Releases: snapetech/QuestarrNG
Release list
QuestarrNG v1.9.0
User-facing changes
Added
- Game Details: Game details now include an expansions tab with available DLC and expansion covers, release years, category labels, and links to their IGDB pages.
- Library Platforms: Platform preferences now carry across library filters, discovery, game adding, download searches, and import eligibility. Hide shelved or already-owned results by default, and track games on a Playing page with notes, milestones, screenshots, and Steam achievements.
- Discovery: Settings now support a global release-name blacklist that filters matching terms from manual searches, auto-search cycles, and AI-assisted release selection.
Security
- Imports: Optional VirusTotal hash lookups and local ClamAV scans run before downloads are unpacked or moved into the library. Flagged files are quarantined and create a Security Alert instead of being imported.
Container image: ghcr.io/snapetech/questarrng:1.9.0
Pull with: docker pull ghcr.io/snapetech/questarrng:1.9.0.
QuestarrNG v1.8.3
User-facing changes
Added
- Settings: System settings now include a Ko-fi link for users who want to support QuestarrNG fork maintenance.
Security
- Dependencies: All application dependencies now pass the full npm security audit, including development tooling. The cache-policy fix from upstream PR Doezer#60 is covered locally while it awaits maintainer review, and license checks no longer pull in a separate npm resolver stack.
Container image: ghcr.io/snapetech/questarrng:1.8.3
Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.3.
QuestarrNG v1.8.1
User-facing changes
Security
- Dependencies: Questarr now pins a tested upstream fix for CVE-2026-93748, preventing stale-cache directives from reusing shared responses that require validation while upstream reviews the fix.
Container image: ghcr.io/snapetech/questarrng:1.8.1
Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.1.
QuestarrNG v1.8.0
User-facing changes
Changed
- Integrations: The SeerrNG provider API now has a versioned OpenAPI contract with a conformance test for its handshake and required route parameters.
Security
- Imports: Archive imports now reject traversal paths and links, and enforce configurable total-entry and declared-expansion limits before archive data is decompressed or written into a game library.
- Action required: Set ARCHIVE_MAX_EXPANDED_BYTES or ARCHIVE_MAX_ENTRIES if your archives need different limits.
- Containers: Compose and Helm deployments can run QuestarrNG as a non-root user with a read-only root filesystem and no Linux capabilities. The image entrypoint preserves
UMASKand checks the writable data volume without changing ownership; rootless file logs are stored there at/app/data/server.log. Published images now include SBOM and provenance attestations.- Action required: Prepare the data volume with the configured UID and GID before enabling rootless mode.
- Integrations: Integration API keys can now be limited to SeerrNG routes and expire after a configurable 30–365 days; existing keys retain their current access, and Settings shows each key's scope and expiry.
- Action required: Create a replacement key if a client should use the new scope or expiration settings.
Container image: ghcr.io/snapetech/questarrng:1.8.0
Pull with: docker pull ghcr.io/snapetech/questarrng:1.8.0.
QuestarrNG v1.7.3
User-facing changes
Changed
- Release Pipeline: Release-note fragments now appear in versioned releases, and Discord announcements use the shared channel webhook configured as the
DISCORD_RELEASE_WEBHOOKActions secret.
Security
- Proxy: YunoHost proxy requests now use a fixed upstream host and forward WebSocket upgrades only, blocking attacker-controlled host and h2c upgrade headers.
- Dependencies: Questarr now bundles a locally patched node-forge release that rejects malformed RSA PKCS#1 v1.5 DigestInfo signatures (CVE-2026-85393).
Container image: ghcr.io/snapetech/questarrng:1.7.3
Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.3.
QuestarrNG v1.7.2
Security
- Downloader and integration requests now pin HTTPS and HTTP connections to the DNS address checked by the SSRF guard. SABnzbd no longer retries requests with certificate validation disabled; self-signed installations can trust their CA through
NODE_EXTRA_CA_CERTS. - File browser, import, SSL certificate, and screenshot paths now use canonical containment checks, including existing symlink parents and missing destination paths. Import confirmation rejects library destinations redirected outside the configured root by a symlink.
- Download-relative paths reject absolute and parent-directory components. Without an explicit path mapping, manual import overrides are restricted to the tracked download's reported directory.
- Replaced the Prowlarr and Synology string regexes that could take excessive time on crafted input, and added a development-server request limit.
- Removed npm from the production image and pinned the Python notification runtime with hashes. Updated Apprise and oauthlib to patched releases.
Changed
- Upgraded Express to 5.2.1 and retained the existing extended query-parser behavior. TypeScript 7 remains excluded until the current typescript-eslint peer range supports it.
