From 5f3ca1b2fb6109705d729816e7260a6966d2b42d Mon Sep 17 00:00:00 2001 From: Milos Gajdos Date: Tue, 9 May 2023 23:51:24 +0100 Subject: [PATCH] Add release notes for 2.8.2-beta.2 release Signed-off-by: Milos Gajdos --- releases/v2.8.2-beta.toml | 12 ++++++++---- version/version.go | 2 +- 2 files changed, 9 insertions(+), 5 deletions(-) diff --git a/releases/v2.8.2-beta.toml b/releases/v2.8.2-beta.toml index 8f6c2e7111..609a83c330 100644 --- a/releases/v2.8.2-beta.toml +++ b/releases/v2.8.2-beta.toml @@ -10,13 +10,17 @@ previous = "v2.8.1" pre_release = false preface = """\ -Welcome to the 2.8.2-beta.1 release of registry! +Welcome to the 2.8.2-beta.2 release of registry! -The 2.8.2-beta.1 registry release fixes several security vulnerabilities. +The 2.8.2-beta.2 registry release fixes several security vulnerabilities. The Go runtime has been bumped to 1.19. See the changelog below for full list of changes. +### CI + +* Dockerfile: fix filenames of artifacts ([#3911](https://github.com/distribution/distribution/pull/3911)) + ### Bugfixes * Fix panic in inmemory driver ([#3815](https://github.com/distribution/distribution/pull/3815)) @@ -29,8 +33,8 @@ See the changelog below for full list of changes. ### Security -* Fix CVE-2022-28391 by bumping alpine from 3.14 to 3.16 ([#3650](https://github.com/distribution/distribution/pull/3650)) -* Fix runaway allocation on /v2/_catalog [`521ea3d9`](https://github.com/distribution/distribution/commit/521ea3d973cb0c7089ebbcdd4ccadc34be941f54) +* Fix [CVE-2022-28391](https://www.cve.org/CVERecord?id=CVE-2022-28391) by bumping alpine from 3.14 to 3.16 ([#3650](https://github.com/distribution/distribution/pull/3650)) +* Fix [CVE-2023-2253](https://www.cve.org/CVERecord?id=CVE-2023-2253) runaway allocation on /v2/_catalog [`521ea3d9`](https://github.com/distribution/distribution/commit/521ea3d973cb0c7089ebbcdd4ccadc34be941f54) ### Dependency Changes diff --git a/version/version.go b/version/version.go index dec503de40..daba7c16f3 100644 --- a/version/version.go +++ b/version/version.go @@ -8,7 +8,7 @@ var Package = "github.com/docker/distribution" // the latest release tag by hand, always suffixed by "+unknown". During // build, it will be replaced by the actual version. The value here will be // used if the registry is run after a go get based install. -var Version = "v2.8.2-beta.1+unknown" +var Version = "v2.8.2-beta.2+unknown" // Revision is filled with the VCS (e.g. git) revision being used to build // the program at linking time.