Skip to content

QuestarrNG v1.6.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 00:38
· 411 commits to main since this release

Added

  • RomM imports: route matched ROM downloads into configured RomM platform folders. Import settings now include a RomM library root, transfer/conflict behavior, platform slug mappings, and manual destination selection. Existing mappings receive safe default slugs during database migration.
  • Prowlarr HTTP opt-in: when syncing indexers from an HTTP Prowlarr instance, administrators can explicitly allow its API key to be sent to the synced HTTP indexers. New indexers remain opted out by default, and syncing with the option off preserves existing per-indexer choices.
  • Prowlarr feed diagnostics: test the management API separately from each enabled torrent or usenet feed to identify indexer-level failures without exposing API keys or feed URLs.
  • Downloader connection checks: the Allow insecure LAN acknowledgement is now applied to unsaved connection-test requests, so operators can test downloaders on trusted HTTP LANs as configured.
  • Proxmox install instructions: the pinned-version example now installs QuestarrNG 1.6.0 from the maintained Snapetech repository.

Fixed

  • File browser scope: directory browsing is limited to configured library and download-mapping roots, and requests through symlinks that escape those roots are rejected.
  • Archive imports: restored directory archive detection and categorized transfer handling so archive and categorized imports follow the maintained import pipeline.
  • Production startup: the compiled server now resolves the shared game-journal schemas and starts successfully after a production build.
  • Database startup: SQLite and PostgreSQL migrations now execute the RomM platform mapping update as separate statements, so fresh and upgraded databases can start successfully.
  • RomM import filenames: filesystem-reserved characters now become spaces, preserving word boundaries in safe ROM destination names.
  • Screenshot uploads: malformed image data now returns a client error instead of surfacing as a server failure.
  • Release images: the tagged QuestarrNG image now publishes both linux/amd64 and linux/arm64, matching the documented supported architectures.

Security

  • IP address parsing dependency: raised the ip-address override to ^10.7.0 (lockfile resolves 10.7.2) to include current upstream security fixes.

Breaking changes

  • Removed the unused legacy PATCH /api/games/:id/notes endpoint. API clients should use the per-user journal endpoints (GET/POST /api/games/:id/journal and DELETE /api/games/:id/journal/:entryId).

Additional changes prepared for 1.5.0 and included in 1.6.0

The 1.5.0 release was not published. Its completed changes ship in 1.6.0:

Removed

  • Legacy PostgreSQL migration tooling: removed scripts/pg-to-sqlite.ts and
    docker-compose.migrate.yml. The tool dated from the v1.1 move off PostgreSQL
    and only knew about 8 of the project's 19 tables, so pointing it at a current
    database would have silently skipped the rest — and it continued past
    per-table failures while still reporting Migration completed. Operators
    still migrating a pre-v1.1 PostgreSQL installation should use the archived
    v1.4.2 release — see MIGRATION.md, which now inlines the
    pinned compose file, links the sources by tag permalink, and spells out how to
    verify the result.

Fixed

  • Downloader connection checks: the insecure-LAN acknowledgement is now
    applied consistently to test-connection requests, allowing configured
    downloaders on trusted HTTP LANs to be tested without bypassing the setting.
  • Documentation: corrected docs/SECRETS.md §8, which presented the
    pg-to-sqlite credential-logging issue as still open. It was real in
    v1.1.0–v1.3.1, which printed the full DATABASE_URL (embedding
    user:password@host), and was fixed in v1.4.0 by commit 99984867; §8
    was never updated when that landed, and its line reference had drifted onto
    the already-fixed line. §8 now states the affected range, the fix, and that
    operators who ran the migration on an affected tag and retained the logs
    should rotate that Postgres password.

Security

  • Dependency Vulnerabilities: Fixed 5 known vulnerabilities in fast-xml-parser, fast-uri, ip-address, and socket.io-parser.
  • Dependency Vulnerabilities: Fixed 3 additional known vulnerabilities in qs and js-yaml, restoring a clean npm audit after the Vulnerability Scan CI job started failing (Doezer#997).
  • Dependency Vulnerabilities: Fixed a critical IP-spoofing vulnerability in proxy-addr, flagged by Aikido Intel.

