Skip to content
CAI
Software that uses CAICheck a score

goharbor/harbor

53.4

Adequate · 24 September 2026

156.9k

lines of production code

Go

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Harbor, an open-source container image registry that manages, stores, and distributes container images and Helm charts. It provides a comprehensive platform for artifact lifecycle management, including support for diverse artifact types like SBOMs, WebAssembly, and CNABs, alongside robust security features such as vulnerability scanning via Trivy and immutable rule enforcement. The system facilitates secure collaboration through role-based access control, automated replication between registries, and proxy caching capabilities, while offering extensive operational visibility through Prometheus metrics, audit logging, and configurable webhook notifications.

How it got here

2016–2018 — Harbor v1.8.0 architecture overhaul

77 changes.

This period focused on the foundational restructuring of Harbor v1.8.0, involving the complete removal of legacy Beego-based controllers, authentication plugins, and deployment scripts. The work established a new modular architecture with a unified API layer, a V2 Job Service, and a modernized Angular frontend, while migrating the database backend to PostgreSQL and enforcing non-root container execution for improved security.

2019–2020 — RBAC, Jobservice, and Artifact Processing

96 changes.

This period focused on implementing a comprehensive RBAC permission model and enhancing the Jobservice with a robust, Redis-backed architecture for task execution and reliability. Significant work was also done to refactor artifact processing into a pluggable system, supporting diverse types like Helm charts and CNABs, while introducing new features for P2P preheating and Prometheus metrics collection.

2021–2026 — Architectural refactoring and new features

59 changes.

This period focused on a comprehensive architectural overhaul, introducing a centralized configuration library, a new modular RBAC system, and a dedicated job scheduler to replace legacy implementations. It also expanded platform capabilities by adding support for WebAssembly and CNAI artifacts, implementing chunked replication, and integrating Valkey as the cache backend.

Features

Add 404 error page and password reset email template

The core views now include a dedicated 404 error page that displays a styled 'Page Not Found' message with a link back to the home page, and a new email template for password reset notifications that provides a clickable link containing the reset UUID.

src/core/views · high confidence

Add Dockerfile and entrypoint for the Harbor Exporter service

This change introduces the containerization artifacts for the Harbor Exporter, including a base image (Dockerfile.base) built on Photon OS 5.0 and a main Dockerfile that compiles the Go exporter binary and packages it. The entrypoint script ensures custom certificates are installed before starting the exporter process, and the container includes a health check that verifies the metrics endpoint is responding on the default port 8001.

make/photon/exporter · high confidence

Add Harbor Exporter for Prometheus metrics

Introduces a new standalone exporter service that exposes Harbor metrics via Prometheus. The service initializes a PostgreSQL database connection (using the jackc/pgx driver), configures a Redis backend worker, and starts an HTTP server to serve metrics. It supports configuration for TLS, caching, and request limits, and includes pprof support for profiling.

src/cmd/exporter · high confidence

Add P2P preheat handler for artifact events

A new event handler named 'P2PPreheat' has been added to the P2P controller to automatically trigger preheating of images when specific events occur. The handler listens for artifact push, image scan, and artifact label events, filtering for image-type artifacts and invoking the preheat enforcer to initiate the preheat process. This enables seamless integration between artifact lifecycle events and the P2P preheat mechanism.

src/controller/event/handler/p2p · high confidence

Add Prometheus metrics collection for HTTP requests and Job Service tasks

This change introduces a new metrics library in src/lib/metric that exposes Prometheus-compatible metrics for monitoring. It defines collectors for general HTTP traffic (in-flight requests, total request counts, and request duration summaries) and for the Job Service (task counts by type and status, task processing time, and service info). A new HTTP server endpoint is provided to serve these metrics, configurable via the METRIC\_NAMESPACE and METRIC\_SUBSYSTEM environment variables, allowing users to integrate Harbor's operational data into their existing Prometheus monitoring stacks.

src/lib/metric · high confidence

Add Redis RDB migration manager for periodic job policies

Introduces a new migration framework in the jobservice to handle Redis data schema upgrades, specifically targeting the transition of periodic job policies from pre-1.8.0 formats to version 1.8.1. The new \Manager\ component orchestrates a chain of migrators, reading the current schema version from Redis and executing necessary transformations, such as adding missing \numeric\_policy\_id\ fields and updating job status to 'Scheduled' for legacy periodic jobs like Garbage Collection and Scan All. This ensures data integrity when upgrading from older Harbor versions that used different Redis structures for scheduling.

src/jobservice/migration · high confidence

Add in-memory cache implementation

A new in-memory cache implementation has been added to the \src/lib/cache/memory\ package, providing a \Cache\ struct backed by a thread-safe \sync.Map\. This implementation supports standard cache operations including saving, fetching, deleting, and checking for key existence, with support for configurable expiration times and key prefixing. It also includes a \Scan\ capability to iterate over keys matching a pattern, automatically cleaning up expired entries during the scan. The implementation registers itself as the 'memory' cache provider via the \cache.Register\ function, making it available for use by other components that rely on the \cache.Cache\ interface.

src/lib/cache/memory · high confidence

Add job service execution context

The job service now includes a new Context struct in the env package to manage shared materials and system control channels during job execution. This context holds the system context with cancel capability, a WaitGroup for coordination, an error channel to report failures to the bootstrap component, and a reference to the base job context, providing the necessary infrastructure for managing job lifecycle and error handling.

src/jobservice/env · high confidence

Add job service to purge audit logs

A new purge job implementation has been added to the job service, enabling the automated deletion of audit records. This job supports configurable retention periods, dry-run modes for safe testing, and filtering by specific event types. It processes both the standard audit log and the extended audit log (audit\_log\_ext) tables, ensuring comprehensive cleanup of historical audit data based on the defined retention policy.

src/jobservice/job/impl/purge · high confidence

Add retry library with configurable backoff and abort support

A new retry utility has been added to the codebase, providing a \Retry\ function that executes a given operation with exponential backoff and jitter by default. Users can configure the initial and maximum intervals, total timeout duration, and a callback function for failure events. The library also supports an \Abort\ mechanism to immediately stop retries and return a specific error, offering a robust way to handle transient failures in operations.

src/lib/retry · high confidence

Add sample job implementation for job service development

A new sample job implementation has been added to the job service to demonstrate how to create custom jobs. This includes a job type that validates parameters (requiring an 'image' parameter starting with 'demo'), handles retries, limits concurrency to one instance, and supports progress check-ins and stop commands. This serves as a reference for developers implementing new job types.

src/jobservice/job/impl/sample · high confidence

Added genyaml tool to generate Swagger configuration definitions

A new \genyaml\ command has been added to the \src/cmd/swagger\ directory. This utility generates YAML files defining Swagger schema structures for system configuration items, specifically creating \configurations.yml\ and \configurationsResponse.yml\. It iterates through the application's metadata configuration list, mapping internal types (such as string, boolean, and integer) to their corresponding Swagger types and response object references, while explicitly excluding system-scope items, the \scan\_all\_policy\, and password fields from the response definitions.

src/cmd/swagger · high confidence

Added icon definitions for new artifact types and accessories

The icon library now includes SHA-256 digests for new artifact types, specifically WebAssembly (WASM) and CNAI, as well as for accessory icons related to Notation, Cosign, Nydus, and SBOM. This allows the UI to display appropriate visual indicators for these specific artifact categories and their associated security or metadata accessories.

src/lib/icon · high confidence

Added pattern matching library for repository filters

The \src/lib/pattern\ package now provides a reusable library for validating and matching repository filters using either regular expressions or doublestar (glob) patterns. This implementation includes validation logic to ensure pattern syntax correctness (such as anchoring regexes and validating doublestar syntax) and matching functions that allow users to define repository access rules via configurable pattern kinds.

src/lib/pattern · high confidence

Added thread-safe list utility for job service

A new synchronized list implementation (SyncList) has been added to the job service common package to provide a thread-safe container for managing job-related data. This utility supports safe concurrent iteration with removal capabilities and prevents nil values from being added to the list, ensuring data integrity during job processing operations.

src/jobservice/common/list · high confidence

Automated daily cleanup of system artifacts

A new scheduled job has been introduced to automatically clean up system artifacts on a daily basis (cron spec: 0 0 0 \* \* \*). This change adds a controller and callback mechanism in the system artifact package that registers a cleanup task with the scheduler, ensuring that unused system artifacts are removed without manual intervention.

src/controller/systemartifact · high confidence

Automated internal TLS certificate generation with SAN support

The \gencert.sh\ script in the Photon prepare directory now automatically generates internal TLS certificates for all Harbor components (proxy, portal, core, jobservice, registry, registryctl, trivy-adapter, and harbor\_db) using a self-signed CA. This change ensures that generated certificates include Subject Alternative Names (SANs) for each service, enabling secure internal communication without requiring users to manually create or import their own CA key pairs.

make/photon/prepare/scripts · high confidence

Configurable Trivy adapter environment and TLS support

The Trivy adapter now supports extensive configuration via environment variables, allowing users to set scan timeouts, proxy settings (HTTP/HTTPS/NO\_PROXY), database repositories, and specific update skip flags (general and Java DB). Additionally, the adapter can now be configured to use TLS for its API server when internal TLS is enabled, securing the communication channel between the adapter and the core service.

make/photon/prepare/templates/trivy-adapter · high confidence

Configurable job service logger framework with multiple backends

The Job Service now uses a new, configurable logger framework that supports multiple backend types simultaneously, including file, database, and standard output. This change introduces a unified entry point that can aggregate logs across these backends, along with built-in sweepers to automatically clean up outdated log entries and getters to retrieve stored log data. Users can now configure logging behavior via settings for log levels, storage locations, and retention policies, replacing the previous static logging implementation.

src/jobservice/logger · high confidence

Exporter environment configuration for Photon template

The Photon build template now includes a new environment configuration file for the exporter component. This file defines runtime settings such as log level, port, metrics endpoints, and connection parameters for Redis and PostgreSQL, ensuring the exporter is correctly wired to the core service and database within the Photon deployment.

make/photon/prepare/templates/exporter · high confidence

GDPR audit log data masking job

A new job service component has been added to support GDPR compliance by masking user identities in audit logs. This job accepts a username parameter and updates the stored username in both the standard audit log manager and the extended audit log manager with a generated checksum, effectively anonymizing the user's identity in historical records.

src/jobservice/job/impl/gdpr · high confidence

HTTP Auth Proxy now supports group population and admin role assignment

The HTTP Auth Proxy authenticator has been enhanced to automatically populate user groups and assign admin privileges based on configuration. When a user authenticates, the system now reviews the session token to fetch group information from the external provider and onboard these groups into Harbor, allowing for role-based access control. Additionally, administrators can now define specific usernames or group names that are automatically treated as Harbor admins, and the system supports configuring whether username lookups are case-sensitive.

src/core/auth/authproxy · high confidence

Helm chart artifact processor added to support values, readme, and dependencies extraction

A new processor for Helm chart artifacts has been introduced in the artifact controller, enabling the system to recognize and handle Helm charts via the 'application/vnd.cncf.helm.config.v1+json' media type. This change allows users to extract specific chart additions—namely values.yaml, README.md, and dependency lists—through the artifact API, providing structured access to chart metadata and content without needing to parse the raw OCI artifact layers manually.

src/controller/artifact/processor/chart · high confidence

Immutable rule management controller

The \src/controller/immutable\ package now provides a dedicated controller for managing immutable rules, including creating, updating, listing, and deleting rules scoped to specific projects. This controller acts as an abstraction layer over the underlying immutable rule manager, handling operations such as enabling/disabling rules and cascading deletions when a project is removed.

src/controller/immutable · high confidence

Initial repository structure and build configuration for Harbor v1.8.0

This change establishes the foundational structure for the Harbor project, introducing the initial Makefile build system, version definitions (including Trivy v0.72.0 and Registry v2.8.3), and essential documentation files such as CHANGELOG.md, CONTRIBUTING.md, and ADOPTERS.md. It also adds developer tooling configurations like .spectral.yaml for API linting, .gitmessage for commit guidelines, and .dockerignore to streamline the build process.

