Debian Package Tracker
Register | Log in
Subscribe

oras

OCI registry cli tool managing content like artifacts, images, packages

Choose email to subscribe with

general
  • source: oras (main)
  • version: 1.3.3-1
  • maintainer: Debian Go Packaging Team (DMD)
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 1.2.0-1
  • testing: 1.3.3-1
  • unstable: 1.3.3-1
versioned links
  • 1.2.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.3.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • oras
action needed
A new upstream version is available: 1.3.4 high
A new upstream version 1.3.4 is available, you should consider packaging it.
Created: 2026-08-28 Last update: 2026-09-03 13:33
lintian reports 1 error and 1 warning high
Lintian reports 1 error and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-01 Last update: 2026-08-01 05:49
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-55588: (needs triaging) ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-08-26 Last update: 2026-09-01 22:00
news
[rss feed]
  • [2026-08-18] oras 1.3.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-31] Accepted oras 1.3.3-1 (source) into unstable (Nilesh Patra)
  • [2025-10-22] oras 1.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-19] Accepted oras 1.3.0-1 (source) into unstable (Nilesh Patra)
  • [2025-08-17] oras 1.2.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-11] Accepted oras 1.2.3-1 (source) into unstable (Nilesh Patra)
  • [2024-06-23] oras 1.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-19] Accepted oras 1.2.0-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Nilesh Patra)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (1, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.3.3-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing