Skip to content

Releases: snapetech/QuestarrNG

QuestarrNG v1.9.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 17:01

User-facing changes

Added

  • Game Details: Game details now include an expansions tab with available DLC and expansion covers, release years, category labels, and links to their IGDB pages.
  • Library Platforms: Platform preferences now carry across library filters, discovery, game adding, download searches, and import eligibility. Hide shelved or already-owned results by default, and track games on a Playing page with notes, milestones, screenshots, and Steam achievements.
  • Discovery: Settings now support a global release-name blacklist that filters matching terms from manual searches, auto-search cycles, and AI-assisted release selection.

Security

  • Imports: Optional VirusTotal hash lookups and local ClamAV scans run before downloads are unpacked or moved into the library. Flagged files are quarantined and create a Security Alert instead of being imported.

Container image: ghcr.io/snapetech/questarrng:1.9.0

Pull with: docker pull ghcr.io/snapetech/questarrng:1.9.0.

QuestarrNG v1.8.3

Choose a tag to compare

@github-actions github-actions released this 04 Oct 02:24

User-facing changes

Added

  • Settings: System settings now include a Ko-fi link for users who want to support QuestarrNG fork maintenance.

Security

  • Dependencies: All application dependencies now pass the full npm security audit, including development tooling. The cache-policy fix from upstream PR Doezer#60 is covered locally while it awaits maintainer review, and license checks no longer pull in a separate npm resolver stack.

Container image: ghcr.io/snapetech/questarrng:1.8.3

Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.3.

QuestarrNG v1.8.1

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:21

User-facing changes

Security

  • Dependencies: Questarr now pins a tested upstream fix for CVE-2026-93748, preventing stale-cache directives from reusing shared responses that require validation while upstream reviews the fix.

Container image: ghcr.io/snapetech/questarrng:1.8.1

Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.1.

QuestarrNG v1.8.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 22:48

User-facing changes

Changed

  • Integrations: The SeerrNG provider API now has a versioned OpenAPI contract with a conformance test for its handshake and required route parameters.

Security

  • Imports: Archive imports now reject traversal paths and links, and enforce configurable total-entry and declared-expansion limits before archive data is decompressed or written into a game library.
    • Action required: Set ARCHIVE_MAX_EXPANDED_BYTES or ARCHIVE_MAX_ENTRIES if your archives need different limits.
  • Containers: Compose and Helm deployments can run QuestarrNG as a non-root user with a read-only root filesystem and no Linux capabilities. The image entrypoint preserves UMASK and checks the writable data volume without changing ownership; rootless file logs are stored there at /app/data/server.log. Published images now include SBOM and provenance attestations.
    • Action required: Prepare the data volume with the configured UID and GID before enabling rootless mode.
  • Integrations: Integration API keys can now be limited to SeerrNG routes and expire after a configurable 30–365 days; existing keys retain their current access, and Settings shows each key's scope and expiry.
    • Action required: Create a replacement key if a client should use the new scope or expiration settings.

Container image: ghcr.io/snapetech/questarrng:1.8.0

Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.0.

QuestarrNG v1.7.3

Choose a tag to compare

@github-actions github-actions released this 02 Oct 03:10

User-facing changes

Changed

  • Release Pipeline: Release-note fragments now appear in versioned releases, and Discord announcements use the shared channel webhook configured as the DISCORD_RELEASE_WEBHOOK Actions secret.

Security

  • Proxy: YunoHost proxy requests now use a fixed upstream host and forward WebSocket upgrades only, blocking attacker-controlled host and h2c upgrade headers.
  • Dependencies: Questarr now bundles a locally patched node-forge release that rejects malformed RSA PKCS#1 v1.5 DigestInfo signatures (CVE-2026-85393).

Container image: ghcr.io/snapetech/questarrng:1.7.3

Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.3.

QuestarrNG v1.7.2

Choose a tag to compare

@snapetech snapetech released this 01 Oct 20:22

Security

  • Downloader and integration requests now pin HTTPS and HTTP connections to the DNS address checked by the SSRF guard. SABnzbd no longer retries requests with certificate validation disabled; self-signed installations can trust their CA through NODE_EXTRA_CA_CERTS.
  • File browser, import, SSL certificate, and screenshot paths now use canonical containment checks, including existing symlink parents and missing destination paths. Import confirmation rejects library destinations redirected outside the configured root by a symlink.
  • Download-relative paths reject absolute and parent-directory components. Without an explicit path mapping, manual import overrides are restricted to the tracked download's reported directory.
  • Replaced the Prowlarr and Synology string regexes that could take excessive time on crafted input, and added a development-server request limit.
  • Removed npm from the production image and pinned the Python notification runtime with hashes. Updated Apprise and oauthlib to patched releases.

