Skip to content

Fix for valid tag@digest image references during registry inspection - #1311

Merged
Abdurrahmaan Iqbal (abdurriq) merged 14 commits into
devcontainers:mainfrom
v-Kaniska244:image-extract-error
Sep 29, 2026
Merged

Abdurrahmaan Iqbal (abdurriq) merged 14 commits into
devcontainers:mainfrom
v-Kaniska244:image-extract-error

Conversation

@v-Kaniska244

@v-Kaniska244 Kaniska (v-Kaniska244) commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fix OCI reference parsing for references that contain both a tag and a digest as reported in #1307:

mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:...

Problem

getRef() previously removed the digest but left the tag attached to the repository resource:

mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm

The resulting path contained :, failed repository path validation, and caused getRef() to return undefined.

Tag-and-digest references are valid OCI references. The digest identifies the exact manifest, while the tag remains useful reference metadata.

Changes

  • Detect and extract a tag before parsing a digest.
  • Remove the tag from resource and path.
  • Preserve the extracted tag in OCIRef.tag.
  • Continue using the digest as OCIRef.version.
  • Distinguish a tag separator from a colon in a registry port.

For example:

docker.io:8001/example/features/test:1.2.3@sha256:...

is parsed as:

registry: docker.io:8001
resource: docker.io:8001/example/features/test
tag: 1.2.3
digest: sha256:...
version: sha256:...

Test Coverage

Added regression coverage in containerFeaturesOCI.test.ts for:

  • An MCR reference containing both a tag and digest.
  • A reference containing a registry port, tag, and digest.
  • Correct registry, namespace, resource, path, tag, and digest parsing.
  • Digest precedence for the resolved version.

Validation

  • Focused OCI parser tests pass.
  • Full OCI test suite passes with 32 tests.
  • Type checking passes.
  • ESLint passes.

@v-Kaniska244
Kaniska (v-Kaniska244) marked this pull request as ready for review September 29, 2026 06:19
@v-Kaniska244
Kaniska (v-Kaniska244) requested a review from a team as a code owner September 29, 2026 06:19
@abdurriq
Abdurrahmaan Iqbal (abdurriq) merged commit 3e363f6 into devcontainers:main Sep 29, 2026
43 of 45 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants