← Back to all sparks
Q

Quay

INFRA · APIS
Velocity5.0

Container image registry with security scanning

Project Quay is in full maintenance mode: CVE patching across two parallel enterprise release lines.

container-registrysecuritycve-patchingopenshiftmaintenance
Current state
Quay's last eight releases are entirely CVE patches, dependency bumps, and SSRF mitigations across two parallel lines — 3.10 LTS and 3.12 current. The one notable security change is a fix hiding robot account tokens from global readonly superusers, correcting a privilege boundary. No new features have shipped in this window.
Where it's heading
Both release lines receive matching security fixes in lockstep within days of each other, suggesting a small maintenance team running a triage-and-backport workflow. Quay operates as infrastructure for Red Hat OpenShift deployments where CVE response cadence and stability matter more than feature velocity. There are no signals of new capability work in this changelog window.
Prediction
Without evidence from this changelog, projecting feature direction is not possible. Further releases will follow the CVE-patch-and-backport pattern unless a new OpenShift requirement introduces a feature mandate.

Recent moves

  1. 4d ago

    Quay 3.12.22: security patches, robot token exposure fix

    Five CVEs patched plus a fix that hides robot account tokens from global readonly superusers — a privilege boundary correction that matters for organizations with tiered admin access. Standard maintenance release, no feature changes.

    View source ↗
  2. 6d ago

    Quay 3.10.26: security patches, robot token exposure fix

    The 3.10 LTS branch receives the same security fixes as 3.12.22 — CVE patches and the robot account token visibility correction — within two days. Consistent with Quay's branch-parallel maintenance cadence.

    View source ↗
  3. 1mo ago

    Quay 3.12.21: SSRF blocked in mirroring, CVEs patched

    SSRF prevention added to repository mirroring sources — blocking server-side request forgery via mirrored registry URLs. Several CVEs addressed via dependency bumps. No feature changes.

    View source ↗
  4. 1mo ago

    Quay 3.10.25: SSRF blocked in mirroring, CVEs patched

    Same SSRF mitigation and CVE patches as 3.12.21 backported to the 3.10 line. The two branches continue to receive matching fixes within the same release window.

    View source ↗
  5. 1mo ago

    Quay 3.12.20: Go 1.25 upgrade, SSRF blocked in proxy cache

    Go runtime updated to 1.25, SSRF prevention added to proxy cache upstream registry configuration, and several CVEs addressed. The Go upgrade and proxy cache SSRF fix are the most operationally significant changes in this release window.

    View source ↗
  6. 2mo ago

    Quay 3.10.24: Go 1.25 upgrade, SSRF blocked in proxy cache

    Go 1.25 and the proxy cache SSRF fix backported to the 3.10 branch. Identical scope to 3.12.20, maintaining the branch-parallel maintenance pattern that defines Quay's current release cadence.

    View source ↗