Repository navigation
What's Changed
- [redhat-3.17] NO-ISSUE: fix(ci): pin s390x buildkit to v0.30.0 to avoid runc masking regression by @nindsimonv in #6783
- [redhat-3.17] PROJQUAY-12812: feat(secscan): add retry limiting via metadata_json by @kleesc in #6659
- [redhat-3.17] QUAYIO-2123: fix(#6768): use defensive .get() by @openshift-cherrypick-robot in #6801
- [redhat-3.17] PROJQUAY-12635: fix: Set secscan endpoint to explicitly communicate via HTTP/1.1 by @ibazulic in #6807
- [redhat-3.17] PROJQUAY-12554: fix(api): hide robot account tokens from global readonly superusers by @openshift-cherrypick-robot in #6761
- [redhat-3.17] PROJQUAY-11685: feat(ldap): add queue-based admin connection pool by @jbpratt in #6119
- [redhat-3.17] PROJQUAY-12588: fix(cve): CVE-2026-56852 - x/text bump by @rhdmalone in #6823
- [redhat-3.17] PROJQUAY-12476: fix(cve): CVE-2026-44705 - tmp by @alexissolanas in #6845
- [redhat-3.17] PROJQUAY-12516: deps: Bump soupsieve to 2.8.4 by @nindsimonv in #6878
- [redhat-3.17] QUAYIO-2123: fix: platform KeyError by @openshift-cherrypick-robot in #6803
- [redhat-3.17] NO-ISSUE: ci: consolidate workflows into sentinel gate by @jbpratt in #6295
- [redhat-3.17] PROJQUAY-12738: fix(cve): CVE-2026-67320 - bump axios to 1.19.0 by @nindsimonv in #6921
- [redhat-3.17] PROJQUAY-12461: fix(cve): CVE-2026-69153 - postcss by @redhat-chai-bot in #6939
- [redhat-3.17] PROJQUAY-12792: fix: Clean up orphaned multipart uploads as part of blob cleanup by @openshift-cherrypick-robot in #6974
- [redhat-3.17] NO-ISSUE: fix(cve): CVE-2026-73089 - bump browserslist by @redhat-chai-bot in #6962
- [redhat-3.17] NO-ISSUE: fix(config): map FEATURE_ENABLE_STALE_MPU_CLEANUP as known-unmapped by @jbpratt in #6979
- [redhat-3.17] PROJQUAY-11682: fix(autoprune): re-land Cosign tag exclusion with race-safe cascade by @nasonawa in #6990
- PROJQUAY-12749: fix(deps): update fast-uri to >=3.1.4 for CVE-2026-16221 by @redhat-chai-bot in #7011
- [redhat-3.17] PROJQUAY-12199: fix(proxy): serve cached images when upstream registry is unavailable by @openshift-cherrypick-robot in #6456
- [redhat-3.17] PROJQUAY-12102: fix(web): redesign logo selection for dark mode support by @openshift-cherrypick-robot in #6265
- [redhat-3.17] PROJQUAY-11580: fix(ui): move usage logs chart legend outside chart SVG to prevent overlap by @openshift-cherrypick-robot in #6017
- [redhat-3.17] PROJQUAY-11441: fix(ui): permission dropdowns navigate away in Firefox by @openshift-cherrypick-robot in #5876
- [redhat-3.17] NO-ISSUE: build(hermetic): Add Containerfile.art and ART files for Konflux integration by @shruti-rh in #6781
- [redhat-3.17] PROJQUAY-11934: fix(ui): import patternfly-charts.css for dark mode chart support by @jbpratt in #7014
- v3.17.5 Changelog Bump by @github-actions[bot] in #6991
- [redhat-3.17] PROJQUAY-12884: chore(playwright): add registry clis and shared browsers to the e2e runner image by @nasonawa in #7029
- [redhat-3.17] PROJQUAY-13134: fix: Ensure that we use Redis connection pooling on user events and pull metrics by @openshift-cherrypick-robot in #7063
- PROJQUAY-12919: fix(cve): CVE-2026-84375 quay/quay-rhel9: js-yaml: Denial of Service vulnerability in YAML parsing [quay-3.17] by @redhat-chai-bot in #7072
- [redhat-3.17] PROJQUAY-12852: fix(cve): CVE-2026-54770 - bump WebOb by @openshift-cherrypick-robot in #7090
- [redhat-3.17] NO-ISSUE: fix(cve): CVE-2026-59879: Bump immutable to 5.1.9 by @alexissolanas in #7113
- [redhat-3.17] NO-ISSUE: fix(cve): CVE-2026-82417: Bump qs to 6.16.0 by @alexissolanas in #7178
- PROJQUAY-12964: fix(cve): CVE-2026-84292 - bump fast-uri by @redhat-chai-bot in #7126
- [redhat-3.17] PROJQUAY-13321: fix(build-logs): handle archived logs in superuser build logs page by @openshift-cherrypick-robot in #7241
