Skip to content

Releases: liquibase/docker

v5.0.3 SECURE

08 Dec 21:01

Choose a tag to compare

Support for Liquibase Secure 5.0.3.

Major Improvements

  • Enhanced Vulnerability Detection: Improved Docker image vulnerability scanning to detect all customer-reported CVEs, including vulnerabilities in nested JAR dependencies and Python packages (#462)
    • Deep dependency scanning extracts and scans nested JARs from Spring Boot fat JARs
    • Scans Python packages from GraalVM virtual filesystems
    • Parent JAR tracking shows which Liquibase JAR contains each vulnerable dependency
    • Multi-scanner approach (Trivy + Grype) eliminates detection gaps

Bug Fixes

  • Fixed secure image naming duplication issue (liquibase/liquibase-secure-secureliquibase/liquibase-secure) (#458)
  • Fixed artifact naming conflict causing 409 errors in vulnerability scanning workflow (#457)
  • Fixed Slack webhook notification failures in security scanning workflow (#457)
  • Resolved LPM automation conflict between workflows (#456)
  • Suppressed false positive CVE-2025-59250 for mssql-jdbc driver (#459)

CI/CD & Infrastructure

  • Upgraded GitHub Actions runners from macos-13 to macos-15-intel for continued support (#460)

Dependencies

  • Bumped actions/checkout from 5 to 6 (#463)

Full Changelog: v5.0.2-SECURE...v5.0.3-SECURE

v5.0.2 SECURE

19 Nov 20:08

Choose a tag to compare

Support for Liquibase Secure 5.0.2.

Major Improvements

  • OpenShift Compatibility: Container can now run with arbitrary user IDs, enabling deployment in OpenShift environments with restrictive security context constraints (#438)
  • LPM Update: Updated Liquibase Package Manager to version 0.2.16 with latest features and fixes (#453)
  • Base Image Upgrade: Migrated to Ubuntu Noble 24.04 LTS for long-term support and security updates (#442)
  • Documentation: Updated README with comprehensive Liquibase 5.0 image changes and usage examples (#450, DAT-21145)

Bug Fixes

  • Fixed LPM automation conflict between workflows preventing simultaneous updates
  • Resolved search path override regression affecting changelog directory detection (DAT-21189, #451)
  • Fixed Trivy workflow vault secret handling and AWS credentials configuration
  • Corrected Slack webhook URL export from vault in security scanning workflow

CI/CD & Infrastructure

  • Authentication Modernization: Migrated GitHub Actions workflows from liquibot to GitHub App authentication for improved security (DAT-21198, #454)
  • Release Process: Fixed duplicate Docker tag creation issue between SECURE and Community releases (DAT-20987, #446, #447)
  • Terminology Updates: Standardized naming from "OSS" to "Community" and "Pro" to "Secure" across workflows and documentation (#448)
  • Build Improvements: Updated S3 URL paths for Liquibase Secure builds and corrected RC build paths (#441, #455)

Dependencies

  • Bumped actions/upload-artifact from 4 to 5 (#449)
  • Bumped github/codeql-action from 3 to 4 (#444)
  • Bumped douglascamata/setup-docker-macos-action to latest (#443, #452)
  • Bumped peter-evans/dockerhub-description from 4 to 5 (#439)

Full Changelog: v5.0.1...v5.0.2-SECURE

v5.0.1

03 Oct 19:12

Choose a tag to compare

Support for Liquibase OSS and Secure 5.0.1

v5.0.0

30 Sep 15:58

Choose a tag to compare

Support for Liquibase OSS and Secure 5.0.0.

v4.33.0

10 Jul 14:25

Choose a tag to compare

Support for Liquibase 4.33.0.

v4.32.0

23 May 20:36

Choose a tag to compare

Support for Liquibase 4.32.0.

v4.31.0

17 Feb 21:38

Choose a tag to compare

Support for Liquibase 4.31.0.

v4.30.0

09 Nov 13:01

Choose a tag to compare

Support for Liquibase 4.30.0.

v4.29.2

16 Sep 14:04

Choose a tag to compare

Support for Liquibase 4.29.2.

v4.29.1

04 Sep 19:49

Choose a tag to compare

Support for Liquibase 4.29.1.