A security release. 3.1.5 fixes a way to skip ATLAS's workspace check with an argument name in another letter case: GHSA-c3p6-m657-h629. Please upgrade.
Security
- Tool argument names must now be lowercase, as every tool's names are. A name in another letter case (for example
"PATH") or with non-ASCII letters is refused. Before, such a name skipped the workspace check, and in 3.1.4 a"Command"argument also skipped the destructive-command deny-list. insert_after's path is now checked at dispatch, like every other write.
Upgrade
- Existing install: in your ATLAS folder, run
git pullfirst, thenatlas upgrade. Or re-run the install command. - New install:
curl -fsSL https://raw.githubusercontent.com/inferstep/ATLAS/main/scripts/atlas-bootstrap.sh | bash
Verify
- The tag
v3.1.5is SSH-signed by a key in.github/allowed_signers(in a checkout:git -c gpg.ssh.allowedSignersFile=.github/allowed_signers verify-tag v3.1.5). - The images are signed by the inferstep/ATLAS build workflow:
cosign verify --certificate-identity https://github.com/inferstep/ATLAS/.github/workflows/build-images.yml@refs/tags/v3.1.5 \ --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/inferstep/atlas-proxy:3.1.5
To hear about releases only, choose Watch → Custom → Releases on the repository page.
Full list: CHANGELOG.md.