- Issued:
- 2026-03-24
- Updated:
- 2026-03-25
RHBA-2026:5684 - Bug Fix Advisory
Synopsis
Red Hat Quay 3.17.0
Type/Severity
Bug Fix Advisory
Topic
Red Hat Quay 3.17.0 is now available with bug fixes.
Description
Quay 3.17.0
Solution
Before applying this update, make sure all previously released errata relevant
to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Quay
Fixes
- PROJQUAY-11080 - Quay 3.17 New UI: Repository state tab hidden when FEATURE_PROXY_CACHE is disabled
- PROJQUAY-11078 - quay registry can't be installed with ModuleNotFoundError: No module named 'alembic'
- PROJQUAY-11029 - Quay operator OBC listing fails in OwnNamespace mode after lib-bucket-provisioner removal
- PROJQUAY-11026 - Org mirror "Sync now" button status should dynamic update based on mirror status
- PROJQUAY-10961 - Org mirror worker does not show more detail when sync failure, making debugging difficult
- PROJQUAY-10956 - Quay 3.17 Org mirror overall State shows Success while repositories are still syncing
- PROJQUAY-10933 - Quay 3.17 Org mirror verify connection incorrectly fails for Quay user namespaces
- PROJQUAY-10932 - Update only the organization's Time Machine setting—this action cannot be saved in version 3.17.0.
- PROJQUAY-10931 - "None" option in repository permissions dropdown menu can't be selected in Create robot account pop-up window
- PROJQUAY-10924 - Logs Chart Display Issue with Short Date Ranges
- PROJQUAY-10923 - Sparse manifest list tags show no visual distinction between present and missing child manifests
- PROJQUAY-10922 - [Sparse Mirror] Architecture filter should be blocked when FEATURE_SPARSE_INDEX is disabled
- PROJQUAY-10921 - [Sparse Manifest Mirror] Architecture filter does not apply to single-architecture manifest tags
- PROJQUAY-10886 - Tags remain immutable after all immutability policies are deleted
- PROJQUAY-10885 - Immutability policy regex uses re.match() instead of re.fullmatch(), causing incorrect tag matching
- PROJQUAY-10883 - The default value "None" of "Default permissions" in "Create robot account" pop-up window is gone
- PROJQUAY-10881 - Despite the expiration being set to "never", tags are still being deleted after the original expiration time, and these deletions are not logged.
- PROJQUAY-10880 - Org mirror from quay fails to find public repos when source registry credentials are provided
- PROJQUAY-10879 - Quay 3.17 Org Mirror: Org-level mirror lacks tag filtering capability, syncing all tags unconditionally
- PROJQUAY-10878 - Quay 3.17 Org Mirror: discovery claim expires before completion for large Harbor projects, causing infinite restart loop
- PROJQUAY-10877 - Quay 3.17 Org Mirror: Harbor repository discovery truncates to first page when Link:next header is absent
- PROJQUAY-10873 - Mirror pods will be terminated and cannot be restarted after the securityContext is overwritten
- PROJQUAY-10868 - Quay 3.17 CloudFront storage backend uses deprecated Trusted Signers instead of Trusted Key Groups
- PROJQUAY-10865 - Quay 3.17 Org Mirror missing no_proxy support in discovery phase causes proxy bypass failures
- PROJQUAY-10863 - The "Remaining retries" field for organizing mirroring does not work when mirroring multiple repositories in batches
- PROJQUAY-10861 - Quay 3.17 Org Mirror should preserve image signatures(Cosign, Notary, etc.)
- PROJQUAY-10860 - Quay 3.17 Immutability Missing audit logs when tags become immutable via policy enforcement
- PROJQUAY-10859 - Quay 3.17 Poor error message quality when pushing to immutable tags
- PROJQUAY-10850 - Quay 3.17 new UI Blank success notification when attempting to delete only immutable tags
- PROJQUAY-10846 - Quay 3.17 Architecture Filter: Pushes original manifest list instead of filtered manifest list
- PROJQUAY-10840 - quay-builder-v3-17 start failed for ERROR: podman socket not found, exiting
- PROJQUAY-10837 - Quay 3.17 New UI allows setting tag expiration on org mirror repos (should be disabled)
- PROJQUAY-10836 - Quay 3.17 Metrics Missing full organization mirror sync lifecycle metrics
- PROJQUAY-10835 - Quay 3.17 Global Readonly Superuser can't read Organization Mirror configurations for auditing
- PROJQUAY-10834 - Quay 3.17 Operator default channel stuck on stable-3.16 instead of stable-3.17
- PROJQUAY-10829 - The "Retries Remaining" field of organization mirror is potentially misleading.
