Releases: quay/quay
Releases · quay/quay
Release list
v3.17.4
What's Changed
- PROJQUAY-11677: fix(cve): CVE-2026-48526 - PyJWT [redhat-3.17] by @aroyoredhat in #6106
- [redhat-3.17] NO-ISSUE: chore(test): backport Playwright tests from master by @jbpratt in #6117
- [redhat-3.17] PROJQUAY-11689: oci: Fix lazy manifest loader for OCI images to properly accept mixed indexes by @openshift-cherrypick-robot in #6122
- [redhat-3.17] PROJQUAY-11598: fix(cve): CVE-2026-44432 - urllib3 by @aroyoredhat in #6081
- [redhat-3.17] PROJQUAY-11583: feat(test): add geo-replication e2e testing with Garage S3 by @openshift-cherrypick-robot in #6051
- [redhat-3.17] NO-ISSUE: test(auth): add LDAP team sync Playwright E2E tests by @openshift-cherrypick-robot in #6138
- [redhat-3.17] NO-ISSUE: fix(playwright): use networkidle to fix flaky ui-toggle test by @openshift-cherrypick-robot in #6125
- [redhat-3.17] NO-ISSUE: fix(test): fix flaky geo-rep and LDAP sync Playwright tests by @jbpratt in #6139
- [redhat-3.17] NO-ISSUE: feat(buildman): enable container builds in CI with PopenExecutor by @jbpratt in #6140
- [redhat-3.17] PROJQUAY-11723: test(playwright/notifications): add build notification delivery tests by @openshift-cherrypick-robot in #6141
- [redhat-3.17] NO-ISSUE: chore(web): remove Cypress and all associated infrastructure by @jbpratt in #6142
- [redhat-3.17] PROJQUAY-11692: fix(superuser): fix BuildTrigger.to_dict() AttributeError and BuildLogs loading race by @openshift-cherrypick-robot in #6147
- [redhat-3.17] PROJQUAY-11688: gc: Optimize deletion queries by @openshift-cherrypick-robot in #6149
- [redhat-3.17] PROJQUAY-11764: chore(web): bump axios to 1.16.1 by @nindsimonv in #6173
- PROJQUAY-11735: fix(cve): CVE-2026-9277 - shell-quote by @aroyoredhat in #6168
- [redhat-3.17] PROJQUAY-11718: fix(cve): CVE-2026-10143 - kafka-python bump by @openshift-cherrypick-robot in #6193
- PROJQUAY-11665: fix(cve): CVE-2026-6322 - FastUri by @namansharma18899 in #6166
- [redhat-3.17] NO-ISSUE: fix(test): isolate autoprune user-namespace tests with freshUser fixture by @openshift-cherrypick-robot in #6201
- [redhat-3.17] NO-ISSUE: fix(test): make builds sort test resilient to identical timestamps by @openshift-cherrypick-robot in #6202
- [redhat-3.17] PROJQUAY-11947: test(e2e): add real export delivery tests for usage logs by @openshift-cherrypick-robot in #6227
- [redhat-3.17] PROJQUAY-11855: permissions: Optimize loading of permissions on UI login by @ibazulic in #6229
- [redhat-3.17] NO-ISSUE: chore(config-tool): update Go base image to 1.25.11-alpine3.24 by @openshift-cherrypick-robot in #6243
- [redhat-3.17] NO-ISSUE: fix(test): click sort button inside column header in builds test by @openshift-cherrypick-robot in #6242
- [redhat-3.17] PROJQUAY-11956: fix(web): disable quota fetch when feature is off by @openshift-cherrypick-robot in #6238
- [redhat-3.17] PROJQUAY-12000: fix(config-tool): s3 validator always uses https matching python backend by @openshift-cherrypick-robot in #6245
- [redhat-3.17] PROJQUAY-11712: deps: Bump golang.org/x/net to version 0.55.0 by @openshift-cherrypick-robot in #6239
- [redhat-3.17] PROJQUAY-11872: fix(cve): CVE-2026-12143 - form-data by @aroyoredhat in #6250
