Harbor
Open source container image registry with security scanning and RBAC
Harbor 2.15 patches swap Redis for Valkey and tighten registry security.
◆Recent moves
- 1d ago
2.15.4-rc1 restores private-network webhooks and legacy signer pulls
Webhooks may target private networks by default again, legacy signer pulls are allowed by default and exposed in harbor.yml, and Trivy moves to 0.75. It walks back hardening defaults that broke existing deployments.
View source ↗ - 16d ago
2.15.3-rc2: second candidate of the security patch
A second release candidate carrying the same 2.15.3 security cherry-picks as rc1. A packaging step toward the final patch.
View source ↗ - 29d ago
2.15.3-rc1: manifest size limit and proxy-cache poisoning fix
Adds a manifest upload size limit, prevents proxy-cache poisoning via robot-name prefixes, constrains registry ping to saved URLs and neutralises formulas in scan CSV exports. It's the main hardening release in the 2.15 patch series.
View source ↗ - 3mo ago
2.15.2-rc3: Valkey replaces Redis as cache backend
Swaps Redis for Valkey as the cache backend, bumps Go to 1.26.3 and adjusts cosign verification to ignore the transparency log. The Valkey move is an operational change for anyone running Harbor's cache separately.
View source ↗ - 3mo ago
2.15.2-rc2: earlier candidate of the Valkey patch
An earlier candidate with the same Valkey and Go changes as rc3. Superseded within days.
View source ↗