Skip to content

Update ghcr.io/onedr0p/jellyfin Docker tag to v10.8.10

Renovate [bot] requested to merge renovate/ghcr.io-onedr0p-jellyfin-10.x into master

This MR contains the following updates:

Package Update Change
ghcr.io/onedr0p/jellyfin patch 10.8.9 -> 10.8.10

Release Notes

jellyfin/jellyfin

v10.8.10: 10.8.10

Compare Source

Jellyfin 10.8.10

Stable hotfix release for 10.8.z release branch.

New Features and Major Improvements

  • CRITICAL SECURITY ADVISORY: GHSA-9p5f-5x8v-x65m and GHSA-89hp-h43h-r5pq can be combined to allow remote code execution for any authenticated Jellyfin user including non-admin users. While the particular execution mechanism of the former dates to the 10.8.0 release, the latter was present for all Jellyfin releases before this point. It is thus absolutely critical for all Jellyfin administrators, regardless of version, to upgrade to this version if they allow any untrusted users and/or expose their instance to the Internet.

Release Notes

N/A

Changelog

GitHub Project: https://github.com/orgs/jellyfin/projects/29

jellyfin [12]

Note: Dependabot automatic MRs are excluded from this list.

jellyfin-web [11]

Note: Dependabot automatic MRs are excluded from this list.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this MR and you won't be reminded about this update again.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Merge request reports

Loading