- PROJQUAY-10828 - Repository mirror retry feature does not work when incorrect credentials are configured
- PROJQUAY-10827 - Quay 3.17 quay.immutable=true manifest label doesn't make tags immutable - handler never called during push
- PROJQUAY-10826 - Quay 3.17 Immutability policy rollback failure leaves tags in inconsistent state
- PROJQUAY-10824 - Quay 3.17 Organization mirror and repository mirror cannot coexist safely
- PROJQUAY-10823 - Quay 3.17 new UI: Usage Logs chart: Event names truncated in legend with ellipsis
- PROJQUAY-10822 - Quay 3.17 Organization mirror UI: Need sync status filter dropdown for discovered repositories
- PROJQUAY-10820 - Quay 3.17 Organization mirror UI: Missing visual indicators for failed repositories and filter mismatches
- PROJQUAY-10819 - Quay 3.17 Organization mirror: Harbor adapter missing Link header pagination check causes incomplete repository discovery
- PROJQUAY-10798 - Cancel a organization mirror process will trigger an endless stream of log "Organization mirror sync failed - Sync cancelled:"
- PROJQUAY-10796 - Failed to mirror image manifests by Architecture-Filter to quay
- PROJQUAY-10794 - Quay 3.17 Organization Mirror: 'Sync Now' does not trigger immediate discovery of new repositories from Harbor
- PROJQUAY-10793 - Quay 3.17 Organization Mirror: Repositories not deleted when filter pattern changes (inconsistent with repo-level mirror)
- PROJQUAY-10789 - The UI's mirror POST API request did not contain the correct sync_start_date value
- PROJQUAY-10783 - Quay 3.17 Quay app POD was crashed with error "ModuleNotFoundError: No module named 'gunicorn'"
- PROJQUAY-10739 - The "Start Date" dropdown calendar in the Organization Mirror form does not work correctly in Firefox and Safari
- PROJQUAY-10738 - Organization mirror setting in Setting tab cannot be saved permanently
- PROJQUAY-10691 - Quay 3.17 Performance Issue: N+1 query in org mirror repository discovery causes 2000+ database queries for 1000 repos
- PROJQUAY-10675 - Quay 3.17 Organization mirror can't discover all image repos from Quay
- PROJQUAY-10674 - Quay 3.17 New UI: Organization mirror log events missing from chart in Usage Logs
- PROJQUAY-10673 - Quay 3.17 New UI should hide Proxy Cache, Immutability, and Auto-Prune policy when organization in Mirror State
- PROJQUAY-10656 - Quay 3.17 quay upgrade POD was crashed with error ModuleNotFoundError: No module named 'alembic'
- PROJQUAY-10609 - Image pulls fail with "cryptography.exceptions.UnsupportedAlgorithm: sha1 is not supported by this backend for RSA signing." error
- PROJQUAY-10604 - Splunk log producer: log_action failed error message loses all context due to dict.update() returning None
- PROJQUAY-10588 - [Data Model] Add OrganizationContactEmail table and migration
- PROJQUAY-10586 - Mirror Sync Start Date has timezone mismatch between config UI and audit log when using Splunk backend
- PROJQUAY-10585 - Change Service Key Expiration show "1/1/1970, 8:33:46 AM" in usages log
- PROJQUAY-10570 - Tag expiration show wrong time "1/1/1970, 8:33:46 AM" in UI logs with Splunk
- PROJQUAY-10508 - Quay 3.17 Auto-Prune Policy Fails When Immutable Tags Exist - Tag Selection Does Not Filter Immutability
- PROJQUAY-10503 - Quay new UI can't bulk remove immutability for multiple image tags
- PROJQUAY-10502 - Quay new UI should not allow to remove immutable image tags
- PROJQUAY-10500 - Quay 3.17 new UI add new label to immutable image tag hit error "Unable to complete request"
- PROJQUAY-10499 - Immutable tags can have expiration dates set via API (logical contradiction and data loss risk)
- PROJQUAY-10273 - [3.16] The Quay New UI is missing the Docker config for Robot Accounts
- PROJQUAY-10169 - [Audit] Splunk-Based Audit Log Display in Quay UI
- PROJQUAY-10168 - [Security] Container Security Hardening for Quay and Mirror Registry
- PROJQUAY-10167 - [Registry] Sparse Manifest Support for Multi-Architecture Filtering
- PROJQUAY-10157 - [Tags] Immutable Tag Support
- PROJQUAY-9750 - The "Expires" dropdown calendar of create service key and "Start Date" dropdown calendar of repository mirror do not have the hour and minute options in Firefox and Safari
