github inferstep/ATLAS v3.1.5
V3.1.5 "Maia"

2 hours ago

A security release. 3.1.5 fixes a way to skip ATLAS's workspace check with an argument name in another letter case: GHSA-c3p6-m657-h629. Please upgrade.

Security

  • Tool argument names must now be lowercase, as every tool's names are. A name in another letter case (for example "PATH") or with non-ASCII letters is refused. Before, such a name skipped the workspace check, and in 3.1.4 a "Command" argument also skipped the destructive-command deny-list.
  • insert_after's path is now checked at dispatch, like every other write.

Upgrade

  • Existing install: in your ATLAS folder, run git pull first, then atlas upgrade. Or re-run the install command.
  • New install: curl -fsSL https://raw.githubusercontent.com/inferstep/ATLAS/main/scripts/atlas-bootstrap.sh | bash

Verify

  • The tag v3.1.5 is SSH-signed by a key in .github/allowed_signers (in a checkout: git -c gpg.ssh.allowedSignersFile=.github/allowed_signers verify-tag v3.1.5).
  • The images are signed by the inferstep/ATLAS build workflow:
    cosign verify --certificate-identity https://github.com/inferstep/ATLAS/.github/workflows/build-images.yml@refs/tags/v3.1.5 \
      --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/inferstep/atlas-proxy:3.1.5
    

To hear about releases only, choose Watch → Custom → Releases on the repository page.

Full list: CHANGELOG.md.

Don't miss a new ATLAS release

NewReleases is sending notifications on new releases.