Skip to content

Referrer discover API returns unbounded references #2890

@migmartri

Description

@migmartri

The referrer discover endpoints (DiscoverPrivate and DiscoverPublicShared) return all direct references for a given digest with no pagination. When a container image is attested multiple times, each attestation adds new references (SBOMs, SARIF reports, etc.), and the API returns all of them in a single response.

There is currently no way to limit the number of references returned or to page through them.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions