Releases: liquibase/docker
Releases · liquibase/docker
v5.0.3 SECURE
Support for Liquibase Secure 5.0.3.
Major Improvements
- Enhanced Vulnerability Detection: Improved Docker image vulnerability scanning to detect all customer-reported CVEs, including vulnerabilities in nested JAR dependencies and Python packages (#462)
- Deep dependency scanning extracts and scans nested JARs from Spring Boot fat JARs
- Scans Python packages from GraalVM virtual filesystems
- Parent JAR tracking shows which Liquibase JAR contains each vulnerable dependency
- Multi-scanner approach (Trivy + Grype) eliminates detection gaps
Bug Fixes
- Fixed secure image naming duplication issue (
liquibase/liquibase-secure-secure→liquibase/liquibase-secure) (#458) - Fixed artifact naming conflict causing 409 errors in vulnerability scanning workflow (#457)
- Fixed Slack webhook notification failures in security scanning workflow (#457)
- Resolved LPM automation conflict between workflows (#456)
- Suppressed false positive CVE-2025-59250 for mssql-jdbc driver (#459)
CI/CD & Infrastructure
- Upgraded GitHub Actions runners from macos-13 to macos-15-intel for continued support (#460)
Dependencies
- Bumped
actions/checkoutfrom 5 to 6 (#463)
Full Changelog: v5.0.2-SECURE...v5.0.3-SECURE
v5.0.2 SECURE
Support for Liquibase Secure 5.0.2.
Major Improvements
- OpenShift Compatibility: Container can now run with arbitrary user IDs, enabling deployment in OpenShift environments with restrictive security context constraints (#438)
- LPM Update: Updated Liquibase Package Manager to version 0.2.16 with latest features and fixes (#453)
- Base Image Upgrade: Migrated to Ubuntu Noble 24.04 LTS for long-term support and security updates (#442)
- Documentation: Updated README with comprehensive Liquibase 5.0 image changes and usage examples (#450, DAT-21145)
Bug Fixes
- Fixed LPM automation conflict between workflows preventing simultaneous updates
- Resolved search path override regression affecting changelog directory detection (DAT-21189, #451)
- Fixed Trivy workflow vault secret handling and AWS credentials configuration
- Corrected Slack webhook URL export from vault in security scanning workflow
CI/CD & Infrastructure
- Authentication Modernization: Migrated GitHub Actions workflows from liquibot to GitHub App authentication for improved security (DAT-21198, #454)
- Release Process: Fixed duplicate Docker tag creation issue between SECURE and Community releases (DAT-20987, #446, #447)
- Terminology Updates: Standardized naming from "OSS" to "Community" and "Pro" to "Secure" across workflows and documentation (#448)
- Build Improvements: Updated S3 URL paths for Liquibase Secure builds and corrected RC build paths (#441, #455)
Dependencies
- Bumped
actions/upload-artifactfrom 4 to 5 (#449) - Bumped
github/codeql-actionfrom 3 to 4 (#444) - Bumped
douglascamata/setup-docker-macos-actionto latest (#443, #452) - Bumped
peter-evans/dockerhub-descriptionfrom 4 to 5 (#439)
Full Changelog: v5.0.1...v5.0.2-SECURE
v5.0.1
Support for Liquibase OSS and Secure 5.0.1
v5.0.0
Support for Liquibase OSS and Secure 5.0.0.
v4.33.0
Support for Liquibase 4.33.0.
v4.32.0
Support for Liquibase 4.32.0.
v4.31.0
Support for Liquibase 4.31.0.
v4.30.0
Support for Liquibase 4.30.0.
v4.29.2
Support for Liquibase 4.29.2.
v4.29.1
Support for Liquibase 4.29.1.