Repository navigation
QuestarrNG v1.6.0
Added
- RomM imports: route matched ROM downloads into configured RomM platform folders. Import settings now include a RomM library root, transfer/conflict behavior, platform slug mappings, and manual destination selection. Existing mappings receive safe default slugs during database migration.
- Prowlarr HTTP opt-in: when syncing indexers from an HTTP Prowlarr instance, administrators can explicitly allow its API key to be sent to the synced HTTP indexers. New indexers remain opted out by default, and syncing with the option off preserves existing per-indexer choices.
- Prowlarr feed diagnostics: test the management API separately from each enabled torrent or usenet feed to identify indexer-level failures without exposing API keys or feed URLs.
- Downloader connection checks: the Allow insecure LAN acknowledgement is now applied to unsaved connection-test requests, so operators can test downloaders on trusted HTTP LANs as configured.
- Proxmox install instructions: the pinned-version example now installs QuestarrNG 1.6.0 from the maintained Snapetech repository.
Fixed
- File browser scope: directory browsing is limited to configured library and download-mapping roots, and requests through symlinks that escape those roots are rejected.
- Archive imports: restored directory archive detection and categorized transfer handling so archive and categorized imports follow the maintained import pipeline.
- Production startup: the compiled server now resolves the shared game-journal schemas and starts successfully after a production build.
- Database startup: SQLite and PostgreSQL migrations now execute the RomM platform mapping update as separate statements, so fresh and upgraded databases can start successfully.
- RomM import filenames: filesystem-reserved characters now become spaces, preserving word boundaries in safe ROM destination names.
- Screenshot uploads: malformed image data now returns a client error instead of surfacing as a server failure.
- Release images: the tagged QuestarrNG image now publishes both
linux/amd64andlinux/arm64, matching the documented supported architectures.
Security
- IP address parsing dependency: raised the
ip-addressoverride to^10.7.0(lockfile resolves 10.7.2) to include current upstream security fixes.
Breaking changes
- Removed the unused legacy
PATCH /api/games/:id/notesendpoint. API clients should use the per-user journal endpoints (GET/POST /api/games/:id/journalandDELETE /api/games/:id/journal/:entryId).
Additional changes prepared for 1.5.0 and included in 1.6.0
The 1.5.0 release was not published. Its completed changes ship in 1.6.0:
Removed
- Legacy PostgreSQL migration tooling: removed
scripts/pg-to-sqlite.tsand
docker-compose.migrate.yml. The tool dated from the v1.1 move off PostgreSQL
and only knew about 8 of the project's 19 tables, so pointing it at a current
database would have silently skipped the rest — and it continued past
per-table failures while still reportingMigration completed.Operators
still migrating a pre-v1.1 PostgreSQL installation should use the archived
v1.4.2 release — see MIGRATION.md, which now inlines the
pinned compose file, links the sources by tag permalink, and spells out how to
verify the result.
Fixed
- Downloader connection checks: the insecure-LAN acknowledgement is now
applied consistently to test-connection requests, allowing configured
downloaders on trusted HTTP LANs to be tested without bypassing the setting. - Documentation: corrected
docs/SECRETS.md§8, which presented the
pg-to-sqlitecredential-logging issue as still open. It was real in
v1.1.0–v1.3.1, which printed the fullDATABASE_URL(embedding
user:password@host), and was fixed in v1.4.0 by commit99984867; §8
was never updated when that landed, and its line reference had drifted onto
the already-fixed line. §8 now states the affected range, the fix, and that
operators who ran the migration on an affected tag and retained the logs
should rotate that Postgres password.
Security
- Dependency Vulnerabilities: Fixed 5 known vulnerabilities in
fast-xml-parser,fast-uri,ip-address, andsocket.io-parser. - Dependency Vulnerabilities: Fixed 3 additional known vulnerabilities in
qsandjs-yaml, restoring a cleannpm auditafter the Vulnerability Scan CI job started failing (Doezer#997). - Dependency Vulnerabilities: Fixed a critical IP-spoofing vulnerability in
proxy-addr, flagged by Aikido Intel.