(repo-wide) · high confidence

Introduce P2P preheat policy enforcement and controller

This change adds the core controller and policy enforcer for the P2P preheat feature in the \src/controller/p2p/preheat\ package. The new \Controller\ manages distribution provider instances (creating, listing, updating, and deleting) and preheat policies (CRUD operations), including health checks for provider instances. The \Enforcer\ implements the logic to trigger preheating based on policies (manual or scheduled) or specific artifact events, handling credential generation and artifact selection. Unit tests are included to verify controller operations and enforcer behavior.

src/controller/p2p · high confidence

Introduce Redis-based job runner with retry logic for missing stats

Added a new Redis-backed job runner implementation (\redis.go\) and its corresponding test suite (\redis\_test.go\) to the jobservice runner package. This new runner wraps job execution to integrate with the Redis worker queue, featuring a retry mechanism that handles transient 'NOT\_FOUND' errors when job statistics are not yet ready, ensuring jobs do not fail prematurely. The implementation also includes panic recovery, tracing instrumentation, and status tracking via the lifecycle controller. A helper utility (\wrapper.go\) was added to facilitate wrapping job handlers into the required interface.

src/jobservice/runner · high confidence

Introduce UAA authentication provider

Users can now authenticate against a UAA (User Account and Authentication) server. This change adds a new UAA authentication implementation in the core auth module, enabling login via UAA credentials and automatically syncing user profile details like email and real name from the UAA server to the local user database upon authentication.

src/core/auth/uaa · high confidence

Introduce accessory management for artifact extensions

Added a new \pkg/accessory\ module that provides the data access, model, and manager layers for handling artifact accessories. This change introduces the \artifact\_accessory\ database table and the \Accessory\ model to store metadata for linked artifacts such as Cosign signatures, Notation signatures, Nydus accelerators, and Harbor SBOMs. The implementation includes a factory-based model system to support different accessory types and a manager to handle CRUD operations, enabling the system to track and manage these extensions alongside their parent artifacts.

src/pkg · high confidence

Introduce annotation parser for artifact metadata

Added a new annotation parsing system in the artifact controller that registers and executes versioned parsers (starting with v1alpha1) to extract metadata from artifact manifests. This implementation processes specific annotations such as skip-lists to filter extra attributes and icons to associate image assets with artifacts, providing the foundational infrastructure for future annotation versions.

src/controller/artifact/annotation · high confidence

Introduce artifact icon retrieval API

The system now provides an API to retrieve icons for artifacts. This controller resolves built-in icons for specific artifact types (such as images, charts, CNAB, Cosign, Notation, Nydus, WebAssembly, SBOM, and CNAI) and falls back to fetching custom icons stored as blobs. Retrieved icons are standardized to PNG format and resized to 50x50 pixels, with results cached to improve performance.

src/controller/icon · high confidence

Introduce common event metadata model and resolver framework

A new model and resolver interface have been added to the common event metadata package to standardize how audit information is extracted from HTTP requests. The \Metadata\ struct now captures essential request details such as username, IP address, request method, and payload, while the \Resolver\ interface allows specific URL patterns to define custom logic for parsing this data into common event structures. This change provides a centralized mechanism for other components to register resolvers that can transform raw request metadata into structured audit events, supporting features like audit logging and user login event tracking.

src/controller/event/metadata/commonevent · high confidence

Introduce dedicated local database authentication module

A new \src/core/auth/db\ package has been added to handle local database authentication. This module implements the \Authenticator\ interface, allowing users to authenticate against the local database using the \user.Manager\ for credential matching and user lookup. The implementation includes logic to validate local passwords and search for existing users, with corresponding unit tests verifying the user search functionality.

src/core/auth/db · high confidence

Introduce job execution data models

A new \models.go\ file has been added to the \src/common/job/models\ package, defining the core data structures for the job system. This includes \JobRequest\ and \JobData\ for launching jobs, \StatsInfo\ for tracking job status and metadata (such as upstream job IDs and cron specifications), and \JobPoolStats\ for monitoring worker pool health. These models provide the foundational schema for job execution, status reporting, and worker management within the application.

src/common/job/models · high confidence

Introduce project metadata controller

A new controller has been added to manage project metadata operations, providing an interface for adding, deleting, updating, and retrieving metadata associated with specific projects. This controller acts as a facade, delegating core logic to the underlying project metadata manager, thereby establishing a dedicated layer for handling project-specific metadata interactions.

src/controller/project/metadata, src/controller/repository · high confidence

Introduce project-level storage quota driver

A new quota driver has been added to manage storage limits on a per-project basis. This driver registers itself to handle project-specific quotas, allowing administrators to configure storage limits that apply individually to each project rather than globally. It calculates current usage by summing the total size of blobs within a project and validates that requested limits are within supported ranges. The implementation includes a batched loader to efficiently fetch project and owner details when resolving quota references.

src/controller/quota/driver/project · high confidence

Introduce proxy cache controller with local fallback and rate-limit handling

The proxy cache feature now includes a dedicated controller in \src/controller/proxy\ that manages pull-through caching logic. This controller implements \UseLocalManifest\ and \UseLocalBlob\ to serve artifacts from the local cache when available, specifically handling upstream 429 rate-limit errors by falling back to local copies if they exist. It also supports a project-level \ProxyCacheLocalOnNotFound\ option, allowing the system to serve locally cached artifacts even when the upstream registry does not have them. The implementation includes inflight request deduplication to prevent duplicate pushes and integrates with the manifest cache handlers to store and retrieve manifest lists and image indexes.

src/controller/proxy · high confidence

Introduce query parameter handling for job stats

The job service now includes a new query package that defines constants for pagination and filtering parameters (such as page number, page size, and job kind) and provides an ExtraParameters type to manage non-paginated query arguments. This infrastructure supports the new get jobs API, enabling more powerful job stats management by allowing clients to filter and paginate job execution data effectively.

src/jobservice/common/query · high confidence

Introduce security context abstraction and context helpers

The security package now provides a \Context\ interface that abstracts authentication and authorization operations, including methods to check identity (\IsAuthenticated\, \GetUsername\), privileges (\IsSysAdmin\, \IsSolutionUser\), and permissions (\Can\). To facilitate usage, \NewContext\ and \FromContext\ functions are added to store and retrieve this security context within standard Go contexts, enabling consistent access to security state across the application.

src/common/security · high confidence

Introduce selector library for artifact filtering

A new selector library has been added to the codebase to provide a standardized mechanism for filtering artifacts. This includes a Candidate data structure that captures repository details, tags, digests, and metadata such as vulnerability severity, alongside a Selector interface and Factory pattern for implementing custom filtering logic. This change supports the preheat policy feature by enabling artifact filters.

src/lib/selector · high confidence

Introduction of a unified BaseAPI controller for common HTTP operations

The \src/common/api\ package now provides a \BaseAPI\ struct that consolidates shared HTTP handling logic for all API controllers. This includes standardized methods for parsing path parameters, decoding JSON requests, validating input, handling pagination headers, and rendering consistent error responses. By centralizing these utilities, API endpoints can rely on a single, consistent foundation for request processing and error management.

src/common/api · high confidence

Introduction of registry controller with validation and deletion safeguards

The registry controller in src/controller/registry has been introduced to manage registry lifecycle operations. It enforces validation rules for registry names and URLs, including automatic normalization of URLs without schemes to HTTP. Deletion of registries is now protected by checks that prevent removal if the registry is referenced by replication policies (as source or destination) or proxy cache projects, ensuring data integrity.

src/controller/registry · high confidence

Job log retrieval and cleanup now supports database storage

The JobService logger framework now includes implementations for retrieving and sweeping logs stored in the database, in addition to the existing file-based approach. This change introduces a \DBGetter\ to fetch log content from the database (respecting size limits) and a \DBSweeper\ to delete outdated database log entries, alongside their corresponding unit tests. This ensures that users can view and manage job logs regardless of whether they are persisted to the file system or the database.

src/jobservice/logger/getter · high confidence

Job logs can now be stored in the database

The job service logger backend now supports persisting job logs directly to the database (PostgreSQL) via a new DBLogger implementation. This change introduces a configurable logging framework that allows logs to be written to the database, in addition to existing backends for file and standard output, enabling users to retrieve and manage job logs through the database.

src/jobservice/logger/backend · high confidence

New AES encryption library with file-based key management

A new encryption library has been added to the codebase, introducing an AES-based encryptor that handles string encryption and decryption. The implementation uses a pluggable key provider pattern, defaulting to a file-based provider that reads the encryption key from a specified path (configurable via the KEY\_PATH environment variable, defaulting to /etc/core/key). This change introduces a new public API for reversible encryption, allowing other components to securely encrypt and decrypt sensitive data using a centralized key management approach.

src/lib/encrypt · high confidence

New CNAB artifact support and unified processor registry

The artifact controller now includes a dedicated processor for CNAB (Cloud Native Application Bundle) artifacts, enabling Harbor to recognize and abstract metadata from CNAB bundles. This is part of a broader restructuring that introduces a centralized processor registry (\processor.go\) with a fallback \DefaultProcessor\ for unknown artifact types, replacing the previous scattered handling logic. The new architecture allows specific processors to register themselves for particular media types, ensuring that CNAB artifacts are processed correctly while maintaining backward compatibility for other artifact types through the default fallback.

src/controller/artifact/processor · high confidence

New CNAI model artifact processor with safe content extraction

This change introduces a new processor for CNAI (Container Native AI) model artifacts, enabling Harbor to handle model-specific content. The processor registers for the \CNAI\ artifact type and supports extracting three addition types: README, LICENSE, and a hierarchical file list. It relies on the \modelpack/model-spec\ library for manifest parsing and implements strict size limits (4MB default) to prevent decompression bombs and memory exhaustion, enforcing limits on both declared blob sizes and actual materialized content for both tar and raw formats.

src/controller/artifact/processor/cnai · high confidence

New Job Service monitoring API for pools, workers, queues, and job control

A new monitoring controller has been added to expose REST APIs for managing and observing the job service. Users can now list worker pools and workers, view job queue status, and pause or resume specific job queues. Additionally, the API allows stopping currently running jobs or all pending jobs of a specific type, and retrieving logs for a job by its ID. This provides direct operational control and visibility into the background job execution engine.

src/controller/jobmonitor · high confidence

New RBAC permission model and provider implementation

The RBAC module now defines a comprehensive set of resources (such as robot accounts, quotas, scanners, and security hub) and actions (create, read, update, delete, list, operate, stop) to support granular access control. A new permission provider system is introduced, including a 'NolimitProvider' that grants broad system-level permissions for user and robot management, and a 'BaseProvider' for standard scope-based policies. This change establishes the foundational permission constants and provider interfaces used to enforce access rules across the platform.

src/common/rbac · high confidence

New Redis cache implementation using go-redis

This change introduces a new Redis cache implementation in the \src/lib/cache/redis\ package, replacing the previous \redigo\-based approach with the \go-redis/v9\ client. The new implementation provides a standard cache interface supporting key operations like save, fetch, delete, and contains, along with a scan capability for iterating over keys. It also adds support for Redis Sentinel configurations and TLS connections, allowing users to configure Redis caching with modern connection options and improved reliability.

src/lib/cache/redis · high confidence

New Redis client and pool management library

This change introduces a new Redis client library in src/lib/redis, providing singleton accessors for registry and harbor Redis connections via environment variables (\_REDIS\_URL\_REG, \_REDIS\_URL\_HARBOR) and a flexible pool manager supporting standard Redis, TLS (rediss), and Sentinel topologies. The implementation includes password sanitization in error logs to prevent credential leakage and adds comprehensive tests for client initialization, retry logic, and secure error handling.

src/lib/redis · high confidence

New Redis-backed session provider with configurable timeouts and renewal control

A new 'harbor' session provider has been added to store session data in Redis, replacing previous storage mechanisms. This change introduces a custom codec for serializing session objects and allows administrators to configure the session timeout via system configuration. Additionally, the provider now supports preventing background polling requests from inadvertently renewing the session TTL, ensuring sessions expire as expected even during active background activity.

src/core/session · high confidence

New UAA client with password authentication and configurable CA certificates

The UAA utility module now includes a new client implementation that supports password-based authentication via the OAuth2 password credentials grant, allowing users to authenticate with a username and password. The client also enables retrieving user information (including email) and searching for users by name via the UAA API. Additionally, TLS verification can be configured to use a custom CA certificate file, providing flexibility for environments with private UAA instances.

src/common/utils/uaa · high confidence

New asynchronous task pool for managing background jobs

The gtask library now includes a new pool implementation that allows users to register and manage asynchronous tasks. This pool supports both one-time jobs and recurring tasks with configurable intervals, providing a centralized way to handle background execution with proper lifecycle management via Start and Stop methods.

src/lib/gtask · high confidence

New base processors and image-specific handlers for OCI/Docker manifests

This change introduces a new \base\ package containing \IndexProcessor\ and \ManifestProcessor\ to handle OCI index, Docker manifest list, OCI manifest, and Docker v2 manifest artifacts. The \ManifestProcessor\ extracts metadata (such as architecture, OS, author, and creation time) into artifact extra attributes and supports unmarshalling config blobs. It also enables the \BUILD\_HISTORY\ addition type, allowing users to retrieve the image build history. Specific image processors (\indexProcessor\, \manifestV1Processor\, \manifestV2Processor\) are registered in the \image\ package to handle respective media types, with \manifestV2Processor\ delegating to the base processor for common logic while adding image-specific metadata extraction and build history support.

src/controller/artifact/processor/image · high confidence

New cache library with Redis support and concurrent build deduplication

A new cache library has been added to the codebase, providing a unified interface for memory and Redis-backed caching. The library supports multiple Redis connection modes, including standard, TLS (rediss), and Sentinel (redis+sentinel). It introduces a \FetchOrSave\ helper that uses \singleflight\ to deduplicate concurrent cache misses, ensuring that only one builder function executes for a given key while others wait for the result. The implementation uses \msgpack\ for serialization and includes utilities for context propagation and factory-based cache initialization.

src/lib/cache · high confidence

New centralized configuration library with declarative API and context-aware access

The \src/lib/config\ package introduces a unified, declarative configuration management system for Harbor. It replaces scattered environment-variable lookups with a \Manager\ interface that supports pluggable backends (defaulting to database storage, with in-memory support for testing) and provides a consistent API for loading, setting, and validating settings. Users benefit from centralized access to system and user-specific configurations (such as LDAP, OIDC, GDPR, and session timeouts) via context-aware helper functions, ensuring that configuration changes are applied consistently across components like the core API and jobservice. The library also includes dedicated utilities for tracing initialization and registry HTTP client timeout management.

src/lib/config · high confidence

New centralized tracing library with secure configuration and OpenTelemetry support

The \src/lib/trace\ package introduces a new, centralized tracing infrastructure for Harbor. It supports both Jaeger and OpenTelemetry (OTLP) exporters, allowing users to configure endpoints, compression, and timeouts via environment variables. A key behavioral change is the masking of Jaeger credentials in configuration logs to prevent password leakage. Additionally, HTTP request spans are now named using the HTTP method and full request URI (e.g., \GET http://host/path\) for better trace visibility, and a helper function is provided to extract trace IDs from request headers or context.

src/lib/trace · high confidence

New chunked copy mechanism for image replication

The image replication transfer module now supports copying blobs in chunks, controlled by the \REPLICATION\_CHUNK\_SIZE\ environment variable (defaulting to 10MB) and retry counts for blobs and chunks. This allows large image layers to be transferred in smaller segments, improving reliability and potentially performance for large artifacts during replication jobs.