Changed

  • Upgraded Express to 5.2.1 and retained the existing extended query-parser behavior. TypeScript 7 remains excluded until the current typescript-eslint peer range supports it.
  • Upgraded the Windows service to .NET 10 LTS and pinned its SDK and NuGet dependency lock to current servicing versions.
  • Enabled automated dependency and code scanning workflows and applied compatible Dependabot updates.

Container image: ghcr.io/snapetech/questarrng:1.7.2

Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.2.

QuestarrNG v1.7.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 14:51

Fixed

  • Indexer HTTP 401 errors now explain when Questarr withheld an API key because the feed uses HTTP, and distinguish the Prowlarr/indexer opt-in from the downloader setting. Indexer search logs no longer retain feed API keys in request URLs. Downloader test failures now state when the HTTP opt-in did not reach the test request.

Container image: ghcr.io/snapetech/questarrng:1.7.1

Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.1.

QuestarrNG v1.7.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 07:33

Added

  • The SeerrNG catalog endpoint can return the exact day-precision IGDB release date for a requested platform, including null when IGDB has no complete date.

Container image: ghcr.io/snapetech/questarrng:1.7.0

Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.0.

QuestarrNG v1.6.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 06:03

Changed

  • Versioned images and installation manifests now report QuestarrNG 1.6.1 consistently. This maintenance release also removes unused release-branch triggers; application behavior is unchanged.

Container image: ghcr.io/snapetech/questarrng:1.6.1

Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.1.

QuestarrNG v1.6.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 00:38

Added

  • RomM imports: route matched ROM downloads into configured RomM platform folders. Import settings now include a RomM library root, transfer/conflict behavior, platform slug mappings, and manual destination selection. Existing mappings receive safe default slugs during database migration.
  • Prowlarr HTTP opt-in: when syncing indexers from an HTTP Prowlarr instance, administrators can explicitly allow its API key to be sent to the synced HTTP indexers. New indexers remain opted out by default, and syncing with the option off preserves existing per-indexer choices.
  • Prowlarr feed diagnostics: test the management API separately from each enabled torrent or usenet feed to identify indexer-level failures without exposing API keys or feed URLs.
  • Downloader connection checks: the Allow insecure LAN acknowledgement is now applied to unsaved connection-test requests, so operators can test downloaders on trusted HTTP LANs as configured.
  • Proxmox install instructions: the pinned-version example now installs QuestarrNG 1.6.0 from the maintained Snapetech repository.

Fixed

  • File browser scope: directory browsing is limited to configured library and download-mapping roots, and requests through symlinks that escape those roots are rejected.
  • Archive imports: restored directory archive detection and categorized transfer handling so archive and categorized imports follow the maintained import pipeline.
  • Production startup: the compiled server now resolves the shared game-journal schemas and starts successfully after a production build.
  • Database startup: SQLite and PostgreSQL migrations now execute the RomM platform mapping update as separate statements, so fresh and upgraded databases can start successfully.
  • RomM import filenames: filesystem-reserved characters now become spaces, preserving word boundaries in safe ROM destination names.
  • Screenshot uploads: malformed image data now returns a client error instead of surfacing as a server failure.
  • Release images: the tagged QuestarrNG image now publishes both linux/amd64 and linux/arm64, matching the documented supported architectures.

Security

  • IP address parsing dependency: raised the ip-address override to ^10.7.0 (lockfile resolves 10.7.2) to include current upstream security fixes.

Breaking changes

  • Removed the unused legacy PATCH /api/games/:id/notes endpoint. API clients should use the per-user journal endpoints (GET/POST /api/games/:id/journal and DELETE /api/games/:id/journal/:entryId).

Additional changes prepared for 1.5.0 and included in 1.6.0

The 1.5.0 release was not published. Its completed changes ship in 1.6.0:

Removed

  • Legacy PostgreSQL migration tooling: removed scripts/pg-to-sqlite.ts and
    docker-compose.migrate.yml. The tool dated from the v1.1 move off PostgreSQL
    and only knew about 8 of the project's 19 tables, so pointing it at a current
    database would have silently skipped the rest — and it continued past
    per-table failures while still reporting Migration completed. Operators
    still migrating a pre-v1.1 PostgreSQL installation should use the archived
    v1.4.2 release — see MIGRATION.md, which now inlines the
    pinned compose file, links the sources by tag permalink, and spells out how to
    verify the result.

Fixed

  • Downloader connection checks: the insecure-LAN acknowledgement is now
    applied consistently to test-connection requests, allowing configured
    downloaders on trusted HTTP LANs to be tested without bypassing the setting.
  • Documentation: corrected docs/SECRETS.md §8, which presented the
    pg-to-sqlite credential-logging issue as still open. It was real in
    v1.1.0–v1.3.1, which printed the full DATABASE_URL (embedding
    user:password@host), and was fixed in v1.4.0 by commit 99984867; §8
    was never updated when that landed, and its line reference had drifted onto
    the already-fixed line. §8 now states the affected range, the fix, and that
    operators who ran the migration on an affected tag and retained the logs
    should rotate that Postgres password.

