github CodesWhat/drydock v1.7.0-rc.17

pre-release3 hours ago

v1.7.0-rc.17

Full Changelog: v1.7.0-rc.16...v1.7.0-rc.17

[1.7.0-rc.17] — 2026-10-02

Security

  • Patch brace-expansion to 5.0.12 and the website to Next.js 16.3.6. Update DOMPurify to 3.4.16 for its in-place sanitization fix.
  • Update Undici to 8.10.2, Nodemailer to 10.0.9, gRPC to 1.14.5, Moment to 2.31.0, fast-uri to 4.1.5, and ip-address to 10.7.1 for the newly published dependency advisories. Keep UI and E2E Undici on their patched 7.29.1 line. Nodemailer 10 requires Node.js 20 or newer; Drydock already requires Node.js 24.
  • Update Alpine OpenSSL to 3.5.9-r0 after 3.5.8-r0 left the package index and the pinned install stopped resolving.
  • Patch Alpine zlib 1.3.2 with the upstream fix for CVE-2026-85091 and update libexpat to 2.8.5-r0 for CVE-2026-93990. The temporary zlib APK retains its upstream version and records a unique local revision; its exact backport is documented in the image scanner's VEX evidence.

Fixed

  • #1284: a disabled healthcheck no longer health-gates the update. A container with healthcheck: disable: true (stored by Docker as Test: ["NONE"]), an empty test, or a healthcheck block with only timing fields was treated as having a healthcheck. Docker never reports a health state for those, so the Docker action waited out the whole rollback window and rolled back an update that had started fine. The gate now applies only when the container has a real CMD or CMD-SHELL probe or Docker is reporting health.
  • #1280: update policy set in the UI survives recreation of an agent-managed container. An agent reports a recreated container as a removal of the old id and an addition of the new one. The controller deleted the old row without keeping its policy, so a maturity setting made in the UI was lost every time the container was updated. The policy is now carried to the replacement whichever of the two events arrives first, and also when a reconnecting agent's snapshot drops the old id before listing the new one. It is only ever carried to a container with the same agent, watcher and name. A local scan that catches Drydock's temporary -old-<timestamp> rename no longer stores that name, which could make the same carry-over miss on the controller host.
  • #1281: the Docker Hub config blob redirect is no longer logged as a failure. Registry redirects are not followed, so the optional created-date lookup against Docker Hub always ends in a 307. The debug line now says the created date is optional and was skipped, instead of "Unable to fetch image config blob created date", which read like the reason an update had not run.
  • Let accepted bulk vulnerability scans finish after the HTTP request completes normally. Previously, inventories larger than the four-scan concurrency limit could stop after the first batch while the UI kept waiting for the remaining results. Prematurely closed, incomplete requests still stop queued scans.

Don't miss a new drydock release

NewReleases is sending notifications on new releases.