src/controller/replication/transfer/image · high confidence

New common HTTP client with configurable TLS and transport options

A new HTTP client library has been introduced in src/common/http to standardize HTTP operations across the application. This includes a new Client wrapper that supports request modifiers, a unified transport layer (transport.go) that replaces the default Go http.Transport with a tuned configuration (e.g., MaxIdleConnsPerHost set to 200 to prevent port exhaustion), and robust TLS management (tls.go) supporting internal mTLS via environment variables and custom CA certificate injection (WithCustomCACert). The transport also integrates OpenTelemetry tracing via otelhttp. Error handling is standardized with a new Error type that wraps HTTP status codes and messages, providing both string and JSON representations.

src/common/http · high confidence

New common data models for authentication, roles, and system configuration

The \src/common/models\ package now includes a set of foundational data structures that define the core entities for the system. This introduces the \User\ model to handle user details and authentication state, alongside \OIDCUser\ for managing external identity provider metadata. Role-based access is supported by the new \Role\ model, while \AuthModel\ and \Token\ structures facilitate registry and service authentication flows. System configuration is now represented by \Database\ (supporting PostgreSQL and SQLite), \UAASettings\ for external authentication endpoints, and \Metric\ for monitoring configuration. Additionally, \job.go\ defines the standard lifecycle states for background jobs, and \base.go\ registers the models with the ORM.

src/common/models · high confidence

New common job client for interacting with the jobservice

A new HTTP client has been added to the common job package to standardize communication with the jobservice. This client provides methods to submit jobs, retrieve job logs, fetch execution statistics, and perform actions like stopping jobs. It includes specific handling for status mismatch errors (e.g., when stopping a job that is no longer running) and supports both default and replication-specific configurations. The change also introduces constants for job types (scan, GC) and statuses, along with parameter structures for scan jobs, establishing a unified interface for job operations across the system.

src/common/job · high confidence

New configuration model definitions for authentication, LDAP, and GDPR settings

This change introduces a new \model.go\ file in \src/lib/config/models\ that defines the data structures for various configuration settings. Specifically, it adds models for HTTP Auth Proxy (\HTTPAuthProxy\), OIDC authentication (\OIDCSetting\), LDAP configuration (\LdapConf\ and \GroupConf\), Quota settings (\QuotaSetting\), and GDPR compliance (\GDPRSetting\). It also defines a generic \ConfigEntry\ struct for storing key-value pairs in the database and a \Value\ struct using the \any\ type for flexible value storage. These models serve as the foundational schema for the application's configuration management system.

src/lib/config/models · high confidence

New contrib backup and restore scripts for Harbor

Added \harbor-backup\ and \harbor-restore\ shell scripts in the \contrib/backup-restore\ directory to help users back up and restore their Harbor instances. These scripts support backing up the PostgreSQL database, container registry data, Chart Museum data, Redis data, secret keys, and the \harbor.yml\ configuration. They offer improved error handling over previous versions, allow skipping tarball creation via the \--no-archive\ flag to facilitate rsync-based transfers to standby nodes, and support syslog logging.

contrib/backup-restore · high confidence

New controllers for OIDC authentication and auth proxy redirects

This change introduces new controller files in the core API layer to handle OIDC login flows and auth proxy redirects. The \OIDCController\ manages the OIDC login redirect, callback handling with PKCE support, and user onboarding, while the \AuthProxyController\ handles token verification and redirection for HTTP auth proxy scenarios. The \CommonController\ is updated to support OIDC-specific login and logout redirects, and the \UserExists\ endpoint now respects self-registration settings. Additionally, an \ErrorController\ is added to handle 404 errors, and corresponding tests are included to verify the new functionality.

src/core/controllers · high confidence

New event metadata resolvers for artifact, project, quota, replication, repository, retention, robot, scan, and tag events

This change introduces a new \metadata\ package under \src/controller/event/metadata\ that provides structured metadata types and \Resolve\ methods for converting internal state into standardized event payloads. Specifically, it adds support for resolving push, pull, and delete artifact events; project creation and deletion; quota warnings and exceedances; replication task status; repository deletion; tag retention task results; robot creation and deletion; image scanning status (completed, stopped, failed); and tag creation and deletion. Each metadata type maps its specific fields (such as artifact details, operator context, or task IDs) into the corresponding event data structures, ensuring consistent event formatting across these subsystems. Unit tests are included to verify the correct resolution of each event type.

src/controller/event/metadata · high confidence

New event model definitions for webhooks and audit logging

A new event model file has been introduced to define the data structures for system events. This includes the Replication struct, which now carries execution and task identifiers in webhook payloads, and the Retention struct to support tag retention webhook notifications. The Scan struct has been added to include scan type information in events. Additionally, the CommonEvent struct provides a mechanism to resolve general events into the audit log format, enabling user login and other operations to be recorded in the audit trail.

src/controller/event/model · high confidence

New internal API for quota synchronization

A new internal API endpoint (/api/internal/syncquota) has been added to allow administrators to manually trigger a synchronization of project quotas. This feature enables users to refresh quota data against the backend storage on demand, which is particularly useful after garbage collection or other operations that may have altered project sizes. The endpoint is protected by system administrator permissions and executes the synchronization asynchronously to avoid request timeouts.

src/core/api · high confidence

New job service client and HTTP response handlers in core utils

The core utils package now includes a thread-safe singleton client for the Job Service, ensuring consistent communication with the background job system. Additionally, new response handlers have been added to standardize HTTP interactions: a status handler for validating expected response codes and a job log handler that streams job service logs directly to the API response or surfaces errors if the job fails.

src/core/utils · high confidence

New job service utility package for common helpers

The jobservice now includes a new \utils\ package (\src/jobservice/common/utils\) providing reusable functions for job management, including generating unique identifiers, validating URLs and ports, checking file/directory existence, reading environment variables, and serializing/deserializing job objects. This package also includes a comprehensive test suite covering all utility functions to ensure reliability.

src/jobservice/common/utils · high confidence

New job statistics management API in Job Service

The Job Service now exposes a new management interface for querying and persisting job statistics. This change introduces a \Manager\ interface and its Redis-backed \basicManager\ implementation, providing methods to retrieve paginated lists of all jobs, scheduled jobs, and periodic job executions, as well as to fetch or save individual job stats. A corresponding mock implementation is generated to support unit testing of this new capability.

src/jobservice/mgt · high confidence

New prepare commands for TLS generation and config migration

The prepare script now includes dedicated CLI commands for managing internal TLS certificates and migrating configuration files across versions. Users can generate internal TLS certificates using the new \gencert\ command, which invokes the underlying \gencert.sh\ script. Additionally, a \migrate\ command allows upgrading Harbor configuration files from version 1.9.0 through 2.15.0 to a specified target version, handling the step-by-step migration process automatically.

make/photon/prepare/commands · high confidence

New purge audit log controller and job policy model

This change introduces the controller logic and data models for the new purge audit log job. The \controller.go\ file registers a scheduler callback (\PURGE\_AUDIT\_LOG\_CALLBACK\) to trigger the purge job, defines the \Controller\ interface with \Start\ and \Stop\ methods, and implements the logic to create task executions and jobs using the \PurgeAuditVendorType\. The \model.go\ file defines the \JobPolicy\ struct, which includes settings for dry run, retention hours, and included event types, along with trigger configuration structures. Tests are added for both the controller's start functionality and the model's JSON string conversion utility.

src/controller/purge · high confidence

New quota webhook handler for project storage events

A new webhook handler has been added to process quota-related events, such as when a project's storage usage exceeds its limit. This handler listens for quota events, retrieves the associated notification policies, and sends a webhook payload containing details like the repository name, project metadata, and custom quota information to configured endpoints.

src/controller/event/handler/webhook/quota · high confidence

New scheduler controller and execution model in job service

The job service now includes a dedicated scheduler controller (src/controller/jobservice/schedule.go) that manages schedule creation, retrieval, listing, deletion, and pause/resume status via the queue status manager. An execution model for replication (src/controller/jobservice/model.go) is also introduced to track execution details such as status, trigger, and timing. These changes provide the underlying control logic for scheduling jobs, including the purge audit log functionality, and are supported by corresponding unit tests.

src/controller/jobservice · high confidence

New secret management library for Harbor services

A new \secret\ package has been added to \src/common/secret\ to centralize how internal service secrets are handled. It introduces a \Store\ for validating secrets against known usernames (e.g., \harbor-jobservice\, \harbor-core\) and utility functions (\FromRequest\, \AddToRequest\) to extract and inject secrets into HTTP requests using a custom \Authorization\ header prefix (\Harbor-Secret\) instead of cookies. This change provides a standardized, header-based mechanism for inter-service authentication within the Harbor core components.

src/common/secret · high confidence

New secret-based HTTP request authorizer

A new SecretAuthorizer modifier has been added to the HTTP client infrastructure, allowing internal services to authenticate requests by injecting a secret into the request headers rather than using cookies. This change introduces a dedicated auth package with tests to validate the behavior, alongside a refactored core Modifier interface that now operates directly on HTTP requests.

src/common/http/modifier · high confidence

New selector implementations for doublestar, labels, severity, and signatures

This change introduces four new selector implementations within the \src/lib/selector/selectors\ library, enabling more granular filtering of artifacts. The \doublestar\ selector adds support for pattern matching on tags, repositories, and namespaces using the doublestar glob library. The \label\ selector allows filtering artifacts by the presence or absence of specific labels. The \severity\ selector enables filtering based on vulnerability severity levels using comparison operators (greater than, less than, equal). Finally, the \signature\ selector filters artifacts based on their signing status (whether any or all tags are signed). These selectors are registered in the central index and provide a unified interface for artifact selection across the system.

src/lib/selector/selectors · high confidence

New standalone database migration tool

A new standalone Docker-based utility has been added to handle database schema migrations independently. This tool packages the migration binary and scripts, configuring an entrypoint that starts a local PostgreSQL instance (unless an external database is specified), executes the migrations, and then stops the instance, providing a self-contained method for applying database changes.

make/photon/standalone-db-migrator, src/cmd/standalone-db-migrator · high confidence

New structured error library with typed codes and stack traces

The \src/lib/errors\ package now provides a structured error type that includes a machine-readable error code, a human-readable message, and a stack trace. This allows callers to programmatically distinguish error types (such as NotFound, Conflict, Unauthorized, or RateLimit) using helper functions like \IsNotFoundErr\ and \IsRateLimitError\, rather than relying on string matching. For users, this means more precise error handling in applications and clearer, traceable error output in logs and JSON responses via the new \MarshalJSON\ implementation.

src/lib/errors · high confidence

New structured logging library in src/lib/log

The \src/lib/log\ package introduces a new structured logging implementation, providing context-aware loggers via \WithLogger\ and \GetLogger\, configurable log levels (Debug, Info, Warning, Error, Fatal), and a pluggable formatter interface with a default text formatter. This library replaces the previous logging mechanism, allowing developers to inject specific loggers into Go contexts and customize output formatting and levels.

src/lib/log · high confidence

New system artifact cleanup job

A new job implementation has been added to the jobservice to automatically clean up system data artifacts. This job invokes the system artifact manager to remove unused records and reclaim storage space, logging the number of deleted records and total space reclaimed upon completion. The implementation includes unit tests verifying the job's execution flow, error handling, and configuration constraints.

src/jobservice/job/impl/systemartifact · high confidence

New task and execution management controllers with scheduled sweep job

This change introduces dedicated controller interfaces and implementations for managing tasks and executions in the \src/controller/task\ package. Users can now interact with a structured \Controller\ for general task operations (stop, get, list, get log, count) and an \ExecutionController\ for execution-specific actions (stop, delete, get, list, count). Additionally, a \SweepController\ is added to handle the cleanup of old executions, which is now scheduled to run daily via a cron job (0 0 0 \* \* \*) registered through the scheduler package.

src/controller/task · high confidence

This update introduces several new utilities in the tools directory. A copyright header-check script and template are added to enforce and automatically fix Apache 2.0 license headers in source files. A new chart migration tool is provided to help users migrate legacy Helm charts from the ChartMuseum backend to the OCI registry backend, including a Dockerfile and Python-based migration script. Additionally, custom Swagger templates are added to generate Go server and client code with improved interface-based design and dependency injection support, alongside a Spectral Dockerfile for API linting and a script to fix Notary database migration issues.

tools · high confidence

New utility functions for notification event handling and image resource URL construction

This change introduces a new utility package at src/controller/event/handler/util containing helper functions for the notification system. The SendHookWithPolicies function enables the system to publish webhook events based on configured notification policies, respecting the global notification enablement setting. Additionally, new helper functions BuildImageResourceURL and GetNameFromImgRepoFullName are provided to construct image resource URLs (supporting both digest and tag references) and extract image names from repository full names, with corresponding unit tests added to verify URL construction logic.

src/controller/event/handler/util · high confidence

New utility library for request handling, context management, and HTTP helpers

The \src/lib\ package now provides a collection of core utilities to support the application's HTTP and data layers. This includes context helpers to safely store and retrieve request-scoped data (such as API version, artifact info, and session renewal flags), URL normalization and validation to prevent SSRF attacks, and HTTP request/response wrappers like \ResponseBuffer\ and \ResponseRecorder\ for testing and controlled output. Additionally, it introduces rate limiting for I/O streams and HTTP transports, pattern matching for OCI registry URLs, and safe type conversion functions.

src/lib · high confidence

New utility package for encryption, concurrency control, and URL handling

The \src/common/utils\ package now provides core utilities for the system. It introduces \encrypt.go\ to handle password hashing (supporting legacy SHA1 and new PBKDF2-HMAC-SHA256) and reversible AES encryption. It adds \passports.go\ to manage task concurrency via a \LimitedConcurrentRunner\ and \PassportsPool\. Additionally, \utils.go\ offers helpers for parsing endpoints (with case-insensitive host matching), generating random strings, and testing TCP connections.

src/common/utils · high confidence

New webhook handlers for artifact, replication, and tag retention events

The system now includes dedicated webhook handlers for artifact lifecycle events (push, pull, delete), replication job outcomes, and tag retention policy executions. These handlers construct and send structured notification payloads to configured webhook endpoints, enabling external systems to react to image replication status, retention cleanup results, and standard artifact changes.

