ORAS CLI

ORAS Project·ORASProject.ORAS

OCI registry client - managing content like artifacts, images, packages

winget install --id ORASProject.ORAS --exact --source winget

Latest 1.3.4·August 27, 2026

Release Notes

ORAS CLI v1.3.4 is a security-focused maintenance release. It scopes registry credentials — mTLS client certificates, custom --header values, and --debug trace output — strictly to the configured registry origin, and adds an opt-in --force copy mode for registries that report incomplete content as present.

Highlights

• 🔒 Security: three credential-scoping advisories are fixed — mTLS client certificates (GHSA-h3wm-jjqf-8jm2), custom request headers (GHSA-whvf-jp7m-59f3), and --debug HTTP traces (GHSA-5jhf-2qmf-m8c5). All three were reported by Hardik Mehta (@hardw00t). • ✨ oras cp and oras push gain --force, which walks every referenced manifest instead of trusting the destination's Exists() response — this fixes manifest blob unknown failures against pull-through caches (ACR Artifact Cache, ECR pull-through, GAR remote repositories). • ⚡ Shared authentication cache: repeated in-process calls now reuse credentials instead of re-running the 401 challenge on every call. • 🛡️ Supply-chain hardening: release checksums and archives are now GPG-signed in the release workflow with the ORAS project release key.

✨ Features

• Add --force to oras cp/oras push to handle partially-populated destinations by @renshao in #2061 • Save authentication context between calls so in-process usage authenticates once by @TerryHowe in #1923 • Sign release checksums in the release workflow by @TerryHowe in #2112

🐛 Bug Fixes

• Avoid send on closed channel in the progress messenger by @harshasiddartha in #2126 • Route logger output to command stderr by @vigneshakaviki in #2123

🔒 Security

• Registry mTLS client certificates are disclosed to cross-origin TLS peers (CWE-201, GHSA-h3wm-jjqf-8jm2):a certificate supplied via --cert-file/--key-file was installed on a single shared transport and presented to any HTTPS peer, including cross-origin redirect and bearer-realm targets and HTTPS proxies. The certificate is now scoped to the configured registry origin. • Registry custom credentials are forwarded across HTTP origins (GHSA-whvf-jp7m-59f3):values passed with --header/--from-header/--to-header were appended to every request, including redirect targets and bearer token realms on other hosts. They are now stripped for any origin that does not match the configured registry. • Debug HTTP traces expose replayable bearer credentials (CWE-532, GHSA-5jhf-2qmf-m8c5):--debug trace output persisted URL userinfo and query parameters (e.g. pre-signed X-Amz-Signature), Location/Content-Location/Referer headers, cookies, proxy authorization, configured custom headers, and token response bodies. These are now redacted.

All three were reported by Hardik Mehta (@hardw00t).

🧹 Maintenance

• Replace containerd/console with golang.org/x/term by @TerryHowe in #2062 • Group GitHub Actions Dependabot updates by @TerryHowe in #2119 • Float the Go version in the release workflow to match the other workflows by @sooraj-sky in #2137 • Cover the shared auth client cache in tests by @subotac in #2127 • Strengthen display handler test assertions by @TerryHowe in #2055 • Expect scrubbed custom header values in e2e by @TerryHowe in #2133 • Dependency bumps:sirupsen/logrus 1.9.4 → 1.10.1 (#2130, #2138), onsi/ginkgo/v2 2.32.1 in /test/e2e (#2129), library/golang 1.26.5 → 1.27.0-alpine (#2134, #2139), and grouped GitHub Actions updates (#2115, #2116, #2117, #2120, #2122, #2124, #2128, #2135, #2140)

New Contributors

• @renshao made their first contribution in #2061 • @vigneshakaviki made their first contribution in #2123 • @harshasiddartha made their first contribution in #2126 • @subotac made their first contribution in #2127 • @sooraj-sky made their first contribution in #2137

Full Changelog:https://github.com/oras-project/oras/compare/v1.3.3...v1.3.4

Installer type: zip

x64—FFDB6AA40267686B5D507DA1F21A57FC502A9A7C86B90C54557D335644C99DBD

Details

Homepage
https://oras.land/
License
Apache-2.0 license
Publisher
ORAS Project
Support
https://github.com/oras-project/oras
Moniker
oras

Tags

dockerociregistrystorage

Older versions (9)

1.3.3
x64—30CA213A565A450DE33001DAE83053DB53C221E6674C5233DC3406B686657969
1.3.0
x64—B050E93AA0DC7A79A61FA8E4074DFA302C41D4AF01B634FE393C5DD687536AEE
1.2.3
x64—8FE890F5C6C89B06FB138839E533A112E0FC026A25B2C8C1B042B32455A56947
1.2.2
x64—25110D69D220BF55469A14C243F759305737DAC6672FB47B4AF4E43B000F55F5
1.2.1
x64—E072DAC29EB4A4B62520B52193E028420C159E5EC192F28BFEBFB11F81C7D6D8
1.2.0
x64—F110B42A20BD4728FB0428D36EE6ED10DE58CD986BBA8E95ECC4F0272CB017BA
1.1.0
x64—2AC83631181D888445E50784A5F760F7F9D97FBA3C089E79B68580C496FE68CF
1.0.1
x64—0B9C50EDA7AA384D435B31710264D08C77A5E83EE6560EE6E13CA46A6ACEC1BA
1.0.0
x64—E47E91FBC72CFE4E5C89321EBC5AF953BCAFA8A9ECDB0B4FBD53FD136578E03E