- PROJQUAY-9729 - Move to UBI minimal for Quay and Quay operator
- PROJQUAY-9610 - Support ARM architecture
- PROJQUAY-9604 - Red Hat Quay downstream base Image switch to UBI minimal 9.7
- PROJQUAY-7025 - FEATURE_SUPERUSERS_FULL_ACCESS is not full access in new UI
- PROJQUAY-6934 - Quay new UI usage logs show error "Unable to complete request" when Quay LOGS_MODEL is Splunk
CVEs
(none)
References
(none)
amd64
| registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:690baea6bca66958dfa7f23487cb0d926a9aeb8174a4ba2f6ab4c7f411c68ffc |
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:c2fcf40e2b5395dbd90e666a1624562393568fbda0ec8eb51db23c9c0f27a6ba |
| registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:3da3eb532c8f1739cf2de400df1c83d109b519c5b22b333bf2c98c08d83b7250 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:cde959e4bbc7cc76e058c06fdcddc6427b955a3d39d276d5ae02125f80088558 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:9ec66dbcd0110dd7125d0b7a3321e405e259b41c6dd5845acbab98c44ea01052 |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:71bc46ebf2f1a28a6ead8f9580031a57352e7566f2dd8376a8c7a34e8121fdba |
| registry.redhat.io/quay/clair-rhel9@sha256:4737f5115321281456e5931ae4c3b9d03b1740ac3e682f84d40d65422e42d5d2 |
| registry.redhat.io/quay/quay-operator-bundle@sha256:3aba56cc0824174083549625a96467c9068421bdc988012809e7a1048f6e6919 |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:1f6d36191d1e4b64775169d3a0b0bb4070bbd44044defd9073bf421238d44a78 |
| registry.redhat.io/quay/quay-rhel9@sha256:449ed88e972abf1c9aca27f6ad36cdb5063ba2822ec2cbf07c1b148a74df1a8a |
arm64
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:2f3ba89e9906a57b0a3330ae8b369ca43f3bda36bbfbae83412d350bf3b95ae8 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:cf041c08abb0a882016ad178f47ad2e2a7ad9fd4a6de0e8588d775bd4826559e |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:9a2cb2f1c988153d869d2393fd5d5a2368b59f0c4d1e2fe7c7d31d6a9689e790 |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:4524639ad6ccf10af5f16cb3a16359447e24b5da569daa9679d78fca27b21934 |
| registry.redhat.io/quay/clair-rhel9@sha256:ab4cbb0109da3c54ceabbb794e1d9608cb849a2522399ac696e5af8cf6f5a346 |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:41fb9a161c73f8e3283ec6e9faf1bf174bbf36b49799745b353aa5ff8732dfd7 |
| registry.redhat.io/quay/quay-rhel9@sha256:ed465e7230bce952ad797882e34ef139fc762e6618b876ce30b2a83127494cdf |
ppc64le
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:25f0207b52a4219f6034d23ea00347dd8e5a22ec5728f5a89e9e21084189e851 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:35cc2fdf310e2f21c5d5a45552b115e7e95d93c9a100337bc8f4671cfd1839a6 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:ef66ccc63288b6cb34669cb581c62a2a7f5073dbad541c465a36e9597bf449c6 |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:1914d39772a8b1bd5407f629a3574178aea7116ef925bbaa04f22c5c2803e4a2 |
| registry.redhat.io/quay/clair-rhel9@sha256:a790759a12ed66cadd3ce0ddd20764bd111a4e0b0e7fde8cd50e970b9b6d7b3e |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:3da4a33524a3b2076cc512b313a32c9144757cfe0b276e47f2ce75a6460a0c04 |
| registry.redhat.io/quay/quay-rhel9@sha256:19b8ea7f1daf4e2e5109e7bcc8916361b2e423a18bc5848241626a180c06f0fe |
s390x
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:e9f396a55a21cd105460697dd8c8a6f5a405221664cfa660aa05692cf6a61548 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:5359eefc352e2b3ad78616be0046f4c903c8d377ee885b67a86073516df6de40 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:6bc2595d257312142f1532c168e53910b76c909d4c158864ed67728f4881bfdb |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:a71bed40339da41e84999609fe1afd562423fba9e64e7b3b6f3b89664fd1ec37 |
| registry.redhat.io/quay/clair-rhel9@sha256:10adbc3cc96c4fd398a90a94440b6787999fbfa5fe4aeec161abf0f6f628167e |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:be44ac620267b718c14afaf1fa290610ee3c622067d4e858875751690cc29956 |
| registry.redhat.io/quay/quay-rhel9@sha256:3118f968dbfe5ffca6ac32ab003b37191417087d17bfd2a39e4a1c2e07fe91c2 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.