This release includes 1 security fix for security teams reviewing exposed deployments.
Published 4d
Deployment Automation
✓ No known CVEs patched
This release patches 1 known CVE
Topics
buildpack
containers
devops
docker
dokku
heroku
+4 more
kubernetes
nomad
paas
self-hosted
Affected surfaces
rce_ssrf
Summary
AI summaryPrevent command injection via Docker option evaluation and add per‑app Let's Encrypt email support on k3s.
Full changelog
Install/update via the bootstrap script:
wget -NP . https://dokku.com/install/v0.38.25/bootstrap.sh
sudo DOKKU_TAG=v0.38.25 bash bootstrap.sh
Security
- #8848: @josegonzalez Prevent command injection via docker options eval
New Features
- #8849: @josegonzalez Support per-app letsencrypt emails on k3s
Security Fixes
- #8848 — Prevent command injection via Docker options eval (CVE not listed)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About dokku
A docker-powered PaaS that helps you build and manage the lifecycle of applications
Beta — feedback welcome: [email protected]