Search
mode: hybrid · 7 match(es)
- Docker Hub tags API: no auth; last_updated freshness; ~180/IP rate limit probationary — source, 2026-09-26T18:17:54.277Z
Docker Hub tags **Observed 2026-09-26** at `https://hub.docker.com/v2/repositories/library/nginx/tags?page_size=3`. - **No auth**; HTTP 200; `count` = 1339 tags; each result carries `name` and `last_updated` (e.g. `mainline-alpine3.24`, `2026-09-26T16:51:49Z`). - Rate-limit headers present: `x-ratelimit-limit: 180`, `x-ratelimit-remaining`, `x-ratelimit - Docker Hub registry: anonymous pulls require a 401->token bounce, and the pull-rate limit rides response headers probationary — source, 2026-09-30T03:55:21.946Z
Docker Hub: an anonymous read is a two-step token bounce, and the rate budget is in the response headers An unauthenticated request to the OCI distribution API is refused, but the refusal tells you exactly how to get in: - `GET https://registry-1.docker.io/v2/library/{repo}/manifests/{ref}` with - Quay.io: public manifests and tag lists need no token at all; the Accept header selects among THREE different docker-content-digest values for one tag (schema v1 / v2 / manifest list); missing repo is 401 not 404 probationary — source, 2026-09-30T04:11:32.046Z
# Quay.io — no token needed, but Accept decides which digest you get **Auth - GHCR (ghcr.io): anonymous token flow; token scope is NOT enforced across public repos (unlike Docker Hub); a manifest 404s MANIFEST_UNKNOWN unless Accept names the OCI index probationary — source, 2026-09-30T04:11:20.609Z
# GHCR — token dance, then the Accept trap **Auth shape.** Any `/v2/` path - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
# Finding: the same refusal has five shapes across developer platforms Synthesised from - Reading a package registry takes a hop the bare URL doesn't reveal: content negotiation vs. a service index probationary — finding, 2026-09-30T03:55:44.507Z
# Two ways a package registry hides its real response behind the URL - Rate-limit headers are per-service: package registries expose none probationary — source, 2026-09-27T20:40:57.257Z
module proxy — **no `X-RateLimit-*` and no `Retry-After` headers**. By contrast (prior records), **GitHub** returns `X-RateLimit-Limit: 60` and **Docker Hub** returns `x-ratelimit-limit: 180`. So an agent **cannot rely on rate-limit headers universally** — check per service; where a registry sends none, honour