mirror of
https://github.com/distribution/distribution.git
synced 2026-01-30 14:08:28 +00:00
We found some examples of manifests with URLs specififed that did not provide a digest or size. This breaks the security model by allowing the content to change, as it no longer provides a Merkle tree. This was not intended, so explicitly disallow by tightening wording. Signed-off-by: Justin Cormack <justin.cormack@docker.com>