src/controller/event/handler/webhook/artifact · high confidence

New webhook policy controller implementation

A new controller has been introduced in the webhook package to manage webhook notification policies. This component provides the core logic for creating, listing, updating, and deleting policies, as well as retrieving associated executions, tasks, and task logs. It specifically handles the lifecycle of both webhook and Slack job vendors, ensuring that related executions are cleaned up when a policy is deleted, and tracks the last trigger time for policies.

src/controller/webhook · high confidence

Registry configuration and environment templates introduced

New Jinja2 templates for the Harbor Registry component have been added to the build preparation phase. The config template defines the registry's storage backend (Redis with optional Sentinel support), enables upload purging by default, enforces TLS 1.2 minimum for internal communication, configures basic authentication via htpasswd, and exposes Prometheus metrics. An environment template is also provided to pass HTTP/HTTPS proxy settings to the registry container.

make/photon/prepare/templates/registry · high confidence

Registry controller introduces blob and manifest deletion APIs with secure authentication

The registry controller now exposes HTTP DELETE endpoints for removing blobs and manifests from the registry storage, enabling garbage collection and cleanup workflows. These new API routes are protected by a secret-based authentication handler that validates requests using constant-time comparison to prevent timing attacks, while the health check endpoint remains publicly accessible. The controller also supports HTTPS with optional mutual TLS (mTLS) client certificate verification and integrates OpenTelemetry tracing for observability across blob and manifest operations.

src/registryctl · high confidence

Replication transfer now supports bandwidth limiting and chunked copying

The replication transfer mechanism in the controller now exposes configuration options to control data transfer behavior. Users can limit the replication bandwidth via a new Speed option and enable chunk-based artifact blob copying via a new CopyByChunk option, moving away from the previous default of copying whole blobs without speed limits. This change introduces the underlying options structure and factory registry for these transfer modes.

src/controller/replication/transfer · high confidence

SBOM artifact processor added

A new SBOM (Software Bill of Materials) processor has been added to the artifact pipeline. This processor registers for the media type application/vnd.goharbor.harbor.sbom.v1, enabling the system to recognize, pull, and extract the content of SBOM artifacts stored in the registry. The implementation ensures that only artifacts with a single layer are processed as valid SBOMs, and includes unit tests to verify correct extraction and error handling for malformed or missing layers.

src/controller/artifact/processor/sbom · high confidence

Security Hub controller implementation for vulnerability and summary APIs

The new \src/controller/securityhub\ package introduces the controller layer for the Security Hub feature, providing endpoints to retrieve project security summaries, list vulnerabilities, and count vulnerability items. The \SecuritySummary\ method aggregates data from the scanner and security hub managers, including total and scanned artifact counts, and optionally includes dangerous CVEs and artifacts based on query options. The \ListVuls\ method retrieves vulnerabilities and can optionally attach artifact tags (limited to 10 per artifact) for better context. A specific behavioral fix ensures that if no default scanner is configured, the security summary returns an empty result instead of an error, improving robustness for projects without active scanning. Tests verify the correct aggregation of counts, tag attachment logic, and error handling.

src/controller/securityhub · high confidence

Support for WebAssembly artifacts

Added a new processor for WebAssembly (WASM) artifacts, enabling Harbor to recognize and handle WASM images. The processor registers the \WASM\ artifact type and supports two formats: OCI-fashion WASM artifacts and annotation-fashion WASM artifacts (identified by specific OCI annotations). It extracts metadata such as architecture, OS, and author, and provides a \BUILD\_HISTORY\ addition type that returns the image's build history as JSON.

src/controller/artifact/processor/wasm · high confidence

System info API now exposes OIDC provider name and current time

The system information endpoint has been updated to include the name of the configured OIDC identity provider in the response when OIDC authentication is active, allowing users to identify which external provider is in use. Additionally, when authenticated, the API now returns the current server time in the protected data section, which can be used by clients for synchronization or session management purposes.

src/controller/systeminfo · high confidence

Vulnerability scan data export execution controller

Added the execution controller for the vulnerability scan data export feature, enabling users to initiate, track, and manage the status of scan data export jobs. This component handles the creation of export executions, retrieves their status and associated tasks, and lists executions filtered by the requesting user, providing the backend logic required to support the export functionality.

src/controller/scandataexport · high confidence

Vulnerability scan data export job

Users can now export vulnerability scan data as a CSV file. This new job implementation generates the report, calculates a checksum, and persists the CSV as a system artifact. It handles edge cases such as empty results by updating the execution status message, and ensures the temporary CSV file is cleaned up after the job completes.

src/jobservice/job/impl/scandataexport · high confidence

Webhook notifications now include scan and SBOM report summaries

The scan webhook handler now enriches notification payloads with detailed scan results. For vulnerability scans, the webhook includes a scan overview (summary of findings), and for SBOM scans, it includes an SBOM overview. The handler also implements a brief wait-and-retry mechanism to ensure scan reports are ready before sending the notification, improving the reliability of the data received by downstream systems.

src/controller/event/handler/webhook/scan · high confidence

Removals

Removal of default Nginx reverse proxy configuration

The default Nginx configuration file located at Deploy/config/nginx/nginx.conf has been removed. This file previously provided a reverse proxy setup to route traffic to the Harbor UI and registry services, including specific settings for handling large image uploads and proxy headers. Its removal means users relying on this specific default configuration for fronting Harbor behind a proxy will need to provide their own Nginx configuration or use an alternative proxy solution.

Deploy/config/nginx · high confidence

Removal of legacy DAO layer and database initialization logic

The data access layer files for access logs, base configuration, item details, projects, project roles, user registration, roles, and user management have been deleted. This removes the legacy Beego ORM-based database interactions, including the initialization routine that established MySQL connections via environment variables and the specific data access functions for managing users, projects, and access logs.

dao · high confidence

Removal of legacy Docker Compose and Python configuration scripts

The legacy \Deploy/docker-compose.yml\ file and the \Deploy/prepare\ Python script have been removed. This eliminates the old v1-style container orchestration definition and the manual Python-based configuration generation process, signaling a shift away from these specific deployment artifacts in favor of newer deployment methods.

Deploy · high confidence

Removal of legacy Docker logging container configuration

The Dockerfile and associated configuration files for the log container (rsyslog and logrotate) have been removed. This eliminates the previous setup that used rsyslog to receive syslog messages via TCP/UDP on port 514 and rotated logs in /var/log/docker/. Users relying on this specific container for centralized Docker logging will no longer have this service available.

Deploy/log · high confidence

Removal of legacy Go controller layer

The legacy Go-based HTTP controllers (including base, login, password, project, register, search, and item detail handlers) have been removed from the codebase. This eliminates the previous server-side rendering and session-based authentication flow, indicating a shift to a different architectural approach for handling user requests and UI rendering.

controllers · high confidence

Removal of legacy MySQL database initialization scripts

The Dockerfile, entrypoint script, and SQL schema definition for the legacy MySQL database deployment have been removed. This eliminates the automated setup of the 'registry' database, including its tables for users, projects, roles, and access logs, indicating a shift away from this specific database configuration or deployment method.

Deploy/db · high confidence

Removal of legacy UI configuration and environment templates

The legacy configuration file (app.conf) and environment variable template (env) for the UI component have been removed. This eliminates the previous mechanism for defining application settings, language types, mail server details, and database/registry connection parameters via these specific template files, indicating a shift in how the UI service is configured or integrated within the deployment architecture.

Deploy/templates · high confidence

Removal of legacy authentication and notification service handlers

The service layer has removed the \auth.go\ and \notification.go\ files, eliminating the legacy Beego-based authentication controller and the notification event handler. This change removes the direct handling of token generation via basic auth credentials and the processing of Docker registry push/pull notifications for access logging and cache refreshing within this specific service package, indicating a shift in how authentication and event-driven notifications are managed in the broader system.

service · high confidence

Removal of legacy authentication and security plugins

The repository has removed several legacy authentication and security components, eliminating their availability for use. Specifically, the \apiauth\ plugin (providing API key and signature-based authentication), the \auth\ plugin (providing HTTP Basic Authentication), and the \cors\ plugin (providing Cross-Origin Resource Sharing support) from the \github.com/astaxie/beego/plugins\ dependency have been deleted. Additionally, the Harbor-specific optional authentication subsystem has been removed, including the \opt\_auth\ framework and its implementations for database (\db\_auth\) and LDAP (\ldap\_auth\) authentication. Users relying on these specific authentication mechanisms or CORS filters will no longer have access to them in this version.

(repo-wide) · high confidence

Removal of legacy model definitions

The models package has been refactored by removing a set of legacy data structures, including AccessLog, AuthModel, Notification, Project, ProjectRole, Repo, RepoItem, Role, Tag, User, and UserProjectRole. This cleanup eliminates unused or outdated schema definitions from the codebase, likely as part of a broader database or API restructuring.

models · high confidence

Removal of legacy service utility packages

The \service/utils\ directory has been cleaned up by removing three files: \auth\_utils.go\, \cache.go\, and \registry\_utils.go\. This eliminates the local implementations for generating authentication tokens, managing the in-memory catalog cache, and handling registry API HTTP requests, indicating these capabilities have been moved to other parts of the system or replaced by external libraries.

service/utils, utils · high confidence

Removal of legacy static frontend assets

The static frontend assets for the Harbor UI, including localization files (locale\_en-US.ini, locale\_zh-CN.ini, locale\_messages.js), CSS stylesheets (base.css, sign-in.css), and JavaScript modules (common.js, login.js, register.js, item-detail.js, project.js, and others), have been deleted. This change removes the legacy client-side codebase that handled user authentication, project management, and repository browsing, indicating a migration away from this specific static UI implementation.

static · high confidence

Removal of vendored Logrus dependency

The vendored copy of the Logrus structured logging library (github.com/Sirupsen/logrus) has been removed from the Godeps workspace. This change eliminates the bundled source code, tests, and documentation for the library from this location, aligning with the project's shift to download dependencies via go get rather than maintaining them in the Godeps directory.

_Godeps/\workspace · high confidence

Architecture

Refactored artifact metadata abstraction into a pluggable registry

The artifact controller now uses a new \Abstractor\ interface and a manifest registry to handle metadata extraction. This change decouples the logic for parsing different manifest schemas (such as OCI, Docker Schema 1/2, and indexes) from the main controller, allowing for more modular and testable artifact processing. The controller now delegates metadata abstraction to specific handlers based on the manifest media type, improving maintainability and supporting diverse artifact types like SBOMs and CNABs.

src/controller/artifact · high confidence

Behavioural changes

Add configurable HTTP client timeout and retry limits for webhook and Slack notification jobs

The notification job implementation now supports configuring the HTTP client timeout and maximum retry count via environment variables. The \JOBSERVICE\_WEBHOOK\_JOB\_HTTP\_CLIENT\_TIMEOUT\ variable sets the HTTP client timeout (defaulting to 3 seconds), and \JOBSERVICE\_WEBHOOK\_JOB\_MAX\_RETRY\ sets the maximum number of retries for both WebhookJob and SlackJob (defaulting to 3). This allows users to tune the reliability and responsiveness of notification delivery to remote endpoints.

src/jobservice/job/impl/notification · high confidence

Add migration script for version 2.15.0 configuration

A new migration script for version 2.15.0 has been added to the Photon prepare process. This script reads the existing configuration and generates a new \harbor.yml\ file using a Jinja2 template, ensuring that boolean values for settings like \strong\_ssl\_ciphers\, \ipv6.enabled\, and \internal\_tls.enabled\ are normalized to lowercase. This change supports the upgrade path from version 2.14.0 to 2.15.0 by standardizing configuration formatting during the migration.

_make/photon/prepare/migrations/version\_2\_15\0 · high confidence

Audit log handler now supports pull events and configurable filtering

The audit log event handler has been updated to include support for artifact pull events, which are now recorded only when the pull audit log feature is enabled via configuration. The handler also processes a broader set of event types (including push, delete, create, and robot events) and checks specific configuration flags to determine whether an audit log entry should be created, ensuring that only relevant and enabled events are persisted.

src/controller/event/handler/auditlog · high confidence

CLI token authentication now supports delete and scanner-pull actions

The v2token security context has been updated to recognize 'delete' and 'scanner-pull' actions in addition to the existing 'pull' and 'push' permissions. When a CLI token contains a wildcard ('\*') action, it now explicitly grants pull, push, and delete capabilities. This change ensures that internal signed tokens used for CLI operations correctly map all specified actions to the corresponding RBAC permissions, allowing users to delete artifacts and perform scanner pulls via the CLI when authorized by the token.

src/common/security/v2token · high confidence

Centralized configuration and role constants for Harbor core

This change introduces a new \src/common/const.go\ file that centralizes string constants for configuration keys, authentication modes, and system settings. For users, this consolidates definitions for authentication providers (LDAP, OIDC, UAA, HTTP Auth Proxy), database connection parameters, and operational settings like GDPR compliance and metrics. It also formalizes the role hierarchy, including the new 'Limited Guest' role, and defines robot account naming prefixes, ensuring consistent configuration handling across the platform.

src/common · high confidence

Centralized event handler registration for system notifications and audit logging

The event handler subsystem now uses a centralized initialization file to explicitly register subscribers for various system events. This change consolidates the wiring for notification handlers (covering artifact push/pull/delete, quota warnings, scanning status, replication, and tag retention), P2P preheat triggers, and audit log recording for a wide range of actions including project and robot lifecycle events. It also registers a post-function for replication task status changes, ensuring that these core operational events are consistently routed to their respective handlers.

src/controller/event/handler · high confidence

Centralized event topic definitions and audit log mapping

The event controller now includes a dedicated topic definition file that standardizes all event types (such as project creation, artifact push/pull, and tag retention) and provides a consistent method to map these internal events to the external audit log format. This ensures that event consumers have a single source of truth for event structures and that audit logs accurately reflect the specific operation and resource involved.