Security

  • Dependency Vulnerabilities: Fixed 5 known vulnerabilities in fast-xml-parser, fast-uri, ip-address, and socket.io-parser.
  • Dependency Vulnerabilities: Fixed 3 additional known vulnerabilities in qs and js-yaml, restoring a clean npm audit after the Vulnerability Scan CI job started failing (Doezer#997).
  • Dependency Vulnerabilities: Fixed a critical IP-spoofing vulnerability in proxy-addr, flagged by Aikido Intel.

Vulnerabilities Addressed

  • proxy-addr (npm overrides pin) 2.0.7 → 2.0.8 — fixes CVE-2026-90711 (AIKIDO-2026-101201, CRITICAL) — an undersized IPv4-mapped IPv6 trust-subnet prefix (e.g. ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104) was accepted without error but trusted every IPv4 address on the internet, letting unauthenticated clients spoof X-Forwarded-For and bypass IP-based access controls, rate limiting, and audit logging, vulnerable range >=1.1.0 <=2.0.7. Reaches production via express, which pins proxy-addr: ~2.0.7 (a range that otherwise excludes the fix).
  • fast-xml-parser 5.10.0 → 5.10.1 — fixes GHSA-8r6m-32jq-jx6q (no CVE assigned, HIGH) — a parsing issue in the 5.9.3–5.10.0 range fixed in 5.10.1.
  • fast-uri (npm overrides pin, dev-only via secretlint → ajv) 3.1.3 → 3.1.4 → 3.1.5 — the 3.1.4 → 3.1.5 bump fixes GHSA-7p8r-x3mc-p8w7 (HIGH) — host confusion via backslash authority introducer, vulnerable range 3.0.0 - 3.1.4.
  • ip-address (transitive via express-rate-limit and socks) 10.2.0 → 10.4.0 — fixes GHSA-mwp4-54f8-5fhr (HIGH, SSRF/trust-boundary bypass via octal-decoded leading-zero octets), plus two moderate SSRF-adjacent advisories (GHSA-4xrf-jv44-h6hh, GHSA-22jq-vg5j-6vgg) already covered by the same bump. No overrides pin needed — express-rate-limit's ^10.2.0 and socks's ^10.1.1 ranges already permit 10.4.0.
  • socket.io-parser (npm overrides pin) 4.2.6 → 4.2.7 — fixes GHSA-2m8v-j782-fhvr (HIGH, CVSS 7.5) — zero-attachment memory exhaustion, vulnerable range 4.0.0 - <4.2.7. Reaches production via socket.io/socket.io-client (real-time download-progress and notification updates).
  • qs (npm overrides pin) 6.15.2 → 6.16.0 — fixes GHSA-4mjr-xmp4-gh2g (MODERATE) — DoS via attacker-controlled isBuffer, vulnerable range >=2.2.5 <6.16.0 — and GHSA-x5fp-wj9c-mxmx (MODERATE) — array-limit bypass via bracket-key comma parsing, vulnerable range >=6.14.2 <=6.15.3. Reaches production via express/body-parser, both of which pin qs: ~6.15.1 (a range that otherwise excludes the fix); the same override also closes the gap in openid, steam-web, and superagent (Doezer#997).
  • js-yaml (npm overrides pin, dev-only, scoped to @eslint/eslintrc) 4.3.0 → 4.3.2 — fixes GHSA-5p4m-2wfm-xmqj (HIGH) — quadratic CPU consumption in !!omap resolution. Scoped rather than global so the already-unaffected top-level js-yaml@5.3.0 is left untouched (Doezer#997).

Changed

  • Dependency updates: undici 7.29.0 → 8.9.0 (direct dependency, used by the SSRF-safe fetch wrapper in server/ssrf.ts). No vulnerability fix — see docs/CVE_FIXES_BY_RELEASE.md for verification. Major version bump; undici 8.9.0 requires Node >=22.19.0, so Questarr's own engines.node floor is raised from >=20 to >=22.19.0 to match — this only formalizes existing practice, since CI (node-version: 26.x) and the production Docker image (node:26-alpine) were already on Node 26. Full test suite and server/__tests__/ssrf.test.ts verified green against the new version.

  • QuestarrNG releases: version checks and release links now follow the
    Snapetech fork. Releases publish versioned images under
    ghcr.io/snapetech/questarrng; latest continues to track the fork's main
    build.

Container image: ghcr.io/snapetech/questarrng:1.6.0

Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.0.