- [redhat-3.17] NO-ISSUE: test(mailpit): override api url by @openshift-cherrypick-robot in #6264
- PROJQUAY-11712: chore(deps): update go version to 1.25.0 by @alexissolanas in #6305
- [redhat-3.17] PROJQUAY-12080: fix(cve): CVE-2026-13676 - FastUri by @openshift-cherrypick-robot in #6337
- [redhat-3.17] PROJQUAY-11963: deps: bump sanitize-html to 2.17.5 by @redhat-chai-bot in #6354
- [redhat-3.17] NO-ISSUE: fix: prevent deadlock in test_has_garbage under parallel execution (PROJQUAY-11089) by @openshift-cherrypick-robot in #6232
- [redhat-3.17] NO-ISSUE: ci: move vpc sg rule cleanup to dedicated workflow job by @openshift-cherrypick-robot in #6206
- [redhat-3.17] NO-ISSUE: test(playwright): align container helper context by @jbpratt in #6411
- [redhat-3.17] NO-ISSUE: test(playwright): replace podman image helpers by @openshift-cherrypick-robot in #6412
- [redhat-3.17] PROJQUAY-11180: fix(proxy): prevent SSRF in proxy cache upstream registry configuration by @nindsimonv in #6413
- [redhat-3.17] NO-ISSUE: fix(web): regenerate package-lock.json with resolved URLs by @redhat-chai-bot in #6423
- [redhat-3.17] NO-ISSUE: fix(playwright): update BUSYBOX_IMAGE to valid digest by @openshift-cherrypick-robot in #6550
- [redhat-3.17] PROJQUAY-12317,PROJQUAY-12276: chore(deps): upgrade pyasn1 from 0.6.3 to 0.6.4 to address CVE-2026-59885,CVE-2026-59886 by @rhdmalone in #6567
- [redhat-3.17] PROJQUAY-12227: fix(ui): correct same repo name tag breadcrumb paths by @openshift-cherrypick-robot in #6518
- [redhat-3.17] PROJQUAY-12333: chore(deps): Bump pillow to 12.3.0 by @nindsimonv in #6618
- [redhat-3.17] PROJQUAY-12393: fix(ui): match domainRoute keywords as path segments by @openshift-cherrypick-robot in #6636
- [redhat-3.17] PROJQUAY-12416: fix(mirroring): use separate authfiles for same-registry mirror by @openshift-cherrypick-robot in #6670
- [redhat-3.17] PROJQUAY-12424: chore(deps): override js-yaml to address CVE-2026-59869 by @openshift-cherrypick-robot in #6674
- PROJQUAY-12402: chore(deps): override brace-expansion to address CVE-2026-13149 by @namansharma18899 in #6691
- v3.17.4 Changelog Bump by @github-actions[bot] in #6694
- PROJQUAY-12355: fix(mirroring): prevent SSRF in repository sources by @redhat-chai-bot in #6725
Full Changelog: v3.17.3...v3.17.4
v3.12.21
What's Changed
- [redhat-3.12] PROJQUAY-12118: fix(cve): CVE-2026-45822 - decode-uri-component by @openshift-cherrypick-robot in #6515
- [redhat-3.12] PROJQUAY-12271: chore(deps): upgrade pyasn1 from 0.6.3 to 0.6.4 to address CVE-2026-59885 by @openshift-cherrypick-robot in #6602
- [redhat-3.12] PROJQUAY-12328: chore(deps): Bump pillow to 12.3.0 by @nindsimonv in #6625
- PROJQUAY-12121: chore(deps): override brace-expansion to address CVE-2026-13149 by @namansharma18899 in #6655
- v3.12.21 Changelog Bump by @github-actions[bot] in #6682
- PROJQUAY-12219: chore(deps): chore(deps): override js-yaml to address CVE-2026-59869 by @namansharma18899 in #6678
- PROJQUAY-12358: fix(mirroring): prevent SSRF in repository sources by @redhat-chai-bot in #6719
Full Changelog: v3.12.20...v3.12.21
v3.10.25
What's Changed
- [redhat-3.10] PROJQUAY-12117: fix(cve): CVE-2026-45822 - decode-uri-component by @openshift-cherrypick-robot in #6516
