Quay
Container image registry with security scanning
Project Quay is in full maintenance mode: CVE patching across two parallel enterprise release lines.
◆Recent moves
- 4d ago
Quay 3.12.22: security patches, robot token exposure fix
Five CVEs patched plus a fix that hides robot account tokens from global readonly superusers — a privilege boundary correction that matters for organizations with tiered admin access. Standard maintenance release, no feature changes.
View source ↗ - 6d ago
Quay 3.10.26: security patches, robot token exposure fix
The 3.10 LTS branch receives the same security fixes as 3.12.22 — CVE patches and the robot account token visibility correction — within two days. Consistent with Quay's branch-parallel maintenance cadence.
View source ↗ - 1mo ago
Quay 3.12.21: SSRF blocked in mirroring, CVEs patched
SSRF prevention added to repository mirroring sources — blocking server-side request forgery via mirrored registry URLs. Several CVEs addressed via dependency bumps. No feature changes.
View source ↗ - 1mo ago
Quay 3.10.25: SSRF blocked in mirroring, CVEs patched
Same SSRF mitigation and CVE patches as 3.12.21 backported to the 3.10 line. The two branches continue to receive matching fixes within the same release window.
View source ↗ - 1mo ago
Quay 3.12.20: Go 1.25 upgrade, SSRF blocked in proxy cache
Go runtime updated to 1.25, SSRF prevention added to proxy cache upstream registry configuration, and several CVEs addressed. The Go upgrade and proxy cache SSRF fix are the most operationally significant changes in this release window.
View source ↗ - 2mo ago
Quay 3.10.24: Go 1.25 upgrade, SSRF blocked in proxy cache
Go 1.25 and the proxy cache SSRF fix backported to the 3.10 branch. Identical scope to 3.12.20, maintaining the branch-parallel maintenance pattern that defines Quay's current release cadence.
View source ↗