Skip to content

Detect registry hosts in image names like Docker does - #1310

Open
Fabian Schurig (FabianSchurig) wants to merge 2 commits into
devcontainers:mainfrom
FabianSchurig:fix/registry-host-detection-811
Open

Fabian Schurig (FabianSchurig) wants to merge 2 commits into
devcontainers:mainfrom
FabianSchurig:fix/registry-host-detection-811

Conversation

@FabianSchurig

Copy link
Copy Markdown

Fixes #811.

qualifyImageName treated every image name with a single / as a Docker Hub name. A private registry such as registry.example.com/image was therefore looked up on docker.io first, and a host with a port (registry.example.com:5000/image) failed to parse. inspectDockerImage then fell back to a full docker pull.

The first path segment is now a registry host when it contains . or :, is localhost, or contains uppercase letters. That is Docker's splitDockerDomain rule. Names without a host are qualified as docker.io, including nested paths: foo/random/image becomes docker.io/foo/random/image. Previously that name was left unchanged, which Docker itself does not do. docker.io/<name> still becomes docker.io/library/<name>.

A repository with no extra path segment (registry.example.com:5000/image) now parses. getRef used to build the path as /image, which its own validation rejected.

The Podman base-image path uses the same hasRegistryHost check. It previously missed myregistry:5000/image and localhost:5000/image and prefixed them with localhost/.

An image name with one slash was always treated as a Docker Hub name, so a
private registry was looked up on docker.io first (devcontainers#811) and a registry host
with a port failed to parse. The first segment is a registry host when it
contains a dot or a colon, is localhost, or has uppercase letters, matching
Docker's splitDockerDomain. Names without a host, including nested paths, are
qualified as docker.io. A repository with no extra path segment now parses.
The Podman base-image path uses the same check.
Copilot AI lite review requested due to automatic review settings September 23, 2026 16:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

OCI parsing can accept invalid identifiers and generate malformed endpoints.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates Docker and Podman image qualification to recognize private registry hosts, ports, localhost, and nested paths.

Changes:

  • Added Docker-compatible registry detection.
  • Updated Podman base-image handling.
  • Adjusted OCI path parsing.
  • Added registry and qualification tests.
File Summary
src/​test/​dockerUtils.test.ts Adds registry detection and qualification tests.
src/​spec-node/​utils.ts Implements registry-aware image qualification.
src/​spec-node/​containerFeatures.ts Reuses registry detection for Podman.
src/​spec-configuration/​containerCollectionsOCI.ts Contains unresolved moderate issues involving invalid feature identifiers and registry-only inputs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/spec-configuration/containerCollectionsOCI.ts Outdated
A name with no slash, such as ghcr.io, was accepted once the empty namespace
stopped producing a leading slash. Keep that case invalid, and still accept a
host plus repository such as registry.example.com:5000/image.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependency confusion attack from looking for manifest in docker.io first

2 participants