Quay
Container image registry with security scanning
The public release feed is pure CVE backporting across two frozen branches.
◆Recent moves
- 17d ago
SSRF fix in proxy cache upstream registry configuration
Alongside the usual dependency bumps, this release fixes server-side request forgery in the proxy cache upstream registry configuration — the only change in the recent feed that patches Quay's own code rather than a dependency. Proxy cache is the feature that talks to arbitrary upstream registries, so it is the natural place for this class of bug.
View source ↗ - 23d ago
Proxy cache SSRF fix backported to the 3.10 branch
The 3.10 branch counterpart carrying the same proxy cache SSRF fix and the same Go and dependency updates, six days ahead of the 3.12 release. The paired-branch backport rhythm is the defining shape of this feed.
View source ↗ - 1mo ago
Dependency CVE roundup for the 3.10 branch
A pure dependency CVE roundup — PyJWT, urllib3, axios, shell-quote and kafka-python — with CI housekeeping and an automated changelog bump. No change an operator would observe beyond the version number.
View source ↗ - 1mo ago
Dependency CVE roundup for the 3.12 branch
The 3.12 twin of the same dependency CVE set, released five days earlier with an identical fix list. Two branches, one set of advisories, no product change.
View source ↗