Vulnerabilities Addressed
- proxy-addr (npm
overridespin) 2.0.7 → 2.0.8 — fixes CVE-2026-90711 (AIKIDO-2026-101201, CRITICAL) — an undersized IPv4-mapped IPv6 trust-subnet prefix (e.g.::ffff:10.0.0.0/8instead of::ffff:10.0.0.0/104) was accepted without error but trusted every IPv4 address on the internet, letting unauthenticated clients spoofX-Forwarded-Forand bypass IP-based access controls, rate limiting, and audit logging, vulnerable range>=1.1.0 <=2.0.7. Reaches production viaexpress, which pinsproxy-addr: ~2.0.7(a range that otherwise excludes the fix). - fast-xml-parser 5.10.0 → 5.10.1 — fixes GHSA-8r6m-32jq-jx6q (no CVE assigned, HIGH) — a parsing issue in the 5.9.3–5.10.0 range fixed in 5.10.1.
- fast-uri (npm
overridespin, dev-only viasecretlint→ajv) 3.1.3 → 3.1.4 → 3.1.5 — the 3.1.4 → 3.1.5 bump fixes GHSA-7p8r-x3mc-p8w7 (HIGH) — host confusion via backslash authority introducer, vulnerable range3.0.0 - 3.1.4. - ip-address (transitive via
express-rate-limitandsocks) 10.2.0 → 10.4.0 — fixes GHSA-mwp4-54f8-5fhr (HIGH, SSRF/trust-boundary bypass via octal-decoded leading-zero octets), plus two moderate SSRF-adjacent advisories (GHSA-4xrf-jv44-h6hh, GHSA-22jq-vg5j-6vgg) already covered by the same bump. Nooverridespin needed —express-rate-limit's^10.2.0andsocks's^10.1.1ranges already permit 10.4.0. - socket.io-parser (npm
overridespin) 4.2.6 → 4.2.7 — fixes GHSA-2m8v-j782-fhvr (HIGH, CVSS 7.5) — zero-attachment memory exhaustion, vulnerable range4.0.0 - <4.2.7. Reaches production viasocket.io/socket.io-client(real-time download-progress and notification updates). - qs (npm
overridespin) 6.15.2 → 6.16.0 — fixes GHSA-4mjr-xmp4-gh2g (MODERATE) — DoS via attacker-controlledisBuffer, vulnerable range>=2.2.5 <6.16.0— and GHSA-x5fp-wj9c-mxmx (MODERATE) — array-limit bypass via bracket-key comma parsing, vulnerable range>=6.14.2 <=6.15.3. Reaches production viaexpress/body-parser, both of which pinqs: ~6.15.1(a range that otherwise excludes the fix); the same override also closes the gap inopenid,steam-web, andsuperagent(Doezer#997). - js-yaml (npm
overridespin, dev-only, scoped to@eslint/eslintrc) 4.3.0 → 4.3.2 — fixes GHSA-5p4m-2wfm-xmqj (HIGH) — quadratic CPU consumption in!!omapresolution. Scoped rather than global so the already-unaffected top-leveljs-yaml@5.3.0is left untouched (Doezer#997).
Changed
-
Dependency updates:
undici7.29.0 → 8.9.0 (direct dependency, used by the SSRF-safe fetch wrapper inserver/ssrf.ts). No vulnerability fix — seedocs/CVE_FIXES_BY_RELEASE.mdfor verification. Major version bump; undici 8.9.0 requires Node>=22.19.0, so Questarr's ownengines.nodefloor is raised from>=20to>=22.19.0to match — this only formalizes existing practice, since CI (node-version: 26.x) and the production Docker image (node:26-alpine) were already on Node 26. Full test suite andserver/__tests__/ssrf.test.tsverified green against the new version. -
QuestarrNG releases: version checks and release links now follow the
Snapetech fork. Releases publish versioned images under
ghcr.io/snapetech/questarrng;latestcontinues to track the fork's main
build.
Container image: ghcr.io/snapetech/questarrng:1.6.0
Pull with: docker pull ghcr.io/snapetech/questarrng:1.6.0.