Quay
Container image registry with security scanning
Quay ships nothing but CVE remediation, mirrored across two supported branches
◆Recent moves
- 7d ago
v3.12.21 patches six advisories and blocks SSRF in mirroring
Dependency bumps against tracked advisories plus a fix preventing SSRF through repository mirroring sources. It is the 3.12 half of a coordinated pair cut alongside v3.10.25 the same day.
View source ↗ - 7d ago
v3.10.25 carries the same advisory fixes to the 3.10 branch
The 3.10 twin of v3.12.21, carrying the identical dependency remediation and mirroring SSRF fix backported to the older supported branch. One body of work, two tags.
View source ↗ - 27d ago
v3.12.20 bumps Go and blocks SSRF in proxy cache config
Toolchain and dependency maintenance plus the proxy-cache half of the SSRF sweep that the August releases later extended to mirroring. Paired with v3.10.24 on the older branch.
View source ↗ - 1mo ago
v3.10.24 backports the Go bump and proxy cache SSRF fix
The 3.10 counterpart to v3.12.20, with the same Go version bump, dependency updates and proxy cache SSRF fix. No branch-specific content.
View source ↗ - 1mo ago
v3.10.23 clears PyJWT, urllib3 and shell-quote advisories
A dependency-only security release on the 3.10 branch covering four tracked advisories. It pairs with v3.12.19, which shipped the same fixes days earlier.
View source ↗ - 1mo ago
v3.12.19 clears the same four dependency advisories
The 3.12 half of the late-June remediation pair, identical in substance to v3.10.23. It establishes the twinned-release pattern that holds across the whole window.
View source ↗