src/controller/event · high confidence

Centralized middleware configuration with optimized database transaction handling

The core middleware stack is now defined in a single centralized location, establishing a strict execution order for URL cleaning, tracing, metrics, session management, CSRF protection, ORM, notifications, transactions, artifact info, security, logging, and read-only mode enforcement. A key behavioral improvement is the optimization of database transaction usage: the transaction middleware is now explicitly skipped for GET, HEAD, and OPTIONS requests, as well as for PATCH and PUT blob upload operations and the /service/token endpoint. This prevents long-running uploads or frequent read requests from holding database connections unnecessarily, while ensuring that the notification middleware executes before the transaction middleware to guarantee log completeness.

src/core/middlewares · high confidence

Config validation aligns with frontend and enforces audit log settings

The configuration controller now validates numeric fields (TokenExpiration, RobotTokenDuration, SessionTimeout) against maximum length limits to match frontend constraints, and enforces that the audit log forward endpoint is configured before allowing the skip-audit-log-database option to be enabled.

src/controller/config · high confidence

Configurable Docker log rotation and external syslog forwarding

The Photon image preparation now includes Jinja2 templates for log management, introducing support for both local and external logging destinations. Users can configure log rotation for Docker logs via the \log\_rotate\_count\ and \log\_rotate\_size\ variables, and enable external syslog forwarding by setting \log\_external\ to true, which directs logs to the specified \log\_ep\_host\, \log\_ep\_port\, and \log\_ep\_protocol\ instead of writing them to local files.

make/photon/prepare/templates/log · high confidence

Database access layer refactored to use Beego v2 ORM and pgx driver

The database access layer in src/common/dao has been rewritten to use the Beego v2 ORM (github.com/beego/beego/v2/client/orm) instead of the legacy version, and the PostgreSQL driver has been switched from lib/pq to jackc/pgx (via github.com/jackc/pgx/v5/stdlib). This change introduces a new Database interface and concrete implementations (pgsql.go, sqlite.go) that handle connection registration, schema upgrades via golang-migrate, and connection pool configuration (max idle/open connections, max lifetime). The migration logic now explicitly constructs the database URL using the pgx5 scheme and supports configurable SSL modes and timezones, ensuring consistent behavior for PostgreSQL connections.

src/common/dao · high confidence

Database schema migration scripts for PostgreSQL

This location contains the SQL migration files that define the database schema evolution for the Harbor registry. The changes cover the creation and modification of core tables such as artifact, repository, and user, as well as the introduction of new capabilities like the task/execution model for replication and retention, P2P preheat policies, and robot accounts. It also includes data migration logic to upgrade existing records to new formats, add necessary indexes for performance, and fix schema inconsistencies across versions.

make/migrations · high confidence

Enhanced Nginx proxy security and configuration flexibility

The Nginx proxy templates have been updated to enforce stronger security postures and support modern network configurations. HTTPS traffic now defaults to TLSv1.2 and TLSv1.3, with optional support for configurable strong SSL ciphers. Security headers including Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy are explicitly added, and cookies are marked with Secure and HttpOnly flags. The configuration also introduces support for dual-stack IPv4/IPv6 listening and allows for custom location configurations via include directives, providing greater flexibility for advanced proxy setups.

make/photon/prepare/templates/nginx · high confidence

Event-based replication now filters policies via query

The replication event handler now filters event-based replication policies directly in the database query rather than loading all policies and filtering them in memory. This change improves performance by reducing the number of policies fetched and processed for each replication event.

src/controller/event/handler/replication/event · high confidence

GC job implementation relocated to jobservice

The garbage collection job logic has been moved into the jobservice package (src/jobservice/job/impl/gc), introducing a new GarbageCollector struct that manages the mark-and-sweep lifecycle, including parameters for deleting untagged artifacts, specific tags, and time windows. This change consolidates the GC execution flow within the job service infrastructure, accompanied by unit tests for the new implementation and utility functions for cache key deletion and manifest removal.

src/jobservice/job/impl/gc · high confidence

Garbage collection controller refactored to use the new task and scheduler models

The garbage collection (GC) logic in the controller layer has been rewritten to align with the new task management and scheduling infrastructure. The new \callback.go\ registers handlers for GC job status changes and check-ins, ensuring that execution extra attributes (freed space, purged blobs/manifests) are updated and project quotas are refreshed upon completion. The \controller.go\ now manages GC executions and tasks via the central \task\ and \scheduler\ packages, supporting manual starts, stops, and scheduled runs. This change replaces the previous implementation with a standardized approach for tracking GC progress and managing its lifecycle.

src/controller/gc · high confidence

Graceful shutdown and admin password warning in core startup

The core service now handles system signals (SIGINT, SIGTERM, SIGQUIT) to perform a graceful shutdown with a 3-second timeout for goroutines, ensuring cleaner termination. Additionally, if the admin password is configured via HARBOR\_ADMIN\_PASSWORD but the admin user already has a password set in the database, the system now logs a warning that the config value is ignored, preventing silent configuration failures.

src/core · high confidence

Harbor 2.1.0 configuration migration and template updates

This change introduces the migration logic for upgrading to version 2.1.0. It adds a Jinja2 template for the Harbor configuration file that includes updated defaults and conditional handling for internal TLS settings. The migration script also implements a specific behavioral change for database configurations: if the existing 'max\_open\_conns' value is between 100 and 1000, it is automatically updated to 1000 to align with new requirements. Additionally, the migration environment is configured with autoescape enabled for security.

_make/photon/prepare/migrations/version\_2\_1\0 · high confidence

Harbor 2.10 configuration migration script

A new migration script for version 2.10.0 has been added to the Photon prepare process. This script reads the existing Harbor configuration and renders a new \harbor.yml\ template using Jinja2, ensuring that boolean configuration values (such as \strong\_ssl\_ciphers\, \internal\_tls.enabled\, and Trivy settings) are normalized to lowercase strings during the upgrade from version 2.9.0.

_make/photon/prepare/migrations/version\_2\_10\0 · high confidence

Harbor 2.12.0 configuration migration with normalized boolean values

The migration script for version 2.12.0 now generates the \harbor.yml\ configuration file using a new Jinja2 template. This update ensures that boolean configuration fields—specifically \strong\_ssl\_ciphers\, \ipv6.enabled\, \ipv4.enabled\, \internal\_tls.enabled\, and \storage\_service.redirect.disable\—are consistently written in lowercase (e.g., \true\/\false\) when migrating from previous versions, correcting potential casing issues in the generated output.

_make/photon/prepare/migrations/version\_2\_12\0 · high confidence

Harbor 2.14.0 configuration migration normalizes boolean values to lowercase

The migration script for version 2.14.0 now ensures that boolean configuration fields (such as \strong\_ssl\_ciphers\, \ipv6.enabled\, \ipv4.enabled\, and \internal\_tls.enabled\) are written in lowercase format in the generated \harbor.yml\. This change standardizes the configuration file format during upgrades from 2.13.0, preventing potential parsing issues caused by mixed-case boolean values.

_make/photon/prepare/migrations/version\_2\_13\_0, make/photon/prepare/migrations/version\_2\_14\0 · high confidence

Harbor 2.2.0 configuration migration with Jinja2 autoescaping

The migration script for upgrading to version 2.2.0 now uses a Jinja2 environment with autoescaping enabled for the \harbor.yml.jinja\ template. This change improves security by automatically escaping special characters in configuration values during the generation of the Harbor configuration file, preventing potential injection issues in the generated YAML.

_make/photon/prepare/migrations/version\_2\_2\0 · high confidence

Harbor 2.3.0 migration script with updated DB defaults and Jinja2 autoescape

The migration script for upgrading to Harbor 2.3.0 now automatically adjusts database connection pool settings (max\_idle\_conns to 100, max\_open\_conns to 900) if the previous configuration matched the old defaults, and enables Jinja2 autoescaping for the generated harbor.yml.jinja template to improve security against XSS in configuration values.

_make/photon/prepare/migrations/version\_2\_3\0 · high confidence

Harbor 2.5.0 configuration migration with Jinja2 autoescape

The migration script for upgrading to Harbor 2.5.0 now uses a Jinja2 template engine with autoescape enabled to generate the \harbor.yml\ configuration file. This change ensures that configuration values are safely escaped during the migration process, preventing potential injection issues in the generated YAML output.

_make/photon/prepare/migrations/version\_2\_5\_0, make/photon/prepare/migrations/version\_2\_6\0 · high confidence

Harbor Core container now runs as non-root user

The Harbor Core container has been reconfigured to run as a non-root user (UID 1000, group 'harbor') for improved security. This change involves a new base Dockerfile that installs the 'shadow' package to create the user and a main Dockerfile that sets the working directory and user context before execution. The entrypoint script now uses 'exec' to replace the shell process with the core binary, ensuring proper signal handling and resource cleanup.

make/photon/core · high confidence

Harbor configuration migration to version 2.8.0

The migration script for version 2.8.0 has been updated to use a new Jinja2 template for generating the \harbor.yml\ configuration file. This change introduces support for configuring the jobservice logger sweeper duration and the HTTP client timeout for webhook jobs. It also corrects the storage service redirect setting by handling both the legacy \disable\ key and the new \deactivate\ key to ensure compatibility during upgrades. Additionally, the migration now normalizes the \internal\_tls.enabled\ value to lowercase and fixes the handling of the \storage.redirect.disable\ template error, while also ensuring the \metric enable\ value is lowercased when migrating from older versions.

_make/photon/prepare/migrations/version\_2\_7\_0, make/photon/prepare/migrations/version\_2\_8\0 · medium confidence

Harbor configuration migration updated for version 1.10.0

The migration logic for upgrading Harbor configurations to version 1.10.0 has been updated to use a new Jinja2 template (\harbor.yml.jinja\) and Python migration script. This change introduces default values for several configuration sections (such as database connection limits, log rotation, and job service workers) that were previously optional or required explicit definition, ensuring a more robust default configuration during the upgrade process. The migration now explicitly handles the transition from version 1.9.0, applying specific template logic to generate the output configuration file.

_make/photon/prepare/migrations/version\_1\_10\0 · high confidence

Harbor installation and build environment is restructured with new shell scripts and updated configuration templates

The \make\ directory has been replaced with a new set of shell scripts (\checkenv.sh\, \common.sh\, \install.sh\, \prepare\, \pushimage.sh\) and a new \harbor.yml.tmpl\ configuration template. The environment check now explicitly validates for Docker (20.10.10+), Go (1.12+), and supports both Docker Compose v1 (1.18.0+) and the v2 plugin. The installation process (\install.sh\) now defaults to using \docker-compose\ (v1) but checks for the v2 plugin, and includes a \--with-trivy\ flag to enable Trivy scanning, while explicitly warning that Chartmuseum and Notary are deprecated and removed. The new \prepare\ script handles configuration input, manages secret key migration from legacy paths, and runs the preparation logic in a privileged container. The configuration template (\harbor.yml.tmpl\) introduces new settings for Trivy (including DB repositories and offline scan options), Job Service (logger sweeper duration, webhook timeouts), and database connection limits, while removing references to Clair, Chartmuseum, and Notary.

make · high confidence

Introduce Photon-based harbor-log image with improved log rotation and configuration

The harbor-log service is rebuilt on Photon OS 5.0, introducing a new base image and container configuration. Log rotation is now executed hourly via a custom script running as user 10000 to prevent permission errors, replacing the previous daily cron job. The rsyslog configuration has been updated to support a maximum message size of 32k and listens on UDP/TCP port 10514, while the container startup process ensures proper ownership of log directories and removes stale PID files to allow for reliable restarts.

make/photon/log · high confidence

Introduce Redis-backed blob size tracking with 24-hour expiration

The blob controller now tracks blob sizes in Redis with a 24-hour expiration time, replacing previous mechanisms for storing accepted stream upload sizes. This change introduces a new \Controller\ interface and implementation in \src/controller/blob\ that manages blob associations, existence checks, and size calculations, while delegating core blob management to the underlying manager. The controller also includes options to filter blob existence checks by artifact or project association.

src/controller/blob · high confidence

Introduce V2 job service core controller with enhanced job management

The job service core has been replaced with a new V2 implementation that introduces a \basicController\ to coordinate job operations. This change adds support for launching scheduled and periodic jobs alongside generic ones, provides detailed retrieval of periodic execution history, and enables filtering job queries to view only scheduled jobs. The new controller also includes improved validation for job requests and metadata, ensuring that only supported job kinds (generic, scheduled, periodic) are processed and that required fields like job name and metadata are present.

src/jobservice/core · high confidence

Introduce V2 periodic job scheduler with improved reliability

The periodic job scheduling logic in the job service has been replaced with a new V2 implementation. This update introduces a dedicated enqueuer that manages job execution timing and a basic scheduler that handles policy storage and lifecycle. Key improvements include fixing the Redis cross-slot issue by upgrading the underlying work package, ensuring jobs are enqueued using UTC time to prevent scheduling drift, and adding logic to prevent duplicate periodic job executions. The new scheduler also improves robustness by handling cases where job statistics are missing during unscheduling and by cleaning up dirty jobs on startup.

src/jobservice/period · high confidence

Introduce local security context with RBAC-based permission checks

The local security context implementation has been replaced with a new \SecurityContext\ that evaluates permissions using the RBAC project evaluator and admin evaluator. This change means that permission checks (such as pull and push actions) are now determined by the user's roles within specific projects and system admin status, rather than previous logic. The context now explicitly supports checking if a user is authenticated, retrieving their username, and verifying system admin or solution user status, providing a more granular and role-based access control mechanism for local security operations.

src/common/security/local · high confidence

Introduce robot account version 2 controller

The robot account controller has been replaced with a new implementation that supports both system-level and project-level robots. This change introduces a new model with explicit level handling, permission management via RBAC, and event notifications for creation and deletion. The controller now handles robot creation with secret generation, expiration logic, and permission assignment, while also supporting updates and deletions with proper cleanup of permissions and event firing.

