A security release. 3.1.6 fixes a way for a command behind a prefix or a nested shell to skip ATLAS's command policy: GHSA-m9w4-p32x-chx9. Please upgrade. Thanks to @Rendegou, who reported and fixed it.
Security
- The command policy now looks past command prefixes and checks the command each nested shell,
evalorenv -Slayer would run, up to 16 layers. - A command whose quoting or layers can't be checked completely is refused, with a message saying so.
- One rarely used form is now refused:
evalof generated command text with nested quoting. Run the generated command directly instead.
Upgrade
- Existing install: in your ATLAS folder, run
git pullfirst, thenatlas upgrade. Or re-run the install command. - New install:
curl -fsSL https://raw.githubusercontent.com/inferstep/ATLAS/main/scripts/atlas-bootstrap.sh | bash
Verify
- The tag
v3.1.6is SSH-signed by a key in.github/allowed_signers(in a checkout:git -c gpg.ssh.allowedSignersFile=.github/allowed_signers verify-tag v3.1.6). - The images are signed by the inferstep/ATLAS build workflow:
cosign verify --certificate-identity https://github.com/inferstep/ATLAS/.github/workflows/build-images.yml@refs/tags/v3.1.6 \ --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/inferstep/atlas-proxy:3.1.6
To hear about releases only, choose Watch → Custom → Releases on the repository page.
Full list: CHANGELOG.md.