This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+9 more
Affected surfaces
Summary
AI summaryFixed AWS credentials handling for IMGPROXY_S3_ASSUME_ROLE_ARN and resolved a rare deadlock in ML model inference.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fixes a rare deadlock during ML model inference. Fixes a rare deadlock during ML model inference. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes AWS credentials lifetime issue when IMGPROXY_S3_ASSUME_ROLE_ARN is used. Fixes AWS credentials lifetime issue when IMGPROXY_S3_ASSUME_ROLE_ARN is used. Source: llm_adapter@2026-06-09 Confidence: low |
— |
Full changelog
Fixed
- Fix AWS credentials lifetime when
IMGPROXY_S3_ASSUME_ROLE_ARNconfig is used. - (pro) Fix a rare deadlock during ML model inference.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About imgproxy
Fast and secure standalone server for resizing and converting remote images.
Related context
Related tools
Earlier breaking changes
- v4.0.0 Removed deprecated OpenTelemetry configuration options (endpoint, protocol, GRPC_INSECURE, propagators, connection timeout); use corresponding OTEL_* variables
- v4.0.0 Docker images now built on Ubuntu 22.04; minimum libc version required is 2.35
- v4.0.0 Minimum libc version requirement changed to 2.35
- v4.0.0 Custom New Relic metrics renamed from imgproxy.X to Custom/imgproxy/X
- v4.0.0 Log format and naming changed to match documentation
Beta — feedback welcome: [email protected]