QuestarrNG v1.7.2
Security
- Downloader and integration requests now pin HTTPS and HTTP connections to the DNS address checked by the SSRF guard. SABnzbd no longer retries requests with certificate validation disabled; self-signed installations can trust their CA through
NODE_EXTRA_CA_CERTS. - File browser, import, SSL certificate, and screenshot paths now use canonical containment checks, including existing symlink parents and missing destination paths. Import confirmation rejects library destinations redirected outside the configured root by a symlink.
- Download-relative paths reject absolute and parent-directory components. Without an explicit path mapping, manual import overrides are restricted to the tracked download's reported directory.
- Replaced the Prowlarr and Synology string regexes that could take excessive time on crafted input, and added a development-server request limit.
- Removed npm from the production image and pinned the Python notification runtime with hashes. Updated Apprise and oauthlib to patched releases.
Changed
- Upgraded Express to 5.2.1 and retained the existing extended query-parser behavior. TypeScript 7 remains excluded until the current typescript-eslint peer range supports it.
- Upgraded the Windows service to .NET 10 LTS and pinned its SDK and NuGet dependency lock to current servicing versions.
- Enabled automated dependency and code scanning workflows and applied compatible Dependabot updates.
Container image: ghcr.io/snapetech/questarrng:1.7.2
Pull with: docker pull ghcr.io/snapetech/questarrng:1.7.2.