github Doezer/Questarr v1.5.0-rc1

pre-release5 hours ago

TL;DR

Highlights

  • Library: Scan Disk / root folders to pick up games already on disk, a global Platforms setting, a new Playing status and page (journal, milestones, screenshots, Steam achievements), a DLC tab, installed-version tracking, Time to Beat and crack status.
  • Downloads & import: optional pre-import VirusTotal/ClamAV scanning, a global release-name blacklist, password-protected archive handling, and an optional AI release check (experimental, bring your own key).
  • Integrations & deployment: optional PostgreSQL backend, Playnite extension, Steam wishlist auto-sync, Windows installer, Helm chart, Proxmox LXC script, CasaOS/Umbrel/Cosmos templates, and QUESTARR_BASE_PATH as a runtime setting.

Fixes: much more reliable imports (RAR and multi-volume extraction, hardlink fallback, failed imports now land in manual review), SABnzbd/NZBGet/qBittorrent v5 fixes, and Playing/Shelved/Completed statuses are no longer overwritten by downloads.

Security: auth moved to httpOnly cookies + CSRF, the real-time channel now requires a session, an IDOR on games was fixed, SSRF/XSS hardening, and 17 production dependency vulnerabilities were fixed (including a critical proxy-addr IP-spoofing issue).

Before you upgrade

  • Running from source? Node >=22.19.0 is now required (the Docker image already uses Node 26).
  • Behind a reverse proxy that doesn't set X-Forwarded-Host, add your public URL to ALLOWED_ORIGINS or APP_URL, or live updates won't connect.
  • Downloaders with self-signed certificates: the TLS bypass is now opt-in, re-enable it per downloader.
  • Indexers over plain HTTP on your LAN need the new per-indexer insecure opt-in.
  • New passwords need 8+ characters with a letter and a digit.
  • Still on a pre-1.1 PostgreSQL install? The old pg-to-sqlite tool is gone; migrate through v1.4.2 first (see MIGRATION.md).
  • This is a release candidate: set your Docker tag to v1.5.0-rc1.

Full Changes: https://github.com/Doezer/Questarr/blob/main/docs/CHANGELOG.md

Download: set your Docker image tag to v1.5.0-rc1

Full Changelog: v1.4.0...v1.5.0-rc1

Don't miss a new Questarr release

NewReleases is sending notifications on new releases.