diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 2ea0878..0e11922 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -49,10 +49,10 @@ jobs: 10 latest smoke-version-jq: ".versionstring" - - version: 11.0.0-rc1 - tarball: https://github.com/owncloud/core/releases/download/v11.0.0-rc1/owncloud-complete-20260629.tar.bz2 + - version: 11.0.0-rc2 + tarball: https://github.com/owncloud/core/releases/download/v11.0.0-rc2/owncloud-complete-20260723.tar.bz2 base: v24.04 - trivy-ignore: v24.04/11.0.0-rc1/.trivyignore + trivy-ignore: v24.04/11.0.0-rc2/.trivyignore smoke-version-jq: "" update-docker-hub-description: diff --git a/CHANGELOG.md b/CHANGELOG.md index 9385661..7c642af 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +## 2026-07-23 + +* Changed + * Update 11.0.0-rc1 to 11.0.0-rc2 built from the GitHub release tarball + ## 2026-06-29 * Changed diff --git a/README.md b/README.md index 4b1be10..27462fa 100644 --- a/README.md +++ b/README.md @@ -34,7 +34,7 @@ ownCloud is an open-source file sync, share and content collaboration software t ## Docker Tags and respective Dockerfile links - [`10.16.3`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.3` -- [`11.0.0-rc1`](https://github.com/owncloud-docker/server/blob/master/v24.04/Dockerfile.multiarch) available as `owncloud/server:11.0.0-rc1` +- [`11.0.0-rc2`](https://github.com/owncloud-docker/server/blob/master/v24.04/Dockerfile.multiarch) available as `owncloud/server:11.0.0-rc2` ## Default volumes diff --git a/agents.md b/agents.md index e1eac66..bf0752e 100644 --- a/agents.md +++ b/agents.md @@ -20,7 +20,7 @@ GitHub Actions. - `v22.04/Dockerfile.multiarch` — image definition (`FROM owncloud/base:22.04`) - `v22.04/overlay/` — files copied into the image root (`ADD overlay /`); currently empty - `v22.04//.trivyignore` — accepted-CVE exclusions for the Trivy scan -- `v24.04/` — Ubuntu 24.04 based image (ownCloud 11.0.0-prealpha) +- `v24.04/` — Ubuntu 24.04 based image (ownCloud 11.0.0-rc2) - `v24.04/Dockerfile.multiarch`, `v24.04/overlay/`, `v24.04//.trivyignore` — as above - `docs/` — design/spec notes - `images/` — README screenshots @@ -39,7 +39,7 @@ There is no local application build (no Node/pnpm/Make toolchain). The image is built by `.github/workflows/main.yml`, which calls reusable workflows from [`owncloud-docker/ubuntu`](https://github.com/owncloud-docker/ubuntu): -- Matrix builds two releases: `10.16.3` (base `v22.04`) and `11.0.0-prealpha` +- Matrix builds two releases: `10.16.3` (base `v22.04`) and `11.0.0-rc2` (base `v24.04`), each via `/Dockerfile.multiarch`. - The ownCloud version is injected with the `TARBALL_URL` build arg — there is no version pinned inside the Dockerfile. diff --git a/v24.04/11.0.0-rc1/.trivyignore b/v24.04/11.0.0-rc1/.trivyignore deleted file mode 100644 index 91164a2..0000000 --- a/v24.04/11.0.0-rc1/.trivyignore +++ /dev/null @@ -1,2 +0,0 @@ -# vulnerability is affecting windows only -CVE-2024-51736 diff --git a/v24.04/11.0.0-rc2/.trivyignore b/v24.04/11.0.0-rc2/.trivyignore new file mode 100644 index 0000000..eeed8ba --- /dev/null +++ b/v24.04/11.0.0-rc2/.trivyignore @@ -0,0 +1,13 @@ +# vulnerability is affecting windows only +CVE-2024-51736 + +# client-side JS libs vendored by the bundled "notes" marketplace app; frontend +# only (not server-side core) and fixable only upstream in owncloud/core +# angular 1.4.14 - prototype pollution +CVE-2019-10768 +# prismjs 0.0.1 - ReDoS +CVE-2021-23341 +CVE-2021-32723 +# underscore 1.7.0 - template code execution / ReDoS +CVE-2021-23358 +CVE-2026-27601