- PROJQUAY-12270: chore(deps): upgrade pyasn1 from 0.6.3 to 0.6.4 for CVE-2026-59885 by @rhdmalone in #6609
- [redhat-3.10] PROJQUAY-12337: chore(deps): Bump pillow to 12.3.0 by @nindsimonv in #6626
- PROJQUAY-12120: chore(deps): override brace-expansion to address CVE-2026-13149 by @namansharma18899 in #6656
- PROJQUAY-12213: chore(deps): chore(deps): override js-yaml to address CVE-2026-59869 by @namansharma18899 in #6679
- v3.10.25 Changelog Bump by @github-actions[bot] in #6688
- PROJQUAY-12356: fix(mirroring): prevent SSRF in repository sources by @redhat-chai-bot in #6718
Full Changelog: v3.10.24...v3.10.25
v3.9.25
What's Changed
- [redhat-3.9] PROJQUAY-12277: chore(deps): upgrade pyasn1 from 0.6.3 to 0.6.4 for CVE-2026-59885 by @openshift-cherrypick-robot in #6611
- [redhat-3.9] PROJQUAY-12329: chore(deps): Bump pillow to 12.3.0 by @nindsimonv in #6627
- PROJQUAY-12126: chore(deps): override brace-expansion to address CVE-2026-13149 by @namansharma18899 in #6657
- PROJQUAY-12217: chore(deps): chore(deps): override js-yaml to address CVE-2026-59869 by @namansharma18899 in #6680
- v3.9.25 Changelog Bump by @github-actions[bot] in #6690
- PROJQUAY-12352: fix(mirroring): prevent SSRF in repository sources by @redhat-chai-bot in #6724
Full Changelog: v3.9.24...v3.9.25
v3.15.7
What's Changed
- [redhat-3.15] PROJQUAY-12115: fix(cve): CVE-2026-45822 - decode-uri-component by @alexissolanas in #6393
- [redhat-3.15] PROJQUAY-12274: chore(deps): upgrade pyasn1 from 0.6.3 to 0.6.4 to address CVE-2026-59885 by @openshift-cherrypick-robot in #6594
- [redhat-3.15] PROJQUAY-12330: chore(deps): Bump pillow to 12.3.0 by @nindsimonv in #6622
- [redhat-3.15] PROJQUAY-12395: feat(secscan): exhausted read by @openshift-cherrypick-robot in #6638
- [redhat-3.15] PROJQUAY-9998: feat(secscan): add retry limiting via metadata_json for v1 and v2 scanners (#6577) by @kleesc in #6644
- PROJQUAY-12124: chore(deps): override brace-expansion to address CVE-2026-13149 by @namansharma18899 in #6653
- NO-ISSUE: chore: v3.15.7 Changelog Bump by @github-actions[bot] in #6661
Full Changelog: v3.15.6...v3.15.7
v3.18.0
What's Changed
- chore(deps): bump axios from 1.12.0 to 1.13.5 in /web by @dependabot[bot] in #5035
- chore(deps-dev): bump webpack from 5.95.0 to 5.105.0 in /web by @dependabot[bot] in #5010
- chore(test): freeze clock in expiration test to avoid midnight wrap by @shaonrh in #5075
- chore(deps): update dependency deprecated to v1.3.1 by @red-hat-konflux[bot] in #3649
- chore(deps): update dependency flask to v2.3.3 by @red-hat-konflux[bot] in #3650
- chore(deps): update registry.access.redhat.com/ubi9/go-toolset docker digest to 82b82ec by @red-hat-konflux[bot] in #5081
- chore(deps): update registry.access.redhat.com/ubi9/nodejs-22-minimal docker digest to 449f3e1 by @red-hat-konflux[bot] in #5082
- chore: disable supervisord logfile writing by @jbpratt in #5080
- fix(security): prevent SSRF in org mirroring API (PROJQUAY-10572) by @shaonrh in #5074
- chore(renovate): add config for CVE-only PRs with auto-merge by @jbpratt in #5093
- chore(deps): update registry.access.redhat.com/ubi9/python-312-minimal:latest docker digest to c570170 by @red-hat-konflux[bot] in #5092