src/controller/robot · high confidence

Introduce secret-based security context for internal service authentication

The \src/common/security/secret\ package now provides a \SecurityContext\ implementation that authenticates internal services (such as the job service and core service) using shared secrets. This context validates secrets against a store, resolves the associated username, and enforces strict permission checks: only the job service and core service are granted pull access, while push permissions are explicitly denied for these internal accounts. A corresponding test suite verifies authentication logic, username resolution, and the correct application of these pull/push restrictions.

src/common/security/secret · high confidence

Introduce standalone database schema migrator

A new standalone migration component has been added to handle database schema upgrades and data transformations. This change introduces a dedicated \Migrate\ function that initializes a migrator to check the current database schema version and subsequently triggers the schema upgrade process, separating migration logic from other application concerns.

src/migration · high confidence

Introduce structured query and sorting model in lib/q

The \src/lib/q\ package now provides a new \Query\ model that replaces the previous string-based sorting approach with a structured \Sorts\ slice, allowing for more robust and type-safe sorting definitions. This change introduces a \Build\ function to parse query strings into keywords, supports range, fuzzy, and list-based filtering, and includes comprehensive tests for the new parsing logic and query cloning capabilities.

src/lib/q · high confidence

Job Service V2: New architecture, configuration, and documentation

The job service has been replaced with a V2 implementation, introducing a new programming model for jobs (including support for unique, scheduled, and periodic jobs) and a new configuration structure defined in the new \config.yml\. The service now uses a Redis URL format for backend connections, supports configurable loggers with file and stdout backends, and includes a new \README.md\ detailing the architecture and usage. Additionally, new test certificates and a script for generating them have been added to support HTTPS configuration.

src/jobservice · high confidence

Job service API now requires authentication and supports HTTPS/mTLS

The Job Service API has been updated to enforce authentication on all incoming requests by validating a secret token in the Authorization header, with the exception of the /stats health check endpoint. Additionally, the API server now supports HTTPS and mutual TLS (mTLS) for secure communication, replacing the previous unauthenticated access model.

src/jobservice/api · high confidence

Job service configuration now supports Redis URLs and environment variable overrides

The job service configuration loader now accepts Redis connection details via a unified Redis URL format (e.g., \redis://user:pass@host:port/db\) instead of separate host and port fields, automatically prepending the \redis://\ schema if missing. Configuration can also be overridden by environment variables (such as \JOB\_SERVICE\_POOL\_REDIS\_URL\ and \JOBSERVICE\_SECRET\), which take precedence over values in the YAML file. Additionally, the system now sanitizes error messages to prevent leaking sensitive credentials like passwords when configuration validation fails.

src/jobservice/config · high confidence

Job service context initialization now includes retry logic and database setup

The job service implementation in \src/jobservice/job/impl\ has been updated to improve reliability during startup. The \Context\ now attempts to load configuration and initialize the database connection with a retry mechanism (up to 5 attempts with exponential backoff) to handle transient failures during job context initialization. Additionally, the context now explicitly initializes the database via \dao.InitDatabase\ and calls \initDBCompleted\ before the job execution context is built, ensuring the database layer is ready for job operations.

src/jobservice/job/impl · high confidence

Job service runtime bootstrap and Redis connection handling

The job service runtime now initializes with a new bootstrap process that configures Redis connections with specific timeouts (30s dial, 10s read/write) and wraps the namespace in curly braces to prevent Redis cross-slot issues. It also introduces a data migration step for RDB storage and sets up the core components including the worker pool, lifecycle controller, and hook agent for status changes.

src/jobservice/runtime · high confidence

Job service v2 core interfaces and execution models

The job service has been replaced with a v2 implementation in the \src/jobservice/job\ package, introducing new core interfaces and models for job execution. This includes the \Context\ interface for managing job execution resources and the \Interface\ for defining job behavior (run, retry, concurrency). New models define job requests, metadata (including \Kind\ for Generic, Scheduled, and Periodic jobs), and stats tracking. The update also introduces configurable execution retention counts via environment variables (e.g., \IMAGE\_SCAN\_EXECUTION\_RETENTION\_COUNT\) and a priority sampling system to influence job execution order.

src/jobservice/job · high confidence

Job status restoration and retry logic in the lifecycle controller

The job service lifecycle controller now includes a background loop that periodically retries failed job status updates, helping to recover jobs that may have become stuck or hung after a service restart. This change introduces a retry mechanism for status transitions and adds tests to verify the controller's ability to track jobs and handle status changes.

src/jobservice/lcm · high confidence

Jobservice configuration templates now support TLS, tracing, metrics, and configurable job loggers

The Jobservice deployment templates have been updated to expose several new configuration options. TLS support is now configurable, allowing the service to run on HTTPS with custom certificates and optional client certificate verification. Distributed tracing is enabled via environment variables, supporting both Jaeger and OpenTelemetry backends. Metrics collection can be enabled with a custom path and port. Job logging is now more flexible, allowing users to configure log levels and sweeper durations for file and database loggers. Additionally, the templates include settings for webhook job timeouts, cache layer Redis URLs, and job duration limits.

make/photon/prepare/templates/jobservice · high confidence

Jobservice container runs as non-root user with TLS health check

The Harbor Jobservice container is now configured to run as a non-root user (harbor) for improved security, utilizing a base image based on Photon OS 5.0. The entrypoint script executes certificate installation before launching the service, and a health check is added to verify availability over both HTTP (port 8080) and HTTPS (port 8443) using the service's SSL certificates.

make/photon/jobservice · high confidence

LDAP controller refactored to new programming model

The LDAP controller in src/controller/ldap has been rewritten to align with the new programming model, introducing a dedicated Controller interface and implementation that manages LDAP operations such as pinging configurations, searching users and groups, and importing users. This change includes a fix for issues encountered during LDAP connection testing and adds comprehensive unit tests to verify the new controller's behavior.

src/controller/ldap · high confidence

Major overhaul of the Docker Compose template for Harbor deployment

The \docker-compose.yml.jinja\ template has been significantly refactored to support modern security and configuration standards. Key changes include enforcing non-root execution for containers (e.g., proxy, registry, DB) via \cap\_drop\ and \cap\_add\ directives, integrating internal TLS configuration for components like the registry, core, and portal, and adding support for external databases and Redis to disable internal instances when needed. The template also introduces new features such as IPv6 support, custom CA certificate injection for UAA and Trivy, and metrics collection in the Harbor Core service, while removing deprecated elements like the \version\ field and ChartMuseum backend.

_make/photon/prepare/templates/docker\compose · high confidence

Migration script for Harbor 2.4.0 configuration generation

Adds a new migration entry for version 2.4.0 that generates the \harbor.yml\ configuration file using a Jinja2 template. This script introduces autoescaping for template security, normalizes boolean values (such as \internal\_tls.enabled\ and Trivy flags) to lowercase, and includes updated default settings for components like Trivy (with configurable timeouts) and database connection pools.

_make/photon/prepare/migrations/version\_2\_4\0 · high confidence

Migration script for Harbor 2.9.0 configuration template

Adds a new migration entry for version 2.9.0 that processes the \harbor.yml\ configuration file using a Jinja2 template. This migration handles the conversion of configuration values to lowercase for boolean fields (such as \internal\_tls.enabled\, \storage\_service.redirect.disable\, and Trivy settings) and ensures proper formatting of the output configuration file for the 2.9.0 release.

_make/photon/prepare/migrations/version\_2\_9\0 · high confidence

Migration script for version 2.11.0 normalizes boolean configuration values

The migration script for upgrading to version 2.11.0 now ensures that boolean configuration fields such as \strong\_ssl\_ciphers\, \ipv6.enabled\, \ipv4.enabled\, and \internal\_tls.enabled\ are written in lowercase (e.g., \true\/\false\) in the generated \harbor.yml\. This change prevents potential configuration errors caused by case-sensitivity issues when migrating from previous versions.

_make/photon/prepare/migrations/version\_2\_11\0 · high confidence

New ORM library with structured query, transaction, and error handling

The \src/lib/orm\ package has been replaced with a new implementation that provides a structured way to interact with the database. Users can now build queries using model annotations (e.g., \filter\, \sort\) and custom filter methods, with support for default sorting and pagination. The library introduces context-based ORM retrieval, a \WithTransaction\ decorator for automatic commit/rollback with savepoint support, and standardized error wrapping for common database issues like 'not found', 'conflict', and 'foreign key violation'.

src/lib/orm · high confidence

New Redis key management and Lua scripts for job service reliability

The job service now uses a dedicated \rds\ package to manage Redis keys and execute atomic Lua scripts, introducing specific keys for job statistics, periodic enqueue tracking, and status-change retry queues. This change adds Lua scripts to atomically set job statuses and handle hook acknowledgments, which helps prevent status synchronization issues and infinite webhook resends. It also includes utility functions for Redis hash operations and distributed locking, along with tests to verify these interactions.

src/jobservice/common/rds · high confidence

New configuration metadata system for type-safe settings

The configuration layer in \src/lib/config/metadata\ has been replaced with a new metadata-driven model that defines all Harbor settings (including OIDC, LDAP, database, tracing, and GDPR options) with explicit types, scopes, and validation rules. This change introduces a singleton metadata registry and strongly-typed value wrappers (e.g., \GetInt\, \GetBool\, \GetDuration\) that validate and transform configuration values at runtime, ensuring that settings like authentication modes, port numbers, and boolean flags are correctly parsed and enforced across the system.

src/lib/config/metadata · high confidence

New hook agent with retry concurrency and HTTP transport tuning

The jobservice hook subsystem now uses a dedicated agent that limits the concurrency of retry goroutines via a token bucket, preventing resource exhaustion when hook delivery fails. The underlying HTTP client is configured with MaxIdleConnsPerHost set to 20 to reduce connection churn and TIME\_WAIT accumulation, and it respects proxy environment variables (including no\_proxy) for outbound requests. These changes aim to stabilize hook event delivery and reduce duplicate or stalled notifications during high job activity.

src/jobservice/hook · high confidence

New internal event handlers for artifact lifecycle and project deletion

This change introduces new internal event handlers in the event controller layer. The \ArtifactEventHandler\ manages artifact pull, push, and delete events, introducing an asynchronous caching mechanism for pull counts and pull times (configurable via \ARTIFACT\_PULL\_ASYNC\_FLUSH\_DURATION\) and ensuring scan reports and executions are cleaned up when artifacts are deleted. The \ProjectEventHandler\ ensures that when a project is deleted, its associated immutable rules, retention rules, and members are automatically removed. Additionally, utility functions are added to trigger automatic scanning and SBOM generation on artifact push based on project metadata settings.

src/controller/event/handler/internal · high confidence

New middleware layer for registry API request handling

The server now uses a new middleware architecture for the registry API. An artifact info middleware extracts repository, digest, and tag details from the request URL and injects them into the context. Blob-specific middlewares handle lifecycle events: they associate blobs with projects on mount and successful upload, track accepted sizes during chunked uploads, and manage blob status (including garbage collection states) during HEAD requests. A job status hook handler processes task status changes from the jobservice, ensuring database records are created before the hook is processed to prevent status loss.

src/server · high confidence

New prepare service with TLS validation and upload purge configuration

The \make/photon/prepare\ directory now contains a new Python-based preparation service (Dockerfile, main.py, models.py) that replaces previous shell-based logic. This service introduces strict validation for internal TLS certificates, ensuring they contain Subject Alternative Names (SANs) and have correct file permissions. It also adds configuration support for the registry's upload purge feature, including validation logic for age and interval settings, and integrates tracing configuration models for Jaeger and OpenTelemetry exporters.

make/photon/prepare · high confidence

New replication job implementation with chunked copy and bandwidth limits

The replication job implementation in the jobservice has been replaced with a new version that supports configurable bandwidth throttling via a 'speed' parameter and enables chunk-based copying via a 'copy\_by\_chunk' flag. This new job also registers a comprehensive set of registry adapters (including Aliyun ACR, AWS ECR, Azure ACR, Docker Hub, DTR, GitHub Container Registry, GitLab, Google GCR, Huawei, JFrog, Quay, Tencent TCR, and VolcEngine CR) to facilitate image replication across these platforms.

src/jobservice/job/impl/replication · high confidence

OIDC group support and new authentication middleware architecture

The authentication system in src/core/auth has been refactored to use a new middleware-based programming model, introducing a pluggable AuthenticateHelper interface that allows different auth modes to register their own logic. As part of this change, OIDC authentication now explicitly supports user groups, enabling OIDC providers to onboard and search for groups via the new Auth implementation. Additionally, a user lock mechanism has been added to temporarily freeze accounts after login failures, improving security against brute-force attempts.

src/core/auth · high confidence

Parallel LDAP group attachment during login

LDAP authentication now attaches user groups in parallel by default, significantly reducing login latency for users belonging to many groups. The implementation splits the group verification workload across five concurrent workers using an error group, ensuring that group membership is resolved efficiently without blocking the authentication flow.

src/core/auth/ldap · high confidence

Photon base image updated to 5.0 with custom TLS certificate installation

The Photon base image is now based on version 5.0 (specifically digest 20260214) and includes updates from the photon-snapshot repository. Additionally, a new script is introduced to automatically append internal TLS CA certificates from /etc/harbor/ssl and custom certificates from /harbor\_cust\_cert to the system's CA bundle, ensuring that components like Clair, Registry, and ChartMuseum trust these internal CAs.

make/photon/common · high confidence

Portal container rebuilt with Node.js, Angular, and non-root execution

The Harbor portal is now built using a Node.js-based pipeline (replacing the previous Python script) and runs as a non-root user for improved security. The build process upgrades the frontend stack to Angular v21 and Clarity v18, and the resulting container image is based on Photon OS 5.0 with Nginx serving the static assets.

