Quay.io
Backend & InfraBuild, Store, and Distribute your Applications and Containers
Release History
View all versions →v3.17.433 fixes3 featuresThis release addresses several CVEs by updating dependencies like PyJWT, urllib3, and FastUri. It also includes improvements to testing infrastructure, bug fixes for build triggers and permissions, and the removal of Cypress.
v3.12.215 fixesThis release addresses several CVEs by upgrading dependencies like pyasn1 and pillow, and overriding others like brace-expansion and js-yaml. It also includes a fix to prevent SSRF in repository sources.
v3.10.255 fixesThis release addresses several CVEs by upgrading dependencies like pyasn1 and pillow, and patching vulnerabilities in decode-uri-component, brace-expansion, and js-yaml. It also includes a fix to prevent SSRF in repository sources.
v3.9.251 fixThis release addresses security vulnerabilities by upgrading dependencies including pyasn1, pillow, brace-expansion, and js-yaml. It also includes a fix to prevent SSRF in repository sources during mirroring.
v3.15.73 fixes2 featuresThis release includes security fixes for CVE-2026-45822 and CVE-2026-59885, dependency upgrades for pyasn1 and pillow, and new features for security scanning with retry limiting.
v3.18.023 fixes5 featuresThis release includes several bug fixes, dependency updates, and new features such as enhanced action logs and manifest track visualization. It also introduces a new `quay serve` command for a minimal OCI Go-based container registry.
v3.12.202 fixesThis release includes dependency updates and security fixes, addressing a CVE in form-data handling and preventing SSRF vulnerabilities in proxy configurations.
v3.15.67 fixesThis release addresses several CVEs by updating various dependencies including PyJWT, shell-quote, urllib3, kafka-python, and form-data. It also includes improvements to the proxy cache and Clair rescans.
v3.16.511 fixesThis release addresses several CVEs by updating various dependencies including PyJWT, urllib3, shell-quote, kafka-python, FastUri, form-data, and decode-uri-component. It also includes improvements to CI processes and proxy cache functionality.
v3.10.242 fixesThis release updates the Go version to 1.25.0 and includes security fixes for CVE-2026-12143 and SSRF vulnerabilities. It also bumps several dependencies.
v3.9.244 fixesThis release addresses several CVEs, including vulnerabilities related to form-data, FastUri, and decode-uri-component. It also includes a fix to prevent SSRF in proxy cache configurations and updates dependencies.
v3.10.234 fixesThis release primarily focuses on security updates by patching several CVEs across various dependencies, including PyJWT, urllib3, shell-quote, and kafka-python. It also includes minor dependency bumps and CI updates.
v3.12.194 fixesThis patch release (v3.12.19) focuses primarily on addressing several reported CVEs by updating underlying dependencies like PyJWT, urllib3, shell-quote, and kafka-python.
v3.9.235 fixesQuay version v3.9.23 primarily focuses on patching several critical CVEs across various dependencies and updating the CI configuration for commit checks.
v3.15.52 fixesThis release focuses primarily on dependency updates, security fixes including addressing an RCE vulnerability, and resolving a configuration issue in the config-tool.
v3.17.32 fixesThis release, v3.17.3, focuses on stability by fixing race conditions and removing hardcoded CDN references. It also ensures proper IP forwarding when nginx is bound to port 8080.
v3.9.221 fixThis release focuses on dependency updates, including security patches for node-forge and cryptography, and fixes a critical RCE vulnerability related to pickle deserialization.
v3.10.221 fixThis release primarily focuses on dependency updates across various components, including security patches for node forge and cryptography, and resolves a critical RCE vulnerability related to pickle deserialization.
v3.12.181 fixThis release primarily focuses on security fixes by bumping several dependencies, including addressing an RCE vulnerability related to unsafe pickle deserialization. Several minor dependency updates were also applied across the board.
v3.17.222 fixesThis release for the redhat-3.17 branch primarily focuses on security fixes (including two CVEs), numerous bug fixes across web UI and mirroring functionality, and significant dependency updates. It also includes extensive migration of UI and API tests from Cypress to Playwright.
v3.14.85 fixesThis release primarily focuses on dependency updates for security and stability, including bumping pgx, pyOpenSSL, node forge, and cryptography, alongside fixing several security vulnerabilities.
v3.16.49 fixes2 featuresThis release focuses heavily on dependency updates, security fixes (including CVEs), and minor web UI improvements, specifically targeting the redhat-3.16 branch.
v3.9.212 fixesThis release updates several dependencies, including pgx to v5 and pyOpenSSL to 26.0.0, and addresses a security vulnerability (CVE-2026-29074).
v3.10.212 fixesThis patch release for Quay 3.10 updates several dependencies, including pgx to v5 and pyOpenSSL to 26.0.0, and addresses a security vulnerability (CVE-2026-29074).
v3.12.172 fixesThis patch release (v3.12.17) primarily updates dependencies, including pgx to v5 and pyOpenSSL to 26.0.0, and addresses a security vulnerability (CVE-2026-29074).
Common Errors
Related Backend & Infra Packages
Production-Grade Container Scheduling and Management
Node.js JavaScript runtime ✨🐢🚀✨
Promise based HTTP client for the browser and node.js
A modern runtime for JavaScript and TypeScript.
Deliver web apps with confidence 🚀
Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one
Subscribe to Updates
Get notified when new versions are released