- chore(deps): update registry.access.redhat.com/ubi9/nodejs-22-minimal:latest docker digest to 449f3e1 by @red-hat-konflux[bot] in #5091
- feat: Enhance action logs with detailed request context for Splunk/ESS EOI compliance (PROJQUAY-9794) by @deshpandevlab in #4980
- chore(ci): add GitHub Actions workflow for Quay QE API tests by @LiZhang19817 in #4919
- [main] deps: upgrade of cryptography from 44.0.1 to 46.0.5 (PROJQUAY-10533) by @nindsimonv in #5096
- chore(deps): bump qs from 6.14.1 to 6.14.2 in /web by @dependabot[bot] in #5109
- chore: updating token like looking test var(PROJQUAY-9794) by @deshpandevlab in #5108
- fix: use resolvable hostname in org mirror E2E tests (PROJQUAY-10630) by @shaonrh in #5111
- fix(storage): fall back to pure-Python rsa for CloudFront signing (PROJQUAY-10609) by @jbpratt in #5090
- fix: log_action failed error message loses all context (PROJQUAY-10604) by @shaonrh in #5116
- feat(web): add manifest track visualization for tags (PROJQUAY-9592) by @shaonrh in #5115
- refactor(ipresolver): replace GeoLite2 with IPLocate (PROJQUAY-6103) by @cubismod in #5054
- NO-ISSUE: ci(lint): require PROJQUAY/NO-ISSUE prefix in PR titles by @jbpratt in #5128
- NO-ISSUE: ci(konflux): Red Hat Konflux update quay-master by @red-hat-konflux[bot] in #5125
- NO-ISSUE: chore(config-tool): remove old package.json by @jbpratt in #5131
- PROJQUAY-10551: chore(deps): upgrade pillow to 12.1.1 for CVE-2026-25990 by @rhdmalone in #5117
- PROJQUAY-1920: fix(config-tool): use dynamic redirect URL for OIDC validation by @jbpratt in #5058
- NO-ISSUE: chore(ci): allow branch prefix for cherrypicks by @jbpratt in #5137
- NO-ISSUE: chore(ci): don't trigger konflux on docs change by @jbpratt in #5140
- PROJQUAY-10419: deps: Update lodash to version 4.17.23 by @aroyoredhat in #5135
- PROJQUAY-10615: feat(config): add Go config parser and offline validator by @jbpratt in #5105
- NO-ISSUE: test(e2e): migrate superuser-org-actions from cy to pw by @jbpratt in #5156
- PROJQUAY-10573: fix(data): use RE2 engine for immutability policy regex to prevent ReDoS by @jbpratt in #5085
- PROJQUAY-10656: fix: preserve site-packages in PYTHONPATH for alembic migrations by @LiZhang19817 in #5158
- NO-ISSUE: test(e2e): migrate manage-team-members from Cypress to Playwright by @jbpratt in #5161
- PROJQUAY-10625: fix(nginx): catch all react rewrite by @jbpratt in #5163
- NO-ISSUE: test(e2e): migrate tags-expanded-view and tags-signatures from Cypress to Playwright by @jbpratt in #5170
- NO-ISSUE: deps: update build requirements.txt by @Marcusk19 in #5186
- NO-ISSUE: deps: downgrade setuptools by @Marcusk19 in #5191
- PROJQUAY-10574: fix(ui): use string-based tab IDs in Settings by @shaonrh in #5190
- PROJQUAY-10168: fix(security): harden Dockerfile with DROP ALL alignment by @Marcusk19 in #5088
- PROJQUAY-10504: fix(v2): block manifest deletion by digest when tags are immutable by @shaonrh in #5193
- NO-ISSUE: chore(local-dev): add reset DB command by @cubismod in #5199
- PROJQUAY-10665: fix(data): remove unbounded user cache in Splunk log mapper by @harishsurf in #5189
- PROJQUAY-10652: deps: upgrade of minimatch to 3.1.5 [master] by @nindsimonv in #5205
