Repository navigation
Update ghcr.io/calibrain/shelfmark Docker tag to v1.3.15 - autoclosed - #2897
renovate[bot] wants to merge 1 commit into
Conversation
ghcr.io/calibrain/shelfmark (docker) v1.3.12 -> v1.3.15Risk: 🔴 Risk The Deep DiveUpdate ScopeUpdates the digest-pinned standard Shelfmark image in both the book and comics deployments, v1.3.12 → v1.3.15. Both Kustomizations reference these deployments without image overrides; this changes the intended runtime. OIDC, storage, resource configuration and external services remain unchanged. PR diff, books configuration, comics configuration. Bundled SeleniumBase advances 4.52.1 → 4.53.5, Selenium 4.47.0 → 4.48.0, Gunicorn 26.1.0 → 26.2.0, websocket-client 1.9.0 → 1.9.2, filelock 3.32.4 → 3.32.5 and platformdirs 4.11.3 → 4.11.7. Python stays 3.14.7 with a refreshed base-image digest; frontend/build dependencies also change. Separate Prowlarr 2.3.5 and qBittorrent 5.2.3-lt2-1 images are unchanged, and their presence does not establish Shelfmark uses them. Upstream comparison, Prowlarr, qBittorrent. Performance & Stability
Features & UX
SecurityNo introduced or resolved CVE was identified in the public Shelfmark advisory feed or GitHub advisory queries for the changed Python runtime packages. There is consequently no identified CVE/CVSS entry to score. This was advisory research, not a complete container/OS vulnerability scan; OIDC remains configured in both deployments. Dependency delta, authentication configuration. Bundled Gunicorn HTTP/2 hardening: Gunicorn 26.2.0 fixes HTTP/2 header validation and forwarded-header trust enforcement (no CVE or CVSS supplied in its release). The image starts a GeventWebSocket worker without TLS or HTTP/2 flags, and local ingress terminates TLS; this is not an evidenced exposed HTTP/2 server path. Its new cleartext HTTP/2 support defaults off and requires explicit activation. Gunicorn release, image startup. Key Fixes
Newer Versions
Hazards & Risks
Further Follow-upApproved audiobook pack exposure: CI can read the manifests and exact upstream code but cannot read either instance’s Sources
🔴 Verdict: RiskHold this update ( |
1d7fed7 to
38b0902
Compare
521e90c to
98d36e0
Compare
98d36e0 to
a1549e5
Compare
This PR contains the following updates:
v1.3.12→v1.3.15Release Notes
calibrain/shelfmark (ghcr.io/calibrain/shelfmark)
v1.3.15Compare Source
What's Changed
Full Changelog: calibrain/shelfmark@v1.3.14...v1.3.15
v1.3.14Compare Source
What's Changed
ce40764tocae66f2by @dependabot[bot] in #1278New Contributors
Full Changelog: calibrain/shelfmark@v1.3.13...v1.3.14
v1.3.13Compare Source
What's Changed
New Contributors
Full Changelog: calibrain/shelfmark@v1.3.12...v1.3.13
Configuration
📅 Schedule: (in timezone America/New_York)
* 0-3 1-7,15-21 * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.