make/photon/portal · high confidence

Portal now supports internal TLS with IPv6 and TLSv1.3

The portal template now configures nginx to serve traffic over HTTPS when internal TLS is enabled, supporting both IPv4 (port 8443) and IPv6 addresses. It enforces TLSv1.2 and TLSv1.3 protocols and allows for stronger cipher suites via the \strong\_ssl\_ciphers\ configuration option, improving security posture. When TLS is disabled, it falls back to HTTP on port 8080.

make/photon/prepare/templates/portal · high confidence

Quota refresh now supports retry backoff and ignoring limitations

The quota controller's Refresh operation now includes a retry mechanism with exponential backoff to handle optimistic-lock conflicts more gracefully, preventing retry storms during high-concurrency updates. Additionally, a new option allows quota refreshes to ignore hard-limit checks, enabling background usage recalculations (such as the periodic project quota refresh) to proceed even if current usage temporarily exceeds configured limits.

src/controller/quota · high confidence

Refactor scanner controller with new base implementation and caching

The scanner controller logic in src/controller/scanner has been refactored to introduce a new base controller (base\_controller.go) that manages scanner registrations and includes a metadata cache with a 30-second expiration. This change updates the controller's behavior by caching scanner metadata to improve performance and modifies the registration listing and retrieval flows to handle capability retrieval errors more gracefully by logging warnings instead of failing the entire operation. The refactoring also introduces a new Options struct and functional options pattern (options.go) for configuring controller behavior, such as ping settings, and adds comprehensive unit tests (base\_controller\_test.go) for the new controller implementation.

src/controller/scanner · high confidence

Refactored configuration preparation with modular utility components

The \make/photon/prepare/utils\ directory has been restructured into a modular package of Python utilities to handle configuration generation and validation. This change introduces dedicated modules for specific components—such as \cert.py\ for certificate management, \configs.py\ for YAML parsing and validation, and individual files for core, db, jobservice, nginx, portal, registry, and trivy adapter—replacing the previous monolithic or less-organized structure. The refactoring standardizes how configuration files are rendered via Jinja2 templates, enforces file permissions and ownership (e.g., using \mark\_file\ and \prepare\_dir\), and centralizes logic for internal TLS, Redis URL parsing, and storage provider configuration, ensuring consistent and secure preparation of Harbor's runtime environment.

make/photon/prepare/utils · high confidence

Refactored core configuration and environment templates

The installation preparation templates for Harbor Core have been restructured to support new operational capabilities. The core environment configuration now includes settings for distributed tracing (Jaeger and OpenTelemetry), metrics collection, and a configurable cache layer with custom Redis URLs. Additionally, the list of supported registry types for proxy caching has been expanded to include GitHub GHCR, JFrog Artifactory, and Docker Registry, and the replication adapter whitelist has been updated accordingly. Internal TLS support is now explicitly configured in the environment variables, and the core application port is dynamically set based on TLS enablement.

make/photon/prepare/templates/core · high confidence

Refactored health check API with new checker implementation

The health check logic in src/controller/health has been refactored to use a new modular checker system. This introduces dedicated checkers for core components including the portal, jobservice, registry, registryctl, database, redis, and trivy (when enabled). The implementation uses periodic health checking with a 10-second interval and 60-second timeout, returning structured status reports that include individual component health states and error details.

src/controller/health · high confidence

Refactored project RBAC evaluation to a new modular permission system

The project-level role-based access control (RBAC) logic has been restructured into a new, modular permission evaluation framework. This change introduces dedicated components for namespace handling, user building, and policy evaluation within the \src/common/rbac/project\ package. Users will experience this as a backend architectural improvement that standardizes how project permissions (such as those for project admins, maintainers, and guests) are resolved, ensuring consistent access checks for resources like repositories, artifacts, and scan results without altering the available roles or permissions themselves.

src/common/rbac/project · high confidence

Refactored project controller with new options and CVE allowlist integration

The project controller has been restructured to support flexible data retrieval via an options pattern, allowing callers to explicitly request additional details such as CVE allowlists, metadata, and owner names when listing or getting projects. Additionally, the project creation flow now automatically initializes an empty CVE allowlist for each new project, ensuring security scanning configurations are present by default.

src/controller/project · high confidence

Refactored project member controller to new programming model

The project member controller in src/controller/member has been rewritten to align with the new programming model. This change introduces a cleaner interface for managing project members, including operations to get, create, delete, list, update roles, and count members. It also adds validation to ensure that at least one member (user or group) is provided when creating a new member, and handles cases where users or groups are not found by returning appropriate error messages. Additionally, the controller now supports adding LDAP groups and user groups to projects, and includes logic to onboard users and groups if they do not already exist. The refactoring also includes comprehensive unit tests to verify the correct behavior of these operations.

src/controller/member · high confidence

Refactored replication execution into dedicated copy and deletion flows

The replication execution logic in the controller has been restructured to separate copy and deletion operations into distinct flow implementations. The \Controller\ now routes replication tasks to either a \CopyFlow\ or a \DeletionFlow\ based on the resource state. The \CopyFlow\ handles fetching source resources, assembling destination resources (including namespace replacement logic), and creating copy tasks, while the \DeletionFlow\ handles creating tasks to delete resources on the destination registry. This change also introduces support for destination registry path component type validation during resource assembly and adds unit tests for the new flow structures.

src/controller/replication/flow · high confidence

Refactored scan controller to use a new task manager architecture

The scan controller logic has been restructured to delegate job execution and status tracking to the task manager. This change introduces a new \basicController\ that manages scan reports, artifacts, and scanners through dedicated managers, and registers callbacks for scan-all and individual scan task status changes. The refactoring ensures that robot accounts are properly cleaned up after scan jobs finish and that scan events are correctly fired with updated metadata, including scan types and operator information.

src/controller/scan · high confidence

Refactored token service to use golang-jwt v5 and RBAC-based access filtering

The token service in src/core/service/token has been rewritten to use the golang-jwt v5 library (imported as github.com/golang-jwt/jwt/v5) and to enforce access control via the RBAC system. The new implementation introduces a modular creator pattern (creator.go) that initializes specific token creators for services like the registry, and uses access filters (repositoryFilter, registryFilter) to determine allowed actions (pull, push, delete, scanner-pull) based on the user's permissions in the security context. The token generation logic (authutils.go) now constructs JWTs with RegisteredClaims and includes a 'kid' header for Docker distribution compatibility. This change ensures that token scopes are dynamically calculated against the project's RBAC policies rather than being statically assigned, and includes updated tests (token\_test.go) to verify the new parsing and creation logic.

src/core/service · high confidence

Refactored user group controller to new programming model

The user group controller has been rewritten to align with the new programming model, introducing a dedicated \Controller\ interface and a concrete implementation that delegates to the \usergroup.Manager\. This change standardizes error handling by using \errors.Is\ for sentinel checks (such as \ldap.ErrNotFound\ and \usergroup.ErrDupUserGroup\) and ensures that context from HTTP requests is properly propagated through middleware layers. The controller now explicitly manages operations like creating, updating, deleting, and searching user groups, with specific logic for LDAP group validation during creation.

src/controller/usergroup · high confidence

Registry container now runs as non-root user

The Harbor registry image has been updated to run as the non-root 'harbor' user (UID 10000) instead of root. This change improves security by deprivileging the container process, ensuring that the registry binary and configuration files are owned by this unprivileged user, and the entrypoint script executes the registry service under this identity.

make/photon/nginx, make/photon/registry · high confidence

Registry controller client initialization with read-only interceptor

The registry controller client is now initialized with a read-only interceptor, ensuring that delete operations are prevented during job execution. This change enhances the stability of registry operations by enforcing read-only access during critical processes, reducing the risk of unintended data loss or conflicts.

src/common/registryctl · high confidence

Registry controller now runs as non-root user

The registry controller container has been updated to run as the non-root 'harbor' user (UID 10000) instead of root. This change improves security by reducing the container's privileges, ensuring that the registry binary, configuration files, and certificates are owned by this user, and that the entrypoint script properly executes the process under this identity.

make/photon/registryctl · high confidence

Registry controller supports TLS, mTLS, and distributed tracing

The registry controller now supports secure internal communication via TLS and mutual TLS (mTLS), configurable through the new \config.yml.jinja\ and \env.jinja\ templates. Users can enable HTTPS on port 8443 with custom certificates, enforce client certificate verification, and configure distributed tracing (Jaeger or OpenTelemetry) via environment variables. Additionally, the log level is now explicitly configurable.

make/photon/prepare/templates/registryctl · high confidence

Removal of Beego-based API controllers

The API layer files (base.go, project.go, project\_member.go, repository.go, search.go, user.go, utils.go) have been deleted, removing the Beego-based HTTP handlers for projects, repositories, users, and search. This eliminates the existing REST endpoints and their associated session-based authentication and permission checks, indicating a migration away from the Beego framework for API routing.

api · high confidence

Removal of custom root certificate from registry configuration

The custom root certificate file (root.crt) has been removed from the Deploy/config/registry directory. This change eliminates the locally defined CA certificate that was previously used to validate the registry's TLS connection, likely reverting to system-trusted certificates or a different trust configuration.

Deploy/config/registry · high confidence

Removal of legacy Beego router configuration

The file routers/router.go, which previously defined all HTTP routes using the Beego framework, has been deleted. This removes the explicit registration of endpoints for user management (such as /login, /signUp, /reset), project operations, repository access, and API services (like /api/search, /api/projects, /api/users) that were previously handled by this central router file.

routers · high confidence

Removal of legacy HTML view templates

The legacy HTML view templates (including sign-in, registration, project management, and password reset pages) have been removed from the views directory. This change eliminates the old Bootstrap-based UI structure, indicating a transition to a different rendering approach or frontend architecture.

views · high confidence

Removal of local configuration and private key files

The application no longer ships with the local configuration file (conf/app.conf) or the RSA private key (conf/private\_key.pem). Users must now provide their own configuration settings and secure their own private keys externally, as the default development configuration (including the HTTP port 80 setting) and the bundled key are no longer present in the repository.

conf · high confidence

Remove legacy Beego pagination utility from quota driver

The file previously located at Godeps/\_workspace/src/github.com/astaxie/beego/utils/pagination/controller.go has been renamed to src/controller/quota/driver/driver.go and its package changed from pagination to driver. The file no longer exports the SetPaginator function that instantiated a Paginator and assigned it to the Beego context; instead, it now only imports the project quota driver package as a side-effect import. This removes the legacy pagination helper from this location.

src/controller/quota/driver · high confidence

Replace Redis with Valkey as the cache backend

The Photon-based cache image now uses Valkey instead of Redis. This change includes a new Dockerfile setup that builds Valkey from source for arm64 architectures (where no package is available) while using the standard Photon package for amd64, ensuring cross-platform support. A health check script and configuration file are provided to manage the new service, maintaining compatibility with existing Redis-compatible clients and configurations.

make/photon/valkey · high confidence

Replication controller refactored with single-active execution support

The replication controller in src/controller/replication has been restructured into dedicated files (execution.go, policy.go, model.go) to manage replication policies and executions. A key behavioral change is the introduction of Single Active Replication: when enabled on a policy, the system checks for existing running executions before starting a new one, skipping and marking the new request as an error if an active execution is already in progress. The controller now also handles scheduled triggers by registering a callback function to initiate replication, and includes robust error handling with panic recovery and retry logic for execution record insertion.

src/controller/replication · high confidence

Replication event handler now includes artifact labels in event payloads

The replication event handler in src/controller/event/handler/replication has been updated to include artifact labels in the events it generates. When handling push, delete, create tag, and delete tag events, the handler now passes the Labels field from the incoming event to the replication event resource metadata. This ensures that replication policies can utilize artifact labels for filtering and decision-making, addressing previous issues where label-based policies were not functioning correctly during replication events.

src/controller/event/handler/replication · high confidence

Replication policy model introduces single-active replication and chunked copy options

The replication policy model now supports Single Active Replication and Copy By Chunk configurations, allowing users to control concurrency and transfer methods for replication tasks. The Policy struct includes new fields for these capabilities, and the validation logic enforces stricter rules for scheduled triggers, specifically requiring the seconds field to be 0 and prohibiting wildcards in the minutes field of the cron expression.

src/controller/replication/model · high confidence

Repository name encoding now double-escapes slashes

The repository name encoding logic has been updated to apply double URL escaping to repository names. This change ensures that forward slashes in repository names (e.g., 'library/ns1/busybox') are encoded as '%252F' instead of the standard single-escaped '%2F', addressing issues with retention repository handling.

src/lib/encode · high confidence

Restrict proxy cache service permissions to specific project operations

The proxy cache service now uses a dedicated security context that limits its permissions to pull, push, and delete actions on repositories within its configured project. Previously, the service may have had broader or less specific access; now, it authenticates as 'harbor\#proxy-cache-service' and verifies that the requested operation matches the project name associated with its repository configuration, ensuring that it cannot access or modify resources outside its designated scope.

src/common/security/proxycachesecret · high confidence

Retention controller refactored to use new scheduler and operator context

The retention controller has been refactored to integrate with the new scheduler system and properly propagate the operator context. A new callback mechanism (callback.go) registers a handler that unmarshals trigger parameters and injects the operator into the context before triggering retention execution. The controller (controller.go) now uses the scheduler to manage scheduled retention jobs, ensuring that the 'harbor-jobservice' user is correctly set as the operator for scheduled tasks. This change ensures that audit logs and webhook payloads correctly reflect the operator responsible for retention executions, addressing previous issues where the operator was not properly propagated.

src/controller/retention · high confidence

Robot accounts now enforce project-level RBAC permissions

The robot security context has been refactored to evaluate access control using the project RBAC engine instead of a simple permission list. This change ensures that robot accounts are subject to the same project-level role-based access control policies as human users, allowing for more granular and consistent permission management for automated workflows.

src/common/security/robot · high confidence

Standardize event operator identity to security username

The event controller now derives the operator identity from the security context's username by default, ensuring that audit logs and webhook payloads accurately reflect the authenticated user. A new helper in the event operator package retrieves this identity, falling back to a legacy context value only if the security context is unavailable, which corrects previous inconsistencies in webhook payload data.

