Affected by GO-2025-3460
and 2 other vulnerabilities
GO-2025-3460: Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution
GO-2026-5094: Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distribution
GO-2026-5185: Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution
CheckBlobDescriptorCache takes a cache implementation through a common set
of operations. If adding new tests, please add them here so new
implementations get the benefit. This should be used for unit tests.