Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,10 +40,10 @@ jobs:
strategy:
matrix:
release:
- version: 10.16.4
tarball: https://github.com/owncloud/core/releases/download/v10.16.4/owncloud-complete-20260729.tar.bz2
- version: 10.16.5
tarball: https://github.com/owncloud/core/releases/download/v10.16.5/owncloud-complete-20260925.tar.bz2
base: v22.04
trivy-ignore: v22.04/10.16.4/.trivyignore
trivy-ignore: v22.04/10.16.5/.trivyignore
extra-tags: |
10.16
10
Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# Changelog

## 2026-09-25

* Changed
* Update 10.16.4 to 10.16.5 built from the GitHub release tarball

## 2026-07-30

* Changed
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ ownCloud is an open-source file sync, share and content collaboration software t

## Docker Tags and respective Dockerfile links

- [`10.16.4`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.4`
- [`10.16.5`, `10.16`, `10`, `latest`](https://github.com/owncloud-docker/server/blob/master/v22.04/Dockerfile.multiarch) available as `owncloud/server:10.16.5`
- [`11.0.0`](https://github.com/owncloud-docker/server/blob/master/v24.04/Dockerfile.multiarch) available as `owncloud/server:11.0.0`

## Default volumes
Expand Down
2 changes: 1 addition & 1 deletion agents.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ There is no local application build (no Node/pnpm/Make toolchain). The image is
built by `.github/workflows/main.yml`, which calls reusable workflows from
[`owncloud-docker/ubuntu`](https://github.com/owncloud-docker/ubuntu):

- Matrix builds two releases: `10.16.4` (base `v22.04`) and `11.0.0`
- Matrix builds two releases: `10.16.5` (base `v22.04`) and `11.0.0`
(base `v24.04`), each via `<base>/Dockerfile.multiarch`.
- The ownCloud version is injected with the `TARBALL_URL` build arg — there is no
version pinned inside the Dockerfile.
Expand Down
25 changes: 0 additions & 25 deletions v22.04/10.16.4/.trivyignore

This file was deleted.

18 changes: 18 additions & 0 deletions v22.04/10.16.5/.trivyignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# vulnerability is affecting windows only: symfony/process v3.4.47 vendored by updater
# v1.1.2 (core lib ships v5.4.51, which is already past the 5.4.46 fix). v1.1.2 is the
# newest updater release, so there is nothing to bump to.
CVE-2024-51736

# no fix exists for this line: aws-sdk-php 3.337.3 vendored by files_primary_s3 v1.6.4.
# The finding is confined to CloudFront URL/cookie signing, which the app never uses --
# it drives the S3 client. Every aws-sdk-php from 3.338.0 onward requires php >= 8.1,
# including the first patched 3.371.4, while 10.16 is a php 7.4 line.
GHSA-27qh-8cxx-2cr5

# fix requires ownCloud to update bundled guzzlehttp/guzzle (-> 7.15.2) in graphapi
# v0.3.1 (7.4.5), files_external_dropbox v2.0.2 (7.8.1) and updater v1.1.2 (7.9.2).
# Core lib is no longer affected: 10.16.5 ships 7.15.5 (owncloud/core#41784). The two
# apps do have fixed releases -- dropbox v2.1.2 and graphapi v0.3.2 -- but both are
# signed in the G2 envelope, which 10.16's integrity check rejects outright, so the
# bundle holds the older pins.
CVE-2026-69246
Loading