diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index aaf07bf..7a4c7dd 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -40,10 +40,10 @@ jobs: strategy: matrix: release: - - version: 10.16.4 - tarball: https://github.com/owncloud/core/releases/download/v10.16.4/owncloud-complete-20260729.tar.bz2 + - version: 10.16.5 + tarball: https://github.com/owncloud/core/releases/download/v10.16.5/owncloud-complete-20260925.tar.bz2 base: v22.04 - trivy-ignore: v22.04/10.16.4/.trivyignore + trivy-ignore: v22.04/10.16.5/.trivyignore extra-tags: | 10.16 10 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0c05e63..15fadb8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +## 2026-09-25 + +* Changed + * Update 10.16.4 to 10.16.5 built from the GitHub release tarball + ## 2026-07-30 * Changed diff --git a/README.md b/README.md index 5456c50..8242332 100644 --- a/README.md +++ b/README.md @@ -33,7 +33,7 @@ ownCloud is an open-source file sync, share and content collaboration software t ## Docker Tags and respective Dockerfile links -- [`10.16.4`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.4` +- [`10.16.5`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.5` - [`11.0.0`](https://github.com/owncloud-docker/server/blob/master/v24.04/Dockerfile.multiarch) available as `owncloud/server:11.0.0` ## Default volumes diff --git a/agents.md b/agents.md index 6c9c006..d1ec200 100644 --- a/agents.md +++ b/agents.md @@ -39,7 +39,7 @@ There is no local application build (no Node/pnpm/Make toolchain). The image is built by `.github/workflows/main.yml`, which calls reusable workflows from [`owncloud-docker/ubuntu`](https://github.com/owncloud-docker/ubuntu): -- Matrix builds two releases: `10.16.4` (base `v22.04`) and `11.0.0` +- Matrix builds two releases: `10.16.5` (base `v22.04`) and `11.0.0` (base `v24.04`), each via `/Dockerfile.multiarch`. - The ownCloud version is injected with the `TARBALL_URL` build arg — there is no version pinned inside the Dockerfile. diff --git a/v22.04/10.16.4/.trivyignore b/v22.04/10.16.4/.trivyignore deleted file mode 100644 index 1a07b77..0000000 --- a/v22.04/10.16.4/.trivyignore +++ /dev/null @@ -1,25 +0,0 @@ -# vulnerability is affecting windows only: symfony/process v3.4.47 vendored by updater -# (core lib ships v5.4.51, which is already past the 5.4.46 fix) -CVE-2024-51736 - -# fix requires ownCloud to update bundled aws-sdk-php (3.337.3 -> 3.371.4) in files_primary_s3 -GHSA-27qh-8cxx-2cr5 - -# NOT a false positive: the 3.x branch of this advisory is fixed in phpseclib 3.0.52 and -# core lib was bumped accordingly, but apps/openidconnect vendors its own copy still at -# 3.0.50 (pulled in by jumbojett/openid-connect-php v1.0.2, requiring ^3.0.7) and the -# app's own autoloader resolves that copy. Suppressed because the impact is a DoS via -# ASN.1 OID amplification, reachable only through IdP-supplied X.509/JWKS material. -# Fix requires ownCloud to release openidconnect 2.3.4 with phpseclib 3.0.54+ (OC10-149). -CVE-2026-44167 - -# fix requires ownCloud to update bundled guzzlehttp/guzzle (-> 7.15.2) in core lib -# (7.10.0), graphapi (7.4.5), files_external_dropbox (7.8.1) and updater (7.9.2) -CVE-2026-69246 - -# not reachable in this image: mtdowling/jmespath.php 2.8.0 in files_primary_s3 is -# only vulnerable via CompilerRuntime, which Env::createRuntime() selects solely when -# JP_PHP_COMPILE is set (it is not), and the bundled aws-sdk-php passes only its own -# literal expressions -- never user input. Fix requires ownCloud to update bundled -# aws-sdk-php (3.337.3 -> 3.388.9, which carries jmespath.php 2.9.2) -CVE-2026-54133 diff --git a/v22.04/10.16.5/.trivyignore b/v22.04/10.16.5/.trivyignore new file mode 100644 index 0000000..e86d76b --- /dev/null +++ b/v22.04/10.16.5/.trivyignore @@ -0,0 +1,18 @@ +# vulnerability is affecting windows only: symfony/process v3.4.47 vendored by updater +# v1.1.2 (core lib ships v5.4.51, which is already past the 5.4.46 fix). v1.1.2 is the +# newest updater release, so there is nothing to bump to. +CVE-2024-51736 + +# no fix exists for this line: aws-sdk-php 3.337.3 vendored by files_primary_s3 v1.6.4. +# The finding is confined to CloudFront URL/cookie signing, which the app never uses -- +# it drives the S3 client. Every aws-sdk-php from 3.338.0 onward requires php >= 8.1, +# including the first patched 3.371.4, while 10.16 is a php 7.4 line. +GHSA-27qh-8cxx-2cr5 + +# fix requires ownCloud to update bundled guzzlehttp/guzzle (-> 7.15.2) in graphapi +# v0.3.1 (7.4.5), files_external_dropbox v2.0.2 (7.8.1) and updater v1.1.2 (7.9.2). +# Core lib is no longer affected: 10.16.5 ships 7.15.5 (owncloud/core#41784). The two +# apps do have fixed releases -- dropbox v2.1.2 and graphapi v0.3.2 -- but both are +# signed in the G2 envelope, which 10.16's integrity check rejects outright, so the +# bundle holds the older pins. +CVE-2026-69246