- PROJQUAY-10573: fix(data): Revert use RE2 engine for immutability policy regex to prevent ReDoS by @Marcusk19 in #5212
- PROJQUAY-10674: fix(web): add org_mirror events to Usage Logs chart by @shaonrh in #5219
- PROJQUAY-10691: fix(data): replace N+1 query with batch SELECT+INSERT in sync_discovered_repos by @shaonrh in #5228
- PROJQUAY-10586: fix(splunk): datetime serialization in audit logs by @harishsurf in #5211
- PROJQUAY-12412: feat(cmd): add
quay servecmd to minimal OCI Go-based container registry by @harishsurf in #5220 - NO-ISSUE: ci(build): add automation to keep requirements-build.txt in sync by @jbpratt in #5217
- PROJQUAY-10788: fix(conf): use PYTHONPATH env var in supervisord config by @SeanZhao-redhat in #5239
- PROJQUAY-10779: fix(web): add missing change_tag_immutability log description by @jbpratt in #5244
- PROJQUAY-10683: chore(deps): upgrade pypdf to 6.7.2 for CVE-2026-27628 by @rhdmalone in #5248
- NO-ISSUE: ci(web): add Playwright E2E test runner container image by @jbpratt in #5241
- PROJQUAY-10789: fix(web): use local time in formatDateForInput by @shaonrh in #5256
- NO-ISSUE: chore: Red Hat Konflux update playwright-e2e by @red-hat-konflux[bot] in #5259
- PROJQUAY-10675: fix(orgmirror): omit public param when authenticated by @shaonrh in #5269
- PROJQUAY-7025: fix(api): grant superusers full visibility on foreign orgs and repos by @jbpratt in #5275
- PROJQUAY-10739: fix(web): replace datetime-local with DatePicker+TimePicker by @shaonrh in #5270
- PROJQUAY-10588: feat(db): add OrganizationContactEmail table and migration by @sridipta in #5277
- PROJQUAY-10506: deps: upgrade of Authlib to 1.6.6 [master] by @nindsimonv in #5289
- PROJQUAY-6631: fix(web,api): allow global readonly superusers to see all repositories by @jbpratt in #5283
- PROJQUAY-10738: fix(web): persist org mirror setup mode across tab switches by @shaonrh in #5303
- NO-ISSUE: chore: Add quay team members to owners file by @harishsurf in #5310
- NO-ISSUE: konflux: ensure each PaC controller only triggers pipelines meant for its own namespace by @Sunandadadi in #5311
- NO-ISSUE: ci: update PR linting regex to include QUAYIO project by @cubismod in #5313
- PROJQUAY-10819: fix(orgmirror): use Link header for Harbor pagination by @shaonrh in #5308
- NO-ISSUE: konflux: Red Hat Konflux kflux-prd-rh02 update quay-py3 by @red-hat-konflux-kflux-prd-rh02[bot] in #5292
- PROJQUAY-10855: deps: upgrade of Authlib to 1.6.7 by @rhdmalone in #5324
- PROJQUAY-10845: secscan: Skip sending artifact images for scanning by @ibazulic in #5316
- PROJQUAY-10524: feat(web): add copy to clipboard buttons by @dmesser in #5026
- PROJQUAY-10845: fix: invalid detection of artifacts and OCI images by @ibazulic in #5331
- PROJQUAY-10668: fix(permissions): add batch team permission checking by @jbpratt in #4999
- PROJQUAY-10849: fix(mirror): remove credentials from mirror worker logs by @Marcusk19 in #5341
- PROJQUAY-10273: fix(web): add Docker Configuration tab to robot account credentials modal by @jbpratt in #5288
- PROJQUAY-9750: fix(ui): replace datetime-local inputs with PatternFly DatePicker + TimePicker by @shaonrh in #5323
- PROJQUAY-10865: ...
