You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(oci): support OCI auth hardening from reference v0.89.0
Bump the pinned reference CLI to v0.89.0 and implement the observable
surface it added (PR devcontainers/cli#1278):
- `--oci-auth-hardening` and `--allow-cross-origin-auth-host` as global
flags, with the same validation the oracle applies: the allow list
requires hardening, and each entry is a '<registry-host>=<auth-host>'
pair of bare authorities.
- `ociAuthDiagnostics` in the `up`, `build` and `read-configuration`
output, reporting what hardening would change.
- Bearer realms pinned to the registry authority or a trusted auth host
(including the built-in Docker Hub and GitLab mappings), and token
endpoints refused a redirect, when hardening is on.
- `scheme` on the feature ref in `read-configuration` output, and the
generated feature Dockerfiles defaulting the base-image ARG to
`scratch` rather than `placeholder`.
The policy is built once per invocation and carried on the command
context, so every OCI client of a command shares its settings and feeds
the same diagnostics. `exec` parses its own flags and therefore applies
the validation itself; `features test` re-invokes this binary and
forwards the flags to the `up` it spawns.
The hardening is enforced in a transport above oras-go, which already
refuses to forward credentials to a cross-origin challenge. That makes
hardening-off stricter here than upstream; the divergence is documented
and the diagnostics still report what hardening would change.
TestOracleFlagCoverage only inspected per-command options, so the two
new global flags went unnoticed; it now checks the oracle's global
options as well, and TestFlagInventoryParity pins them to the root
command.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
notes: "0.89 global flag: accepted before the command name and the output carries the ociAuthDiagnostics envelope field (all false when no registry is contacted)."
notes: "Mirrors the oracle's own 'Global options consume exactly one argument' test (src/test/cli.test.ts), asserted on read-configuration because yargs and cobra render --help differently: the repeatable flag must consume exactly one value and leave the subcommand intact."
0 commit comments