v1.6.1-rc.15
Full Changelog: v1.6.1-rc.14...v1.6.1-rc.15
[1.6.1-rc.15] — 2026-10-02
Security
- Patch brace-expansion to 5.0.12 and the website to Next.js 16.3.6. Update Axios to 1.20.0 for its HTTP request security fixes.
- Update Undici to 8.10.2, Nodemailer to 10.0.9, gRPC to 1.14.5, Moment to 2.31.0, fast-uri to 4.1.5, and ip-address to 10.7.1 for the newly published dependency advisories. Keep UI and E2E Undici on their patched 7.29.1 line. Nodemailer 10 requires Node.js 20 or newer; Drydock already requires Node.js 24.
- Update Alpine OpenSSL to 3.5.9-r0 after 3.5.8-r0 left the package index, and drop the scanner exception for CVE-2026-14456, which the packaged OpenSSL has fixed since 3.5.8. Axios 1.20.0 also starts honouring CIDR entries in
NO_PROXY, so a registry address covered by one now connects directly instead of through the configured proxy. - Patch Alpine zlib 1.3.2 with the upstream fix for CVE-2026-85091 and update libexpat to 2.8.5-r0 for CVE-2026-93990. The temporary zlib APK retains its upstream version and records a unique local revision; its exact backport is documented in the image scanner's VEX evidence.
Fixed
- Let accepted bulk vulnerability scans finish after the HTTP request completes normally. Previously, inventories larger than the four-scan concurrency limit could stop after the first batch while the UI kept waiting for the remaining results. Prematurely closed, incomplete requests still stop queued scans.
Note: this is a maintenance cut, built from dev/v1.6 at fb436e55c41cb70281979160d030eccfeb3f2048, not from main.
- The container image and release artifact are cosign-signed (identity
release-cut.yml@refs/heads/main, since the workflow run itself always executes at that ref), but carry no SLSA build-provenance attestation — this workflow's own OIDC token always claimsmainHEAD as the build source, which would be false for this artifact, so attestation is skipped rather than publish a false claim.