v1.6.1
Full Changelog: v1.6.1-rc.15...v1.6.1
[1.6.1] — 2026-10-02
Consolidates the 1.6.1-rc.1 … 1.6.1-rc.15 prereleases. Users upgrading from
1.6.0 get everything below; users already on 1.6.1-rc.15 receive no additional
runtime changes.
Changed
- The release cut verifies base image pins and published image architecture before signing. It checks that each Dockerfile base image pin names a multi-platform index, then checks the arm64 and amd64 images' own binaries before promoting them. This guards against the single-platform pin mistake that shipped a mislabelled arm64 image on the v1.7 line (#1021). The 1.6 line was never affected.
Fixed
- Update checks and registry lookups report their real result. A failed digest check now surfaces as an explicitly unknown status instead of "Up to date", and nested OCI image indexes resolve to the real platform manifest (#814, #808). Tag suggestion no longer ranks a bare integer build-number tag above a real dotted version (#859). Digest watching is re-derived every scan, so containers first seen before v1.5.0-rc.17 no longer stay Current when the registry has a newer digest (#1070). Containers first seen before their registry was configured recover from an
unknownregistry name (#945). - Notifications fire once per update. Cron scans are single-flight with one follow-up scan and a deadline, a
once=truetrigger no longer re-fires when a rate-limited digest lookup changes the history hash, and batch and digest modes take the same atomic reservation as the simple path (#972). A torn-down watcher no longer warns about a scan deadline it no longer owns. Monthly and longer watcher schedules no longer expire scans after 1 ms. - Update policy survives agent and controller handoffs. Agent container reconciliation prunes before ingesting and skips the prune on an ambiguous empty inventory, so snooze, maturity mode, minimum age, and skipped tags or digests are no longer lost on reconnect. The policy retention cache is durable across drydock's own self-update, and policy is stashed by Docker id when a container moves from the controller to an agent, including when
DD_LOCAL_WATCHER=false. One failing local watcher no longer deletes its containers' records while another watcher registers fine (#565, #922). A single malformed container no longer zeroes an agent inventory sync, and an edge agent's in-flight initialization can no longer replace its reconnected owner. - Updates and rollbacks deploy what was verified. Docker and Compose updates pin the pulled image by digest for signature verification, scanning, SBOM generation, and the replacement create, and Compose runs its preflight before any stop or remove. The pre-update hook, image prune, and rollback row now wait for the post-pull gate, and Docker Hub images pulled through
index.docker.iobind correctly. A rollback of a compose-managed container restores the backup image, and an automatic rollback after a failed healthcheck pulls the backup image before touching the running container. Compose updates pick up runtime defaults the new image ships (#734, #736). The self-update helper no longer destroys a health-verified replacement when removing the old controller fails. - Store and startup fixes. The session store writes
dd-sessions.jsoninstead of sharing/store/dd.jsonwith the main store, so a session autosave can no longer erase containers, settings, or audit rows. Startup no longer crashes when the store volume forbidschmod(#874), andDD_AGENT_ALLOW_INSECURE_SECRETis no longer parsed as an agent namedallow. - WebSocket and proxy fixes. Log-stream upgrades behind a TLS-terminating proxy no longer 403 when
X-Forwarded-Protois absent, andwsorwssin that header is accepted (#867, #887). - Debug dumps redact values, not names. Environment variable names stay visible and only sensitive values are redacted (#875). Apprise service URLs, Rocket.Chat user IDs, and Telegram chat IDs are redacted as well.
- Home Assistant agent entities receive state when MQTT agent topic segmentation is enabled. The state publisher now uses the same topic builder as discovery (#1139). The default
HASS_AGENTTOPICSEGMENT=falsebehavior is unchanged. - Bulk vulnerability scans finish. Accepted bulk scans continue after the HTTP request completes normally, so inventories larger than the four-scan concurrency limit no longer stop after the first batch.
- Build and CI fixes. The Docker image pins
tzdata=2026d-r0, the arm64 image arch check resolves each platform's own manifest, the demo site sendsCross-Origin-Opener-Policy, Crowdin sync targets the highest integration branch and opens its pull request, and the portwing fleet-soak artifact retention matches the 30-day ceiling. Demo favicons match the refreshed branding (#689).
Security
- Agent container ingestion checks ownership. Bulk and incremental ingestion paths and the prune ahead of them verify that the reporting agent owns the container id it names, so a connected agent can no longer take over or delete a container held by another agent or by the controller's own watchers. Ownership is decided by the container ids the controller's watchers have enumerated, never by watcher name (#922).
- Image and package patches. Alpine zlib 1.3.2 is patched for CVE-2026-85091, libexpat is updated to 2.8.5-r0 for CVE-2026-93990, and OpenSSL is updated to 3.5.9-r0 with the CVE-2026-14456 scanner exception dropped. The temporary zlib APK keeps its upstream version and carries a unique local revision, documented in the image scanner's VEX evidence.
- Runtime dependency updates. Joi 18.2.8 (CVE-2026-84367, CVE-2026-84368), Vitest 4.1.11 (CVE-2026-84373), Nodemailer 10.0.9, Axios 1.20.0, Undici 8.10.2, gRPC 1.14.5, Moment 2.31.0, fast-uri 4.1.5, ip-address 10.7.1, and brace-expansion 5.0.12, plus js-yaml 3.15.2 for the e2e workspace (CVE-2026-84375). Axios 1.20.0 honours CIDR entries in
NO_PROXY, so a registry address covered by one now connects directly instead of through the configured proxy. Nodemailer 10 requires Node.js 20 or newer, and Drydock already requires Node.js 24. - Website dependency updates. The documentation site moves to Next.js 16.3.6 with its Sharp and SWC helper updates, and baseline-browser-mapping moves to 2.11.20. Website dependencies are not included in the Docker image.
Documentation
- Deprecation docs realigned with the shipped code.
DEPRECATIONS.mdand the generated deprecations page now match the shipped behavior, including thePUT /api/v1/settingspath, theWUD_AGENT_SECRETfallback removal, and the WebSocket origin-check, anonymous-auth grandfather, and session cookie rename entries.
Note: the standard seven-day release-candidate soak was shortened for this release.
- Candidate age at promotion: 1867s (~0.0 days), short of the usual 7 days (604800s).
- Reason: Owner decision. rc.15 differs from rc.14, which soaked for sixteen days, only by dependency and base-image security patches (OpenSSL, zlib, libexpat and npm advisories) and the bulk-scan fix already on the line. A further seven days would only delay the security updates.
Note: this is a maintenance cut, built from dev/v1.6 at fb436e55c41cb70281979160d030eccfeb3f2048, not from main.
- The container image and release artifact are cosign-signed (identity
release-cut.yml@refs/heads/main, since the workflow run itself always executes at that ref), but carry no SLSA build-provenance attestation — this workflow's own OIDC token always claimsmainHEAD as the build source, which would be false for this artifact, so attestation is skipped rather than publish a false claim.