This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
ReleasePort's take
Moderate signalv0.38.4 patches per-app openresty configuration handling and scheduler-k3s image routing. Routine maintenance release with dependency bumps across the stack.
Why it matters: Test openresty overrides and scheduler routing changes in dev. Routine patch with configuration and image routing fixes; no critical issues warrant immediate action.
Summary
AI summaryFixed per-app overrides for openresty global-only properties.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Split scheduler-docker-local report into raw, computed, and global Split scheduler-docker-local report into raw, computed, and global Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
Bump golang.org/x/crypto from 0.50.0 to 0.51.0 in /plugins/common Bump golang.org/x/crypto from 0.50.0 to 0.51.0 in /plugins/common Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
Bump github.com/traefik/traefik/v2 from 2.11.45 to 2.11.46 in /plugins/scheduler-k3s Bump github.com/traefik/traefik/v2 from 2.11.45 to 2.11.46 in /plugins/scheduler-k3s Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
Bump dokku/openresty-docker-proxy from 0.10.0 to 0.11.0 in /plugins/openresty-vhosts Bump dokku/openresty-docker-proxy from 0.10.0 to 0.11.0 in /plugins/openresty-vhosts Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
Bump python from 3.14.3-alpine to 3.15.0b1-alpine in /docs/_build Bump python from 3.14.3-alpine to 3.15.0b1-alpine in /docs/_build Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Reject per-app sets for openresty global-only properties Reject per-app sets for openresty global-only properties Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Expose raw deploy-branch and keep-git-dir in git:report Expose raw deploy-branch and keep-git-dir in git:report Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Route CNB images through launcher on scheduler-k3s Route CNB images through launcher on scheduler-k3s Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Other | Medium |
Add `dokku-http-oauth` to community plugins Add `dokku-http-oauth` to community plugins Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Other | Medium |
Isolate scheduler-k3s registry tags per bats file Isolate scheduler-k3s registry tags per bats file Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Other | Medium |
Migrate from junit_files to files in EnricoMi/publish-unit-test-result-action Migrate from junit_files to files in EnricoMi/publish-unit-test-result-action Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Other | Medium |
Upgrade actions in shared build-image compose action Upgrade actions in shared build-image compose action Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Other | Medium |
Skip packer lint job on dependabot PRs Skip packer lint job on dependabot PRs Source: llm_adapter@2026-05-21 Confidence: low |
— |
Full changelog
Install/update via the bootstrap script:
wget -NP . https://dokku.com/install/v0.38.4/bootstrap.sh
sudo DOKKU_TAG=v0.38.4 bash bootstrap.sh
Bug Fixes
- #8615: @josegonzalez Reject per-app sets for openresty global-only properties
- #8613: @josegonzalez Expose raw deploy-branch and keep-git-dir in git:report
- #8549: @josegonzalez Route CNB images through launcher on scheduler-k3s
New Features
- #8614: @josegonzalez Split scheduler-docker-local report into raw, computed, and global
Documentation
- #8603: @cheif Add
dokku-http-oauthto community plugins
Tests
- #8618: @josegonzalez Isolate scheduler-k3s registry tags per bats file
- #8616: @josegonzalez Migrate from junit_files to files in EnricoMi/publish-unit-test-result-action
- #8617: @josegonzalez Upgrade actions in shared build-image compose action
- #8609: @josegonzalez Skip packer lint job on dependabot PRs
- #8604: @dependabot[bot] chore(deps): bump python from 3.14.3-bookworm to 3.15.0b1-bookworm in /tests/apps/dockerfile-release
Dependencies
- #8606: @dependabot[bot] chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 in /plugins/common
- #8608: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.45 to 2.11.46 in /plugins/scheduler-k3s
- #8607: @dependabot[bot] chore(deps): bump dokku/openresty-docker-proxy from 0.10.0 to 0.11.0 in /plugins/openresty-vhosts
- #8605: @dependabot[bot] chore(deps): bump python from 3.14.3-alpine to 3.15.0b1-alpine in /docs/_build
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About dokku
A docker-powered PaaS that helps you build and manage the lifecycle of applications
Related context
Beta — feedback welcome: [email protected]