v3.15.6
What's Changed
- PROJQUAY-11675: fix(cve): CVE-2026-48526 - PyJWT [redhat-3.15] by @openshift-cherrypick-robot in #6130
- [redhat-3.15] PROJQUAY-11770: chore(web): bump axios to 1.16.1 by @nindsimonv in #6175
- [redhat-3.15] PROJQUAY-11734: fix(cve): CVE-2026-9277 - shell-quote by @openshift-cherrypick-robot in #6184
- [redhat-3.15] PROJQUAY-11596: fix(cve): CVE-2026-44432 - urllib3 by @nindsimonv in #6132
- [redhat-3.15] PROJQUAY-11719: fix(cve): CVE-2026-10143 - kafka-python bump by @openshift-cherrypick-robot in #6195
- [redhat-3.15] NO-ISSUE: ci: move vpc sg rule cleanup to dedicated workflow job by @openshift-cherrypick-robot in #6208
- [redhat-3.15] NO-ISSUE: chore(config-tool): update Go base image to 1… by @openshift-cherrypick-robot in #6251
- [redhat-3.15] PROJQUAY-11873: fix(cve): CVE-2026-12143 - form-data by @openshift-cherrypick-robot in #6281
- [redhat-3.15] PROJQUAY-11712: chore(deps): update go version to 1.25.0 by @openshift-cherrypick-robot in #6308
- PROJQUAY-11713: deps: Bump golang.org/x/net to version 0.55.0 by @alexissolanas in #6333
- [redhat-3.15] PROJQUAY-11959: deps: bump sanitize-html to 2.17.5 by @nindsimonv in #6366
- [redhat-3.15] PROJQUAY-9369: fix: Trigger Clair rescan after proxy cache completes blob downloads by @openshift-cherrypick-robot in #5435
- NO-ISSUE: chore: v3.15.6 Changelog Bump by @github-actions[bot] in #6384
- [redhat-3.15] PROJQUAY-10892: fix(proxy): prevent SSRF in proxy cache upstream registry configuration by @nindsimonv in #6416
Full Changelog: v3.15.5...v3.15.6
v3.9.24
What's Changed
- [redhat-3.9] NO-ISSUE: chore(config-tool): update Go base image to 1… by @openshift-cherrypick-robot in #6255
- [redhat-3.9] PROJQUAY-11712: chore(deps): update go version to 1.25.0 by @openshift-cherrypick-robot in #6312
- [redhat-3.9] PROJQUAY-11876: fix(cve): CVE-2026-12143 - form-data by @aroyoredhat in #6320
- [redhat-3.9] NO-ISSUE: ci: move vpc sg rule cleanup to dedicated workflow job by @openshift-cherrypick-robot in #6288
- PROJQUAY-11706: deps: Bump golang.org/x/net to version 0.55.0 by @alexissolanas in #6346
- PROJQUAY-12082: fix(cve): CVE-2026-13676 - FastUri by @namansharma18899 in #6361
- [redhat-3.9] PROJQUAY-11958: deps: bump sanitize-html to 2.17.5 by @nindsimonv in #6370
- v3.9.24 Changelog Bump by @github-actions[bot] in #6387
- [redhat-3.9] PROJQUAY-10894: fix(proxy): prevent SSRF in proxy cache upstream registry configuration by @nindsimonv in #6422
- [redhat-3.9] PROJQUAY-12114: fix(cve): CVE-2026-45822 - decode-uri-component by @alexissolanas in #6508
Full Changelog: v3.9.23...v3.9.24
v3.16.5
What's Changed
- [redhat-3.16] PROJQUAY-11492: chore(web): bump axios to 1.15.2 by @nindsimonv in #6022
