Skip to content

Update ghcr.io/calibrain/shelfmark Docker tag to v1.3.15 - autoclosed - #2897

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-calibrain-shelfmark-1.x
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-calibrain-shelfmark-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/calibrain/shelfmark patch v1.3.12 → v1.3.15

Release Notes

calibrain/shelfmark (ghcr.io/calibrain/shelfmark)

v1.3.15

Compare Source

What's Changed

Full Changelog: calibrain/shelfmark@v1.3.14...v1.3.15

v1.3.14

Compare Source

What's Changed
New Contributors

Full Changelog: calibrain/shelfmark@v1.3.13...v1.3.14

v1.3.13

Compare Source

What's Changed
New Contributors

Full Changelog: calibrain/shelfmark@v1.3.12...v1.3.13


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 through 7 and 15 through 21 of the month, and on Monday (* 0-3 1-7,15-21 * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from claytono as a code owner September 7, 2026 05:17
@renovate renovate Bot added the renovate label Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

ghcr.io/calibrain/shelfmark (docker) v1.3.12 -> v1.3.15

Risk: 🔴 Risk

The Deep Dive

Update Scope

Updates the digest-pinned standard Shelfmark image in both the book and comics deployments, v1.3.12 → v1.3.15. Both Kustomizations reference these deployments without image overrides; this changes the intended runtime. OIDC, storage, resource configuration and external services remain unchanged. PR diff, books configuration, comics configuration.

Bundled SeleniumBase advances 4.52.1 → 4.53.5, Selenium 4.47.0 → 4.48.0, Gunicorn 26.1.0 → 26.2.0, websocket-client 1.9.0 → 1.9.2, filelock 3.32.4 → 3.32.5 and platformdirs 4.11.3 → 4.11.7. Python stays 3.14.7 with a refreshed base-image digest; frontend/build dependencies also change. Separate Prowlarr 2.3.5 and qBittorrent 5.2.3-lt2-1 images are unchanged, and their presence does not establish Shelfmark uses them. Upstream comparison, Prowlarr, qBittorrent.

Performance & Stability

  • Search deadline and clearer failures: Release searches gain a default 300-second server budget; the browser waits for that budget plus 45 seconds instead of aborting at 180 seconds. This activates automatically and permits longer successful cold-start searches while bounding failed solves. Queued downloads keep their separate budgets. Neither app declares RELEASE_SEARCH_TIMEOUT; persisted settings are unavailable in CI. Traefik is the default ingress and its checked values/rendered arguments set no response timeout override; no proxy incompatibility was established. Deadline changes, client alignment, Traefik configuration.
  • Rate-limited download hosts: HTTP 429 now applies a shared per-host cooldown escalating through 2, 5, 10, 15 and 30 minutes, steering retries toward other mirrors. It activates on rate limiting and can delay other downloads using the same host; local mirror use is not observable from the manifests. Backoff implementation.
  • Browser bypass reliability: Solved pages are read only after becoming available, real Anna’s Archive result pages are less likely to be misclassified as challenges, and solvers receive the original URL instead of DDoS-Guard’s ?check=1 probe. The new page-source wait defaults to 20 seconds. These fixes apply automatically when those providers run; CI cannot observe their saved enablement. Page reads, challenge detection, probe handoff.

Features & UX

  • Review and split multi-book releases: The download UI now attempts file-list inspection and presents detected packs for approval; approved books can be filed separately through the existing naming rules. AudiobookBay and supported torrent sources can supply file lists; unavailable inspection falls back to the ordinary download, with a manual multi-book toggle for uninspectable packs. Splitting requires a plan/toggle and organization enabled. This could serve the mounted Grimmory, Komga and Audiobookshelf destinations, but saved organization settings are unknown. See Hazards before enabling this workflow. Pack feature, fallback safeguards, book destinations, comic destination.
  • Personal book languages: Users can select their own default search languages, including multiple languages or all languages, while inheriting the administrator default when no override exists. The existing setting is preserved when moved to Search Mode. This is useful for the OIDC-provisioned accounts in both instances; users must choose overrides, and their saved preferences are unavailable in CI. User preferences, compatibility follow-ups, OIDC provisioning.
  • Multiple named Newznab indexers: Administrators can configure NEWZNAB_INDEXERS as named URL/API-key rows, with source labels and combined results. Activation requires configuration; the legacy single URL/key remains the fallback when the list is empty. No Newznab keys appear in either app’s manifests, but PVC settings may enable it. Newznab support, deployment environment.
  • MP4 audiobooks and unsupported-format warnings: MP4 becomes a recognized audiobook format, and Prowlarr results can warn when an explicitly declared format is not processable. Existing customized format selections still need MP4 selected; this is format recognition, not transcoding or a guarantee that the downstream player accepts every codec. The books instance mounts an Audiobookshelf destination; actual formats and Prowlarr linkage remain unknown. MP4 support, format warnings, audio mount.
  • Persistent search controls: Homepage search controls remain visible rather than depending on hover. This is an automatic UI change for both instances; an unconfirmed interaction report is noted under Newer Versions. Search controls.

