Skip to content

remote: resolve push-check credentials against the repository - #2411

Merged
Subserial merged 1 commit into
google:mainfrom
mzihlmann:check-push-permission-repo-scope
Aug 18, 2026
Merged

Subserial merged 1 commit into
google:mainfrom
mzihlmann:check-push-permission-repo-scope

Conversation

@mzihlmann

@mzihlmann mzihlmann commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #2410

PR #510 narrowed credential resolution from the registry to the repository level. CheckPushPermission was never updated. Therefore, a config.json holding both a registry-level entry and a more specific repository-level one made the check reject a push that Write then performed successfully.

The test asserts that CheckPushPermission and Write always agree across five credential scopes. The two cases holding both a registry-level and a repository-level entry fail on main, one in each direction.

PR google#510 narrowed credential resolution from the registry to the repository level.
CheckPushPermission was never updated. Therefore, a config.json holding both a
registry-level entry and a more specific repository-level one made the check
reject a push that Write then performed successfully.
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 50.00000% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 57.44%. Comparing base (d3bca10) to head (976b305).

Files with missing lines Patch % Lines
pkg/v1/remote/check.go 50.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2411      +/-   ##
==========================================
+ Coverage   57.42%   57.44%   +0.02%     
==========================================
  Files         166      166              
  Lines       11558    11558              
==========================================
+ Hits         6637     6640       +3     
+ Misses       4142     4138       -4     
- Partials      779      780       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Subserial
Subserial merged commit 82cc428 into google:main Aug 18, 2026
19 checks passed
Subserial pushed a commit to Subserial/go-containerregistry that referenced this pull request Aug 18, 2026
…#2411)

PR google#510 narrowed credential resolution from the registry to the repository level.
CheckPushPermission was never updated. Therefore, a config.json holding both a
registry-level entry and a more specific repository-level one made the check
reject a push that Write then performed successfully.
Subserial pushed a commit to Subserial/go-containerregistry that referenced this pull request Aug 18, 2026
…#2411)

PR google#510 narrowed credential resolution from the registry to the repository level.
CheckPushPermission was never updated. Therefore, a config.json holding both a
registry-level entry and a more specific repository-level one made the check
reject a push that Write then performed successfully.
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
crane 0.22.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## What's Changed
* mutate: let Time and Canonical take tarball.LayerOption by @mzihlmann in google/go-containerregistry#2403
* build: add multi-architecture Cloud Build configurations for crane, gcrane, and krane by @tprussak in google/go-containerregistry#2412
* remote: resolve push-check credentials against the repository by @mzihlmann in google/go-containerregistry#2411
* Allow single-character repository paths by @semx in google/go-containerregistry#2407
* fix: add missing substitutions and workspace cleanup to new build files by @tprussak in google/go-containerregistry#2413
* remote: retry failed Puller and Pusher initialization by @iahsanGill in google/go-containerregistry#2406
* build(deps): bump the actions group across 1 directory with 8 updates by @dependabot[bot] in google/go-containerregistry#2405
* build(deps): bump the go-deps group across 1 directory with 3 updates by @dependabot[bot] in google/go-containerregistry#2415
* go.mod: bump Go version + add toolchain directive to replace .go-version file by @Subserial in google/go-containerregistry#2416
* fix: Fix new build options and provenance by @tprussak in google/go-containerregistry#2417
* fix(build): unify new build flow into cloudbuild_v2.yaml by @tprussak in google/go-containerregistry#2419

## New Contributors
* @mzihlmann made their first contribution in google/go-containerregistry#2403
* @tprussak made their first contribution in google/go-containerregistry#2412
* @semx made their first contribution in google/go-containerregistry#2407

**Full Changelog**: https://github.com/google/go-containerregistry/compare/v0.21.9...v0.21.10</pre>
  <p>View the full release notes at <a href="https://github.com/google/go-containerregistry/releases/tag/v0.22.0">https://github.com/google/go-containerregistry/releases/tag/v0.22.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!17674
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CheckPushPermission still resolves credentials at registry scope

3 participants