From 27f7071e15df1196f0830d52dfd885cbc6c6446c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= <323649642+oc-tmueller@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:11:26 +0200 Subject: [PATCH] feat(server): update 10.16.4 to 10.16.5 image from GitHub release tarball MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Point the v22.04 matrix entry at the newly published 10.16.5 release: https://github.com/owncloud/core/releases/download/v10.16.5/owncloud-complete-20260925.tar.bz2 (sha256 676e366b881141c46f858c4e05086a59ba8092640f0d641146201830e0b920bf) As before, the dated "-complete-" bundle is pinned rather than the core-only or -qa asset. Note the 20260925 date stamp is shared with the upcoming 11.0.1 bundle -- both were built the same day, as 10.16.4 and 11.0.0-rc3 shared 20260729 -- but they are distinct files and the tag in the URL disambiguates. 10.16.5 carries four security fixes over 10.16.4: #41784 bundled PHP dependencies updated to close sixteen published advisories (guzzle 7.10.0 -> 7.15.5, phpseclib, psr7, promises, dom-sanitizer, symfony/routing, symfony/polyfill-php80) #41803 appconfig public_/remote_ keys can no longer be used for path traversal #41827 SVG/MVG and script content is rejected before it reaches the ImageMagick bitmap preview path #41834 the Imagick coder is pinned per preview provider plus seven bugfixes (#41782, #41808, #41814, #41815, #41835, #41855, #41869) and one further dependency update (#41787). The versioned .trivyignore directory is renamed to match, and two of its five entries are dropped because the apps that carried them moved on in this bundle: - CVE-2026-44167 (phpseclib DoS): openidconnect went v2.3.3 -> v2.3.5, which vendors phpseclib 3.0.56, past the 3.0.54 fix. - CVE-2026-54133 (jmespath.php): files_primary_s3 went v1.6.1 -> v1.6.4, which vendors mtdowling/jmespath.php 2.9.2, the fixed version. The remaining three stay, with their notes corrected to the versions actually shipped here: symfony/process v3.4.47 still arrives through updater v1.1.2 (Windows-only, and still the newest updater release), aws-sdk-php 3.337.3 still arrives through files_primary_s3 v1.6.4 (no patched release runs on php 7.4), and guzzle is no longer a core-lib finding -- 10.16.5 ships 7.15.5 -- but is still vendored old by graphapi v0.3.1, files_external_dropbox v2.0.2 and updater v1.1.2. core's version.php at v10.16.5 reads 10.16.5, which is what the CI smoke test asserts through smoke-version-jq, and the pinned URL was confirmed to resolve. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com> --- .github/workflows/main.yml | 6 +++--- CHANGELOG.md | 5 +++++ README.md | 2 +- agents.md | 2 +- v22.04/10.16.4/.trivyignore | 25 ------------------------- v22.04/10.16.5/.trivyignore | 18 ++++++++++++++++++ 6 files changed, 28 insertions(+), 30 deletions(-) delete mode 100644 v22.04/10.16.4/.trivyignore create mode 100644 v22.04/10.16.5/.trivyignore diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index aaf07bf..7a4c7dd 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -40,10 +40,10 @@ jobs: strategy: matrix: release: - - version: 10.16.4 - tarball: https://github.com/owncloud/core/releases/download/v10.16.4/owncloud-complete-20260729.tar.bz2 + - version: 10.16.5 + tarball: https://github.com/owncloud/core/releases/download/v10.16.5/owncloud-complete-20260925.tar.bz2 base: v22.04 - trivy-ignore: v22.04/10.16.4/.trivyignore + trivy-ignore: v22.04/10.16.5/.trivyignore extra-tags: | 10.16 10 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0c05e63..15fadb8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +## 2026-09-25 + +* Changed + * Update 10.16.4 to 10.16.5 built from the GitHub release tarball + ## 2026-07-30 * Changed diff --git a/README.md b/README.md index 5456c50..8242332 100644 --- a/README.md +++ b/README.md @@ -33,7 +33,7 @@ ownCloud is an open-source file sync, share and content