to both core.extraEnvVars and jobservice.extraEnvVars

This disables the protection entirely. Only use it if you trust all project admins, and block 169.254.169.254 at the network level.

Warning

Breaking change: signing unsigned images fails when content trust is enforced

The fix for GHSA-wrw5-gmvj-gf23 removes the User-Agent based exemption that let cosign and notation pull unsigned images. In projects that only allow signed images, cosign sign and notation sign on a new, unsigned image now fail with 412 Precondition Failed. Images that already have a signature are not affected.

To allow signing clients again, set CONTENT_TRUST_LEGACY_SIGNER_PULL_ENABLED=true on core. The value must be exactly true.

  • Helm: add it to core.extraEnvVars
  • harbor.yml installs: there is no harbor.yml option. Add it to common/config/core/env and restart. Re-running ./prepare overwrites that file.

The exemption still trusts the client's User-Agent, but only for users or robots with push permission on the project. Projects that block vulnerable images have no opt-out: a signing client can no longer pull an image that the vulnerability policy blocks.

What's Changed

Security Advisories 🔒

Other Changes

  • fix: pin redis 7.2.11 instead of 7.2.6 in the redis base image by @bupd in #24066

Full Changelog: v2.13.5...v2.13.6