Security

No introduced or resolved CVE was identified in the public Shelfmark advisory feed or GitHub advisory queries for the changed Python runtime packages. There is consequently no identified CVE/CVSS entry to score. This was advisory research, not a complete container/OS vulnerability scan; OIDC remains configured in both deployments. Dependency delta, authentication configuration.

Bundled Gunicorn HTTP/2 hardening: Gunicorn 26.2.0 fixes HTTP/2 header validation and forwarded-header trust enforcement (no CVE or CVSS supplied in its release). The image starts a GeventWebSocket worker without TLS or HTTP/2 flags, and local ingress terminates TLS; this is not an evidenced exposed HTTP/2 server path. Its new cleartext HTTP/2 support defaults off and requires explicit activation. Gunicorn release, image startup.

Key Fixes

  • More reliable author searches: Multi-author metadata is narrowed to the first author; Prowlarr searches by title and ranks candidates by author instead of filtering them out at query time. This activates when the affected searches are used; the repository contains Prowlarr but does not expose Shelfmark’s saved provider connection. Author narrowing, Prowlarr ranking, Prowlarr deployment.
  • Pending qBittorrent magnets survive: Torrents awaiting metadata are no longer treated as failed solely for temporarily having zero size; follow-up handling improves pending-name/identity behavior. This applies automatically if Shelfmark uses the unchanged qBittorrent service; the link is not declared in either app manifest. Magnet fix, follow-ups, qBittorrent pin.

Newer Versions

  • No newer published release: v1.3.15, published September 2, remains latest at evaluation. The pack correction described in Hazards is merged on main but unreleased; it is not included in this PR. Releases, pack correction.
  • Other unreleased fixes are not established regressions from this update: Main adds Anna’s Archive aa_ddg_check cookie retention to avoid repeated browser solves and keeps polling Real-Debrid torrents in queued state. The corresponding omissions existed before the proposed range, so these do not drive the label. Provider use is unknown. Cookie fix, Real-Debrid fix.
  • Open reports: A v1.3.15 user reports Anna’s Archive serving an incompatible /books/ card layout, and another reports the Search Options menu jumping on click without specifying a version. Neither establishes a new deployment regression relative to v1.3.12; these are discovery context, not verdict drivers. Archive layout report, menu report.

Hazards & Risks

  • New approved-pack path can misfile audiobook tracks: v1.3.15’s new match_plan_to_files() sends tracks missing from an approved file list into heuristic grouping. An isolated reproduction with two planned books and a truncated first book produced three output groups, splitting 140 FLAC tracks into an extra book. This path is new after v1.3.12 and the merged correction is unreleased. It requires an approved plan with unmatched chaptered tracks and organization enabled; ordinary single-book downloads without a plan do not enter it. The Audiobookshelf NFS destination makes the consequence relevant, although actual pack use is unknown. This introduced defective path drives renovate:risk; the similar older issue alone would not. New planner and transfer gates.
  • No documented mandatory migration or auth break: The reviewed range adds no database migration and preserves the legacy Newznab fallback and existing language setting. Single-replica Recreate rollout behavior and PVCs are unchanged; no consequential data conversion requiring a special recovery prerequisite was identified. Version comparison, rollout configuration.

Further Follow-up

Approved audiobook pack exposure: CI can read the manifests and exact upstream code but cannot read either instance’s /config settings or user-approved download plans. The new grouping defect is already reproduced; further investigation concerns exposure, not whether it exists. In an authorized local session, read each instance’s effective FILE_ORGANIZATION_AUDIOBOOK setting (including environment/user overrides) and establish whether users can approve chaptered-audio packs. The exact file-gathering policy is here. For a candidate fixed release, rerun the evidence file’s two-book planner probe: the 250 first-book tracks must remain together and produce exactly two groups, not three. If such plans can be used, retain renovate:risk and wait for a released version containing the correction; if a deployment-enforced restriction prevents that path, the specific blocker is removed and the remaining changes can be reassessed as routine. No such restriction appears in the checked books or comics manifests. Merely having no packs queued today does not prevent future exposure.

Sources


🔴 Verdict: Risk

Hold this update (renovate:risk): the newly introduced approved-pack processing path can split audiobook tracks incorrectly, and its fix is merged but not released. The configured Audiobookshelf destination makes that a material new workflow risk; pre-existing provider issues and routine rollout checks do not drive this label.

@renovate
renovate Bot force-pushed the renovate/ghcr.io-calibrain-shelfmark-1.x branch 25 times, most recently from 1d7fed7 to 38b0902 Compare September 8, 2026 16:40
@renovate
renovate Bot force-pushed the renovate/ghcr.io-calibrain-shelfmark-1.x branch 4 times, most recently from 521e90c to 98d36e0 Compare September 9, 2026 03:17
@renovate
renovate Bot force-pushed the renovate/ghcr.io-calibrain-shelfmark-1.x branch from 98d36e0 to a1549e5 Compare September 9, 2026 04:40
@renovate renovate Bot changed the title Update ghcr.io/calibrain/shelfmark Docker tag to v1.3.15 Update ghcr.io/calibrain/shelfmark Docker tag to v1.3.15 - autoclosed Sep 9, 2026
@renovate renovate Bot closed this Sep 9, 2026
@renovate
renovate Bot deleted the renovate/ghcr.io-calibrain-shelfmark-1.x branch September 9, 2026 04:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants