Repository navigation
Update ghcr.io/calibrain/shelfmark Docker tag to v1.4.0 - #3124
Conversation
ghcr.io/calibrain/shelfmark (docker) v1.3.15 -> v1.4.0Risk: 🔴 Risk The Deep DiveUpdate ScopeBoth Shelfmark deployments, Performance & Stability
Features & UXThese are all opt-in. Source, client, and naming settings live in the
SecurityNo GHSA or CVE advisories are published for calibrain/shelfmark (advisories), and this release introduces none. It also contains several auth hardening fixes that apply to this OIDC deployment:
Overall, the update closes security holes and opens none. Key Fixes
Newer Versionsv1.4.0 (2026-09-26) is the latest release. There are 18 commits on
No security advisory was introduced in v1.4.0 and fixed later. Hazards & RisksOIDC is always enforced, even without a local password adminv1.3.15 resolved
Other behaviour changes
Further Follow-up
Sources
🔴 Verdict: RiskThis minor release hardens security and has no known regressions. It is rated risk because the auth change (#1397) runs on this |
6dc22d0 to
facca46
Compare
facca46 to
1a8e8c2
Compare
This PR contains the following updates:
v1.3.15→v1.4.0Release Notes
calibrain/shelfmark (ghcr.io/calibrain/shelfmark)
v1.4.0Compare Source
What's Changed
cae66f2tocad9a2cby @dependabot[bot] in #1307New Contributors
Full Changelog: calibrain/shelfmark@v1.3.15...v1.4.0
Configuration
📅 Schedule: (in timezone America/New_York)
* 0-3 1-7,15-21 * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.