src/controller/event/operator · high confidence

Standardized Go linting and mock generation via new configuration files

The project now uses centralized configuration files to enforce code quality and streamline testing infrastructure. A new \.golangci.yaml\ file configures the linter (golangci-lint) with a specific set of enabled linters (including gosec, staticcheck, and revive) and defines exclusion rules for generated code and specific paths, while also integrating a copyright header template (\src/copyright.tmpl\) to ensure consistent licensing notices. Additionally, \.mockery.yaml\ replaces ad-hoc mock generation with a structured, config-driven approach for the mockery tool, defining output directories and naming conventions for mocks across controllers, jobservice, and common libraries.

src · high confidence

Standardized HTTP error response format and handling

The HTTP library now centralizes error handling in a new \SendError\ function that ensures all API responses follow a consistent JSON error array format (e.g., \{"errors":\[{"code":"...","message":"..."}\]}\). This change aligns internal error codes with standard HTTP status codes, safely masks internal server errors (5xx) from client responses to prevent information leakage, and normalizes error payloads from various sources including OpenAPI validation errors, legacy error types, and custom error codes.

src/lib/http · high confidence

Synchronized schedule policies and queue status from database to Job Service

A new sync worker in the Job Service now periodically synchronizes schedule policies from the database into the Job Service datastore, ensuring that scheduled jobs are correctly registered and managed. Additionally, the worker syncs the job queue status from the database to Redis, allowing the system to reflect paused or active states of job queues (such as garbage collection) in real-time. This change ensures consistency between the core database records and the Job Service's internal execution state.

src/jobservice/sync · high confidence

System-level RBAC policies and namespace evaluation

The system resource access model now uses a dedicated namespace and evaluator to manage permissions for administrative functions. This change introduces a new system namespace (prefix /system) and a policy set that grants read, create, update, delete, list, and stop actions on resources such as projects, users, user groups, registries, replication, distribution, garbage collection, scan-all, system volumes, LDAP users, configuration, job service monitoring, and security hub. The new evaluator uses these policies to determine access for system-level operations.

src/common/rbac/system · high confidence

Tag controller now updates repository modification time on tag changes

The tag controller in src/controller/tag has been refactored to automatically bump the parent repository's update\_time whenever a tag is created, updated, or deleted. This ensures that the repository's 'last modified' timestamp accurately reflects tag-level operations, which is critical for cache invalidation and synchronization mechanisms that rely on repository modification times.

src/controller/tag · high confidence

Trivy adapter now builds from source with a new multi-stage Dockerfile structure

The Trivy adapter image build process has been refactored to compile the adapter binary from source rather than relying on pre-built binaries. This change introduces a new set of build files (Dockerfile.base, Dockerfile.binary, builder.sh) that use a Go builder stage to compile the scanner-trivy binary, which is then copied into a Photon 5.0 base image. The final image includes an entrypoint script that handles certificate installation before executing the newly built binary, ensuring the adapter runs with the latest code changes integrated at build time.

make/photon/trivy-adapter · high confidence

Updated migration template for version 2.0.0 with autoescape and port support

The migration logic for upgrading to version 2.0.0 now uses a Jinja2 template that includes the HTTP port configuration and enables autoescaping for security. This ensures that the generated harbor.yml configuration file correctly reflects the network port settings and protects against template injection vulnerabilities during the upgrade process.

_make/photon/prepare/migrations/version\_2\_0\0 · high confidence

Upgrade to PostgreSQL 18 with in-container upgrade support

The Harbor database container now runs on PostgreSQL 18, upgrading from the previous version 15. To ensure a smooth transition for existing deployments, the container includes built-in logic to automatically detect the old data directory and perform an in-place upgrade using pg\_upgrade when starting up. This process handles necessary configuration adjustments, such as data checksum compatibility and collation version metadata refreshes, allowing users to upgrade their Harbor installation without requiring manual database migration steps.

make/photon/db · high confidence

User deletion now cleans up project memberships and OIDC metadata

When a user is deleted, the system now automatically removes their associated project member records to prevent orphaned data. Additionally, if the authentication mode is configured as OIDC, the corresponding OIDC user metadata is also deleted. This ensures that user removal is comprehensive across both project memberships and external identity provider records.

src/controller/user · high confidence

Fixes

Fix legacy scheduled job implementation for GC, scan all, and replication

The legacy job implementations for garbage collection, scan all, and replication have been corrected to ensure they function properly as periodic schedulers. This fix addresses issues with the legacy scheduled jobs by ensuring the scheduler wrappers are correctly defined and registered, allowing these background tasks to execute as intended.

src/jobservice/job/impl/legacy · medium confidence

Introduce new concurrency-safe job worker implementation

A new concurrency-safe worker implementation (cworker) has been added to the jobservice, featuring a Redis-backed deduplicator to prevent duplicate job execution, a reaper process to recover jobs from dead worker pools and sync outdated status, and support for unique job enforcement. This replaces the previous worker logic to fix issues with dangling states, status mismatches, and infinite webhook retries, while providing a cleaner interface for job registration, enqueueing, and stats reporting.

src/jobservice/worker · high confidence

Test coverage

Added UAA mock server and test fixtures; Added mock authentication server for testing; Added mock implementations for testing controllers; Added test server for job service unit tests; Added test utilities for Redis connection and namespace management; Added test utility package for configuration, database, and HTTP mocking; Added tests for migration path search logic; Added tests for the config controller; Added tests for user configuration loading and validation; Added unit tests for the user group controller; Initial Python API test framework and library.

Dependencies

Harbor Portal v2.10.0: Angular v21 and Clarity v18 upgrade with ESLint migration

The Harbor UI has been upgraded to Angular v21 and Clarity v18, requiring Node.js v22.22.3. This release migrates the build system from TSLint to ESLint (with @angular-eslint) and Prettier, introducing new configuration files (\.eslintrc.js\, \.prettierrc.json\, \.stylelintrc.json\) and a new \app-swagger-ui\ project for the API explorer. The portal version is now 2.10.0.

src/portal · high confidence

Updated build environment and dependency manifests

The build preparation scripts now use Python 3.13 with pinned versions of Click and Pytest, while the Go backend has been upgraded to version 1.26.4 with numerous library updates including Helm v3.18.5, Kubernetes client v0.36.3, and OpenTelemetry v1.44.0. The Harbor UI has been upgraded to Angular v21 and Clarity v18, and the Swagger UI component now uses Webpack v5.111 and Swagger UI v5.32.15.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 48 → 53 (+5.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 81 (+0.7)
  • Architecture 80 → 81 (+0.8)
  • Maturity 65 → 67 (+1.9)
  • Readiness 65 → 65 (-0.4)
  • Security 43 → 64 (+21.6)
  • Domain Modelling 59 → 64 (+4.9)
  • Accessibility 40 → 39 (-0.8)

Resolved (254)

  • Boundary-crossing change coupling: project.go ↔ project_metadata.go (src/pkg/project/models/project.go)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (src/portal/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/portal/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/portal/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/controller/event/metadata/tag.go)
  • Duplicated block (10 lines × 2) (src/core/auth/ldap/ldap.go)
  • Duplicated block (10 lines × 2) (src/pkg/reg/adapter/dtr/adapter.go)
  • Duplicated block (10 lines × 2) (src/pkg/reg/adapter/volcenginecr/helper.go)
  • Duplicated block (10 lines × 2) (src/server/middleware/blob/post_initiate_blob_upload.go)
  • Duplicated block (10 lines × 2) (src/server/middleware/repoproxy/proxy.go)
  • Duplicated block (10 lines × 2) (src/server/v2.0/handler/auditlog.go)
  • Duplicated block (10 lines × 2) (src/server/v2.0/handler/gc.go)
  • Duplicated block (10 lines × 2) (src/server/v2.0/handler/preheat.go)
  • Duplicated block (10 lines × 2) (src/server/v2.0/handler/robot.go)
  • Duplicated block (10 lines × 2) (src/server/v2.0/handler/robot.go)
  • Duplicated block (10 lines × 3) (src/common/http/client.go)
  • Duplicated block (10 lines × 3) (src/common/http/client.go)
  • Duplicated block (10 lines × 3) (src/server/v2.0/handler/preheat.go)
  • …and 234 more

New (520)

  • AccountSettingsModalComponent.handleValidation (cognitive 36) (src/portal/src/app/base/account-settings/account-settings-modal.component.ts)
  • AddP2pPolicyComponent.addOrSave (cognitive 26) (src/portal/src/app/base/project/p2p-provider/add-p2p-policy/add-p2p-policy.component.ts)
  • AddP2pPolicyComponent.addOrSave (cyclomatic 22) (src/portal/src/app/base/project/p2p-provider/add-p2p-policy/add-p2p-policy.component.ts)
  • AppLevelAlertsComponent.getDefaultScanner (cognitive 16) (src/portal/src/app/shared/components/app-level-alerts/app-level-alerts.component.ts)
  • ArtifactCommonPropertiesComponent.ngOnChanges (cognitive 28) (src/portal/src/app/base/project/repository/artifact/artifact-common-properties/artifact-common-properties.component.ts)
  • ArtifactListTabComponent.clrLoad (cognitive 19) (src/portal/src/app/base/project/repository/artifact/artifact-list-page/artifact-list/artifact-list-tab/artifact-list-tab.component.ts)
  • ArtifactListTabComponent.clrLoad (cyclomatic 17) (src/portal/src/app/base/project/repository/artifact/artifact-list-page/artifact-list/artifact-list-tab/artifact-list-tab.component.ts)
  • ArtifactListTabComponent.confirmDeletion (cognitive 16) (src/portal/src/app/base/project/repository/artifact/artifact-list-page/artifact-list/artifact-list-tab/artifact-list-tab.component.ts)
  • CI installs an unverified third-party binary (.github/workflows/CI.yml)
  • ClassTooLong: ArtifactListTabComponent (src/portal/src/app/base/project/repository/artifact/artifact-list-page/artifact-list/artifact-list-tab/artifact-list-tab.component.ts)
  • ClassTooLong: CreateEditRuleComponent (src/portal/src/app/base/left-side-nav/replication/replication/create-edit-rule/create-edit-rule.component.ts)
  • ClassTooLong: GarbageCollector (src/jobservice/job/impl/gc/garbage_collection.go)
  • ClassTooLong: PolicyComponent (src/portal/src/app/base/project/p2p-provider/policy/policy.component.ts)
  • ClassTooLong: basicController (src/controller/scan/base_controller.go)
  • ClassTooLong: controller (src/controller/artifact/controller.go)
  • ClassTooLong: projectAPI (src/server/v2.0/handler/project.go)
  • ConfigurationAuthComponent.pingTestServer (cognitive 25) (src/portal/src/app/base/left-side-nav/config/auth/config-auth.component.ts)
  • CreateEditEndpointComponent.getChanges (cognitive 34) (src/portal/src/app/base/left-side-nav/registries/create-edit-endpoint/create-edit-endpoint.component.ts)
  • CreateEditRuleComponent.getAllLabels (cognitive 24) (src/portal/src/app/base/left-side-nav/replication/replication/create-edit-rule/create-edit-rule.component.ts)
  • CreateEditRuleComponent.onSubmit (cognitive 16) (src/portal/src/app/base/left-side-nav/replication/replication/create-edit-rule/create-edit-rule.component.ts)
  • …and 500 more

Changes since last survey

  • 89 commits — 56 feature/other, 33 fixes

By area

  • .github/workflows — 20 commits
  • src/portal — 18 commits
  • src/server — 11 commits
  • src/pkg — 8 commits
  • src/go.mod — 5 commits
  • .github/dependabot.yml — 4 commits
  • src/controller — 4 commits
  • src/lib — 4 commits
  • make/migrations — 2 commits
  • src/common — 2 commits
  • src/core — 2 commits
  • tests/apitests — 2 commits
  • tests/resources — 2 commits
  • (root) — 1 commit
  • .github/auto-assignees.yml — 1 commit
  • src/jobservice — 1 commit
  • tests/ci — 1 commit
  • tests/robot-cases — 1 commit

Notable commits

  • fix: Fix CPU saturation from full table scans during artifact deletion by indexing sbom_digest (#23773)
  • fix: Fix. Return 404 when artefacts are requested for the non-existing repository. (#17618)
  • fix: chore(deps): bump Angular packages to fix known vulnerabilities (#23724)
  • fix: chore(deps): bump Go modules to fix known vulnerabilities (#23720)
  • fix: chore(deps): revert github.com/gorilla/csrf to v1.7.2 (#23759)
  • fix: chore(deps): upgrade Go dependencies to fix CVEs (#23801)
  • fix: fix(cache): avoid double prefix when removing expired entries (#23913)
  • fix: fix(ci): add explicit permissions block to workflows (#23676)
  • fix: fix(ci): remove contents read permission from label check workflow (#23702)
  • fix: fix(gc): do not count blobs missing from storage as freed space (#23972)
  • fix: fix(i18n): improve Korean translation of FULL_NAME (#22701)
  • fix: fix(migration): make sbom_report index creation idempotent (#23895)
  • fix: fix(portal): Keep the swagger-ui loading page intact when webpack minifies HTML (#23859)
  • fix: fix(quota): enable retry backoff on quota usage updates (#23789)
  • fix: fix(registry): Refactor registry update handling to improve URL validation (#23671)
  • fix: fix(repoproxy): prevent proxy-cache poisoning via robot-name prefix (#23675)
  • fix: fix(repoproxy): query robot account to validate proxy session and fix ut (#23776)
  • fix: fix(retention): drop retention_id metadata on project delete (#23942)
  • fix: fix(systeminfo): make HTTPS URL scheme check case-insensitive for CA download (#23888)
  • fix: fix: Add \n to the escape pattern (#23697)
  • …and 69 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

goharbor/harbor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e5e0e72c7455778dbeda45f4cd0db65a9a371705 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.