collaboration software t ## Docker Tags and respective Dockerfile links -- [`10.16.4`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.4` +- [`10.16.5`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.5` - [`11.0.0`](https://github.com/owncloud-docker/server/blob/master/v24.04/Dockerfile.multiarch) available as `owncloud/server:11.0.0` ## Default volumes diff --git a/agents.md b/agents.md index 6c9c006..d1ec200 100644 --- a/agents.md +++ b/agents.md @@ -39,7 +39,7 @@ There is no local application build (no Node/pnpm/Make toolchain). The image is built by `.github/workflows/main.yml`, which calls reusable workflows from [`owncloud-docker/ubuntu`](https://github.com/owncloud-docker/ubuntu): -- Matrix builds two releases: `10.16.4` (base `v22.04`) and `11.0.0` +- Matrix builds two releases: `10.16.5` (base `v22.04`) and `11.0.0` (base `v24.04`), each via `/Dockerfile.multiarch`. - The ownCloud version is injected with the `TARBALL_URL` build arg — there is no version pinned inside the Dockerfile. diff --git a/v22.04/10.16.4/.trivyignore b/v22.04/10.16.4/.trivyignore deleted file mode 100644 index 1a07b77..0000000 --- a/v22.04/10.16.4/.trivyignore +++ /dev/null @@ -1,25 +0,0 @@ -# vulnerability is affecting windows only: symfony/process v3.4.47 vendored by updater -# (core lib ships v5.4.51, which is already past the 5.4.46 fix) -CVE-2024-51736 - -# fix requires ownCloud to update bundled aws-sdk-php (3.337.3 -> 3.371.4) in files_primary_s3 -GHSA-27qh-8cxx-2cr5 - -# NOT a false positive: the 3.x branch of this advisory is fixed in phpseclib 3.0.52 and -# core lib was bumped accordingly, but apps/openidconnect vendors its own copy still at -# 3.0.50 (pulled in by jumbojett/openid-connect-php v1.0.2, requiring ^3.0.7) and the -# app's own autoloader resolves that copy. Suppressed because the impact is a DoS via -# ASN.1 OID amplification, reachable only through IdP-supplied X.509/JWKS material. -# Fix requires ownCloud to release openidconnect 2.3.4 with phpseclib 3.0.54+ (OC10-149). -CVE-2026-44167 - -# fix requires ownCloud to update bundled guzzlehttp/guzzle (-> 7.15.2) in core lib -# (7.10.0), graphapi (7.4.5), files_external_dropbox (7.8.1) and updater (7.9.2) -CVE-2026-69246 - -# not reachable in this image: mtdowling/jmespath.php 2.8.0 in files_primary_s3 is -# only vulnerable via CompilerRuntime, which Env::createRuntime() selects solely when -# JP_PHP_COMPILE is set (it is not), and the bundled aws-sdk-php passes only its own -# literal expressions -- never user input. Fix requires ownCloud to update bundled -# aws-sdk-php (3.337.3 -> 3.388.9, which carries jmespath.php 2.9.2) -CVE-2026-54133 diff --git a/v22.04/10.16.5/.trivyignore b/v22.04/10.16.5/.trivyignore new file mode 100644 index 0000000..e86d76b --- /dev/null +++ b/v22.04/10.16.5/.trivyignore @@ -0,0 +1,18 @@ +# vulnerability is affecting windows only: symfony/process v3.4.47 vendored by updater +# v1.1.2 (core lib ships v5.4.51, which is already past the 5.4.46 fix). v1.1.2 is the +# newest updater release, so there is nothing to bump to. +CVE-2024-51736 + +# no fix exists for this line: aws-sdk-php 3.337.3 vendored by files_primary_s3 v1.6.4. +# The finding is confined to CloudFront URL/cookie signing, which the app never uses -- +# it drives the S3 client. Every aws-sdk-php from 3.338.0 onward requires php >= 8.1, +# including the first patched 3.371.4, while 10.16 is a php 7.4 line. +GHSA-27qh-8cxx-2cr5 + +# fix requires ownCloud to update bundled guzzlehttp/guzzle (-> 7.15.2) in graphapi +# v0.3.1 (7.4.5), files_external_dropbox v2.0.2 (7.8.1) and updater v1.1.2 (7.9.2). +# Core lib is no longer affected: 10.16.5 ships 7.15.5 (owncloud/core#41784). The two +# apps do have fixed releases -- dropbox v2.1.2 and graphapi v0.3.2 -- but both are +# signed in the G2 envelope, which 10.16's integrity check rejects outright, so the +# bundle holds the older pins. +CVE-2026-69246