- Upgraded the Windows service to .NET 10 LTS and pinned its SDK and NuGet dependency lock to current servicing versions.
- Enabled automated dependency and code scanning workflows and applied compatible Dependabot updates.
Container image: ghcr.io/snapetech/questarrng:1.7.2
Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.2.
QuestarrNG v1.7.1
Fixed
- Indexer HTTP 401 errors now explain when Questarr withheld an API key because the feed uses HTTP, and distinguish the Prowlarr/indexer opt-in from the downloader setting. Indexer search logs no longer retain feed API keys in request URLs. Downloader test failures now state when the HTTP opt-in did not reach the test request.
Container image: ghcr.io/snapetech/questarrng:1.7.1
Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.1.
QuestarrNG v1.7.0
Added
- The SeerrNG catalog endpoint can return the exact day-precision IGDB release date for a requested platform, including
nullwhen IGDB has no complete date.
Container image: ghcr.io/snapetech/questarrng:1.7.0
Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.0.
QuestarrNG v1.6.1
Changed
- Versioned images and installation manifests now report QuestarrNG 1.6.1 consistently. This maintenance release also removes unused release-branch triggers; application behavior is unchanged.
Container image: ghcr.io/snapetech/questarrng:1.6.1
Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.1.
QuestarrNG v1.6.0
Added
- RomM imports: route matched ROM downloads into configured RomM platform folders. Import settings now include a RomM library root, transfer/conflict behavior, platform slug mappings, and manual destination selection. Existing mappings receive safe default slugs during database migration.
- Prowlarr HTTP opt-in: when syncing indexers from an HTTP Prowlarr instance, administrators can explicitly allow its API key to be sent to the synced HTTP indexers. New indexers remain opted out by default, and syncing with the option off preserves existing per-indexer choices.
- Prowlarr feed diagnostics: test the management API separately from each enabled torrent or usenet feed to identify indexer-level failures without exposing API keys or feed URLs.
- Downloader connection checks: the Allow insecure LAN acknowledgement is now applied to unsaved connection-test requests, so operators can test downloaders on trusted HTTP LANs as configured.
- Proxmox install instructions: the pinned-version example now installs QuestarrNG 1.6.0 from the maintained Snapetech repository.
Fixed
- File browser scope: directory browsing is limited to configured library and download-mapping roots, and requests through symlinks that escape those roots are rejected.
- Archive imports: restored directory archive detection and categorized transfer handling so archive and categorized imports follow the maintained import pipeline.
- Production startup: the compiled server now resolves the shared game-journal schemas and starts successfully after a production build.
- Database startup: SQLite and PostgreSQL migrations now execute the RomM platform mapping update as separate statements, so fresh and upgraded databases can start successfully.
- RomM import filenames: filesystem-reserved characters now become spaces, preserving word boundaries in safe ROM destination names.
- Screenshot uploads: malformed image data now returns a client error instead of surfacing as a server failure.
- Release images: the tagged QuestarrNG image now publishes both
linux/amd64andlinux/arm64, matching the documented supported architectures.
Security
- IP address parsing dependency: raised the
ip-addressoverride to^10.7.0(lockfile resolves 10.7.2) to include current upstream security fixes.
Breaking changes
- Removed the unused legacy
PATCH /api/games/:id/notesendpoint. API clients should use the per-user journal endpoints (GET/POST /api/games/:id/journalandDELETE /api/games/:id/journal/:entryId).
Additional changes prepared for 1.5.0 and included in 1.6.0
The 1.5.0 release was not published. Its completed changes ship in 1.6.0:
Removed
- Legacy PostgreSQL migration tooling: removed
scripts/pg-to-sqlite.tsand
docker-compose.migrate.yml. The tool dated from the v1.1 move off PostgreSQL
and only knew about 8 of the project's 19 tables, so pointing it at a current
database would have silently skipped the rest — and it continued past
per-table failures while still reportingMigration completed.Operators
still migrating a pre-v1.1 PostgreSQL installation should use the archived
v1.4.2 release — see MIGRATION.md, which now inlines the
pinned compose file, links the sources by tag permalink, and spells out how to
verify the result.
Fixed
- Downloader connection checks: the insecure-LAN acknowledgement is now
applied consistently to test-connection requests, allowing configured
downloaders on trusted HTTP LANs to be tested without bypassing the setting. - Documentation: corrected
docs/SECRETS.md§8, which presented the
pg-to-sqlitecredential-logging issue as still open. It was real in
v1.1.0–v1.3.1, which printed the fullDATABASE_URL(embedding
user:password@host), and was fixed in v1.4.0 by commit99984867; §8
was never updated when that landed, and its line reference had drifted onto
the already-fixed line. §8 now states the affected range, the fix, and that
operators who ran the migration on an affected tag and retained the logs
should rotate that Postgres password.