Vulnerabilities Addressed

  • proxy-addr (npm overrides pin) 2.0.7 → 2.0.8 — fixes CVE-2026-90711 (AIKIDO-2026-101201, CRITICAL) — an undersized IPv4-mapped IPv6 trust-subnet prefix (e.g. ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104) was accepted without error but trusted every IPv4 address on the internet, letting unauthenticated clients spoof X-Forwarded-For and bypass IP-based access controls, rate limiting, and audit logging, vulnerable range >=1.1.0 <=2.0.7. Reaches production via express, which pins proxy-addr: ~2.0.7 (a range that otherwise excludes the fix).
  • fast-xml-parser 5.10.0 → 5.10.1 — fixes GHSA-8r6m-32jq-jx6q (no CVE assigned, HIGH) — a parsing issue in the 5.9.3–5.10.0 range fixed in 5.10.1.
  • fast-uri (npm overrides pin, dev-only via secretlint → ajv) 3.1.3 → 3.1.4 → 3.1.5 — the 3.1.4 → 3.1.5 bump fixes GHSA-7p8r-x3mc-p8w7 (HIGH) — host confusion via backslash authority introducer, vulnerable range 3.0.0 - 3.1.4.
  • ip-address (transitive via express-rate-limit and socks) 10.2.0 → 10.4.0 — fixes GHSA-mwp4-54f8-5fhr (HIGH, SSRF/trust-boundary bypass via octal-decoded leading-zero octets), plus two moderate SSRF-adjacent advisories (GHSA-4xrf-jv44-h6hh, GHSA-22jq-vg5j-6vgg) already covered by the same bump. No overrides pin needed — express-rate-limit's ^10.2.0 and socks's ^10.1.1 ranges already permit 10.4.0.
  • socket.io-parser (npm overrides pin) 4.2.6 → 4.2.7 — fixes GHSA-2m8v-j782-fhvr (HIGH, CVSS 7.5) — zero-attachment memory exhaustion, vulnerable range 4.0.0 - <4.2.7. Reaches production via socket.io/socket.io-client (real-time download-progress and notification updates).
  • qs (npm overrides pin) 6.15.2 → 6.16.0 — fixes GHSA-4mjr-xmp4-gh2g (MODERATE) — DoS via attacker-controlled isBuffer, vulnerable range >=2.2.5 <6.16.0 — and GHSA-x5fp-wj9c-mxmx (MODERATE) — array-limit bypass via bracket-key comma parsing, vulnerable range >=6.14.2 <=6.15.3. Reaches production via express/body-parser, both of which pin qs: ~6.15.1 (a range that otherwise excludes the fix); the same override also closes the gap in openid, steam-web, and superagent (Doezer#997).
  • js-yaml (npm overrides pin, dev-only, scoped to @eslint/eslintrc) 4.3.0 → 4.3.2 — fixes GHSA-5p4m-2wfm-xmqj (HIGH) — quadratic CPU consumption in !!omap resolution. Scoped rather than global so the already-unaffected top-level js-yaml@5.3.0 is left untouched (Doezer#997).

Changed

  • Dependency updates: undici 7.29.0 → 8.9.0 (direct dependency, used by the SSRF-safe fetch wrapper in server/ssrf.ts). No vulnerability fix — see docs/CVE_FIXES_BY_RELEASE.md for verification. Major version bump; undici 8.9.0 requires Node >=22.19.0, so Questarr's own engines.node floor is raised from >=20 to >=22.19.0 to match — this only formalizes existing practice, since CI (node-version: 26.x) and the production Docker image (node:26-alpine) were already on Node 26. Full test suite and server/__tests__/ssrf.test.ts verified green against the new version.

  • QuestarrNG releases: version checks and release links now follow the
    Snapetech fork. Releases publish versioned images under
    ghcr.io/snapetech/questarrng; latest continues to track the fork's main
    build.

Container image: ghcr.io/snapetech/questarrng:1.6.0

Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.0.