- [redhat-3.16] NO-ISSUE: fix(ci): use larger runner for build-and-publish multi-arch job by @openshift-cherrypick-robot in #6059
- [redhat-3.16] PROJQUAY-11655: fix(templates): remove hardcoded external CDN references by @openshift-cherrypick-robot in #6092
- PROJQUAY-11676: fix(cve): CVE-2026-48526 - PyJWT [redhat-3.16] by @rhdmalone in #6116
- [redhat-3.16] PROJQUAY-11597: fix(cve): CVE-2026-44432 - urllib3 by @nindsimonv in #6131
- [redhat-3.16] PROJQUAY-11779: chore(web): bump axios to 1.16.1 by @nindsimonv in #6174
- PROJQUAY-11733: fix(cve): CVE-2026-9277 - shell-quote by @aroyoredhat in #6182
- [redhat-3.16] PROJQUAY-11717: fix(cve): CVE-2026-10143 - kafka-python bump by @openshift-cherrypick-robot in #6194
- PROJQUAY-11662: fix(cve): CVE-2026-6322 - FastUri by @namansharma18899 in #6180
- [redhat-3.16] NO-ISSUE: fix: prevent deadlock in test_has_garbage under parallel execution (PROJQUAY-11089) by @openshift-cherrypick-robot in #6222
- [redhat-3.16] NO-ISSUE: ci: move vpc sg rule cleanup to dedicated workflow job by @openshift-cherrypick-robot in #6207
- [redhat-3.16] NO-ISSUE: chore(config-tool): update Go base image to 1… by @alexissolanas in #6248
- PROJQUAY-11709: deps: Bump golang.org/x/net to version 0.55.0 by @alexissolanas in #6256
- [redhat-3.16] PROJQUAY-11874: fix(cve): CVE-2026-12143 - form-data by @aroyoredhat in #6276
- [redhat-3.16] PROJQUAY-11712: chore(deps): update go version to 1.25.0 by @openshift-cherrypick-robot in #6306
- PROJQUAY-12119: fix(cve): CVE-2026-45822 - decode-uri-component by @alexissolanas in #6364
- [redhat-3.16] PROJQUAY-11964: deps: bump sanitize-html to 2.17.5 by @nindsimonv in #6363
- [redhat-3.16] PROJQUAY-9369: fix: Trigger Clair rescan after proxy cache completes blob downloads by @openshift-cherrypick-robot in #5018
- PROJQUAY-12081: fix(cve): CVE-2026-13676 - FastUri by @namansharma18899 in #6359
- [redhat-3.16] PROJQUAY-10893: fix(proxy): prevent SSRF in proxy cache upstream registry configuration by @nindsimonv in #6414
- v3.16.5 Changelog Bump by @bcaton85 in #6451
Full Changelog: v3.16.4...v3.16.5
v3.10.24
What's Changed
- [redhat-3.10] PROJQUAY-11712: chore(deps): update go version to 1.25.0 by @openshift-cherrypick-robot in #6310
- [redhat-3.10] PROJQUAY-11871: fix(cve): CVE-2026-12143 - form-data by @aroyoredhat in #6319
- PROJQUAY-11708: deps: Bump golang.org/x/net to version 0.55.0 by @alexissolanas in #6343
- [redhat-3.10] PROJQUAY-11961: deps: bump sanitize-html to 2.17.5 by @nindsimonv in #6369
- [redhat-3.10] PROJQUAY-10888: fix(proxy): prevent SSRF in proxy cache upstream registry configuration by @nindsimonv in #6421
- v3.10.24 Changelog Bump by @github-actions[bot] in #6429
Full Changelog: v3.10.23...v3.10.24