Security
- Dependency Vulnerabilities: Fixed 5 known vulnerabilities in
fast-xml-parser,fast-uri,ip-address, andsocket.io-parser. - Dependency Vulnerabilities: Fixed 3 additional known vulnerabilities in
qsandjs-yaml, restoring a cleannpm auditafter the Vulnerability Scan CI job started failing (Doezer#997). - Dependency Vulnerabilities: Fixed a critical IP-spoofing vulnerability in
proxy-addr, flagged by Aikido Intel.
Vulnerabilities Addressed
- proxy-addr (npm
overridespin) 2.0.7 → 2.0.8 — fixes CVE-2026-90711 (AIKIDO-2026-101201, CRITICAL) — an undersized IPv4-mapped IPv6 trust-subnet prefix (e.g.::ffff:10.0.0.0/8instead of::ffff:10.0.0.0/104) was accepted without error but trusted every IPv4 address on the internet, letting unauthenticated clients spoofX-Forwarded-Forand bypass IP-based access controls, rate limiting, and audit logging, vulnerable range>=1.1.0 <=2.0.7. Reaches production viaexpress, which pinsproxy-addr: ~2.0.7(a range that otherwise excludes the fix). - fast-xml-parser 5.10.0 → 5.10.1 — fixes GHSA-8r6m-32jq-jx6q (no CVE assigned, HIGH) — a parsing issue in the 5.9.3–5.10.0 range fixed in 5.10.1.
- fast-uri (npm
overridespin, dev-only viasecretlint→ajv) 3.1.3 → 3.1.4 → 3.1.5 — the 3.1.4 → 3.1.5 bump fixes GHSA-7p8r-x3mc-p8w7 (HIGH) — host confusion via backslash authority introducer, vulnerable range3.0.0 - 3.1.4. - ip-address (transitive via
express-rate-limitandsocks) 10.2.0 → 10.4.0 — fixes GHSA-mwp4-54f8-5fhr (HIGH, SSRF/trust-boundary bypass via octal-decoded leading-zero octets), plus two moderate SSRF-adjacent advisories (GHSA-4xrf-jv44-h6hh, GHSA-22jq-vg5j-6vgg) already covered by the same bump. Nooverridespin needed —express-rate-limit's^10.2.0andsocks's^10.1.1ranges already permit 10.4.0. - socket.io-parser (npm
overridespin) 4.2.6 → 4.2.7 — fixes GHSA-2m8v-j782-fhvr (HIGH, CVSS 7.5) — zero-attachment memory exhaustion, vulnerable range4.0.0 - <4.2.7. Reaches production viasocket.io/socket.io-client(real-time download-progress and notification updates). - qs (npm
overridespin) 6.15.2 → 6.16.0 — fixes GHSA-4mjr-xmp4-gh2g (MODERATE) — DoS via attacker-controlledisBuffer, vulnerable range>=2.2.5 <6.16.0— and GHSA-x5fp-wj9c-mxmx (MODERATE) — array-limit bypass via bracket-key comma parsing, vulnerable range>=6.14.2 <=6.15.3. Reaches production viaexpress/body-parser, both of which pinqs: ~6.15.1(a range that otherwise excludes the fix); the same override also closes the gap inopenid,steam-web, andsuperagent(Doezer#997). - js-yaml (npm
overridespin, dev-only, scoped to@eslint/eslintrc) 4.3.0 → 4.3.2 — fixes GHSA-5p4m-2wfm-xmqj (HIGH) — quadratic CPU consumption in!!omapresolution. Scoped rather than global so the already-unaffected top-leveljs-yaml@5.3.0is left untouched (Doezer#997).
Changed
-
Dependency updates:
undici7.29.0 → 8.9.0 (direct dependency, used by the SSRF-safe fetch wrapper inserver/ssrf.ts). No vulnerability fix — seedocs/CVE_FIXES_BY_RELEASE.mdfor verification. Major version bump; undici 8.9.0 requires Node>=22.19.0, so Questarr's ownengines.nodefloor is raised from>=20to>=22.19.0to match — this only formalizes existing practice, since CI (node-version: 26.x) and the production Docker image (node:26-alpine) were already on Node 26. Full test suite andserver/__tests__/ssrf.test.tsverified green against the new version. -
QuestarrNG releases: version checks and release links now follow the
Snapetech fork. Releases publish versioned images under
ghcr.io/snapetech/questarrng;latestcontinues to track the fork's main
build.
Container image: ghcr.io/snapetech/questarrng:1.6.0
Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.0.