- PROJQUAY-12880: fix(cve): bump lxml to 6.1.3 for CVE-2026-49825 by @rhdmalone in #7244
- [redhat-3.17] PROJQUAY-13273: fix(playwright): route superuser build GET through fresh-login retry by @jbpratt in #7247
- [redhat-3.17] NO-ISSUE: fix(playwright): give each readonly-superuser describe its own org name by @jbpratt in #7254
- [redhat-3.17] PROJQUAY-13330: fix(ui): Quay UI does not display shield icon for images signed with cosign by @openshift-cherrypick-robot in #7258
- [redhat-3.17] NO-ISSUE: fix(playwright): clear leaked theme preference in the auto-theme test by @openshift-cherrypick-robot in #7262
- [redhat-3.17] NO-ISSUE: chore(ci): make e2e test coverage check non-blocking by @openshift-cherrypick-robot in #7273
- [redhat-3.17] PROJQUAY-12223: fix(referrers): invalidate cache on manifest push with subject by @jbpratt in #7268
- [redhat-3.17] NO-ISSUE: ci(sentinel): skip web suites for workflow-only changes by @jbpratt in #7270
- [redhat-3.17] PROJQUAY-13334: test(v2): add quota enforcement integration tests for V2 registry push operations by @openshift-cherrypick-robot in #7280
- [redhat-3.17] PROJQUAY-13336: fix(quota): cancel rejected blob uploads by @openshift-cherrypick-robot in #7287
- [redhat-3.17] NO-ISSUE: fix(cve): bump compression to 1.8.2 by @redhat-chai-bot in #7222
- [redhat-3.17] PROJQUAY-13338: fix(oci): skip label validation for nested manifest indexes by @openshift-cherrypick-robot in #7292
- [redhat-3.17] NO-ISSUE: fix(playwright): credential the api fixture so the fresh-login retry is armed by @jbpratt in #7304
- [redhat-3.17] NO-ISSUE: fix(playwright): filter by name in superuser user-management assertions by @openshift-cherrypick-robot in #7311
- [redhat-3.17] NO-ISSUE: fix(ci): skip the web suite for CI-irrelevant workflow edit. by @openshift-cherrypick-robot in #7326
- [redhat-3.17] QUAYIO-2183: fix(logging): downgrade client-caused bearer token errors from ERROR to WARNING by @openshift-cherrypick-robot in #7330
- [redhat-3.17] NO-ISSUE: optimize: Read all repo permissions in bulk rather than one at a time by @openshift-cherrypick-robot in #7341
- [redhat-3.17] NO-ISSUE: feat(playwright): attach server spans to failed tests and trace API requests by @jbpratt in #7349
- [redhat-3.17] NO-ISSUE: test(playwright): retry all mail requests by @openshift-cherrypick-robot in #7360
- [redhat-3.17] NO-ISSUE: fix(playwright): pin CI image Chromium to lockfile version by @jbpratt in #7366
- [redhat-3.17] PROJQUAY-13368: fix(expiry): Set temp tag and blob expiry to 6 hours by default by @openshift-cherrypick-robot in #7376
- [redhat-3.17] PROJQUAY-13369: optimize: Do not run expensive quota lookups when not needed (#7347) by @ibazulic in #7378
- [redhat-3.17] NO-ISSUE: fix(playwright): raise expanded-view beforeAll timeout and log retry errors by @openshift-cherrypick-robot in #7386
- [redhat-3.17] PROJQUAY-11975: fix(ldap): handle single-line trace format in password redaction by @openshift-cherrypick-robot in #7401
- [redhat-3.17] PROJQUAY-13376: fix(ui): Add proper verification to tag modal by @openshift-cherrypick-robot in #7405
- [redhat-3.17] PROJQUAY-13378: fix(ui): treat unauthorized email as unverified, not an error by @openshift-cherrypick-robot in #7408
- [redhat-3.17] PROJQUAY-13377: fix(ui): Ensure we verify robot name/description during creation in the modal dialog by @openshift-cherrypick-robot in #7407
- [redhat-3.17] NO-ISSUE: fix(ci): skip the web suite for repo-metadata-only changes by @openshift-cherrypick-robot in #7411
- [redhat-3.17] NO-ISSUE: fix(config-tool): bump x/crypto to v0.52.0 and pgx/v5 to v5.9.2 for CVEs by @jbpratt in #7446
- [redhat-3.17] PROJQUAY-13396: fix(registry): bound BLOB_DELETE lock wait and stop re-acquiring in the fallback by @openshift-cherrypick-robot in #7441
Full Changelog: v3.17.4...v3.17.5