Update docker.io/gotenberg/gotenberg Docker tag to v8.37.0

Share
Update docker.io/gotenberg/gotenberg Docker tag to v8.37.0
Photo by Asep Rendi / Unsplash

No problems upgrading the Docker container with a Docker compose yaml file within Portainer and by means of Portainer DevOps resp. GitOps with dependency update facilitated by Mend's Renovate Bot.

This MR contains the following updates:

Package Update Change
docker.io/gotenberg/gotenberg minor 8.36.0 → 8.37.0

Release Notes

gotenberg/gotenberg (docker.io/gotenberg/gotenberg)

v8.37.0: 8.37.0

Compare Source

Security Fixes ⚠️

  • Strip URL userinfo before allow-list and deny-list matching. The regexes saw the credentials, so http://trusted.example.com@10.0.0.1/ satisfied an allow-list anchored on trusted\.example\.com and skipped the IP checks, and http://a@127.0.0.1/ slipped past a deny-list anchored on 127\..
  • Treat CGNAT and benchmarking ranges as non-public. 100.64.0.0/10, where Alibaba Cloud serves instance metadata, and 198.18.0.0/15 passed the *_DENY_PRIVATE_IPS checks.
  • Reject metadata keys that collide with ExifTool options. An unprefixed key such as csv or o reached ExifTool as a command-line option, not a tag. Such keys now return 400; prefix them with a group, for example XMP:csv.
  • Validate qpdf split spans. qpdf read a span that is not a page range as another source file and appended its pages to the output. It now rejects such spans and the engine chain moves on.
  • Keep redirect verdicts generic. A downloadFrom redirect blocked by the outbound policy answered 400 with the allow-list, deny-list, or IP policy in the message. It now gets the same generic 403 as a blocked first hop.
  • Bound what a hostile page or origin can hold. Chromium's CONNECT tunnels close after 2 minutes of silence and cap at 512 in flight. downloadFrom fetches honor the request deadline, webhook deliveries get their own budget, retries included, and a remote Retry-After can no longer exceed the configured maximum wait.

New Features

  • Process a request's PDF files concurrently. --pdfengines-max-concurrency bounds how many files the per-file features (metadata, encryption, stamps, watermarks, flattening, and more) process at once, across all requests. The default 1 keeps the sequential behavior; raise it to trade memory for speed on multi-file requests. LibreOffice is not affected: scale containers instead.
  • downloadFrom limits. --api-download-from-max-concurrency bounds the fetches in flight per request, 10 by default (previously unbounded). --api-download-from-max-entries caps the array size, 0 (no limit) by default.
  • Startup warnings for risky configurations. Gotenberg now warns about allow-list patterns that match more than intended (unanchored, catch-all, or with an unterminated host), since a match skips the IP checks, and about --api-enable-debug-route without authentication. Nothing fails to start.

Bug Fixes

  • Health check failed during planned restarts (#​1648). A probe between two conversions got 503 while --chromium-restart-after or --libreoffice-restart-after recycled the process. Planned restarts now report healthy; unplanned ones still don't. Thanks @​adq-talbot.
  • DOCX math formulas were silently dropped (#​1644). The 8.30.0 image slimming removed libreoffice-math; it's back (#​1645). Thanks @​joh-klein.
  • Chromium crashes hung until the request timeout (#​1640). A renderer crash now fails fast with 503 (#​1641). Thanks @​cqjjjzr and @​Haseeb-1698.
  • About 75 MB extra per Chromium browser (#​1656). Recent Chromium builds preload the WebUI omnibox popup at start, headless included. Gotenberg now disables it. Thanks @​carma-codebase.
  • Telemetry exported without an exporter configured (#​1643). An unset OTEL_*_EXPORTER fell back to OTLP on localhost and kept retrying. Each signal now stays off until its variable is set, as documented. Thanks @​SuperSandro2000.
  • Encrypted .xlsb returned 500 (#​1655). It now returns 400 pointing at the password form field. Thanks @​MaxFreedomPollard.
  • Uploads sharing a filename lost all but one file. Duplicates are now kept as name (2).ext, in upload order. Very long extensions and a best-effort symlink step no longer fail the request with 500.
  • Async conversions could pick up another request's Gotenberg-Output-Filename. The header is now read before Echo recycles the request context.
  • Resource leaks. Webhook callbacks answering 4xx leaked a connection, a failed LibreOffice start leaked its outbound proxy, and Chromium's per-conversion network map kept every settled request.

Chore

  • Updated Chromium to 152.0.7977.82.
  • Updated LibreOffice to 26.8.0.
  • Updated unoconverter to v0.5.0, which drops the distutils dependency.
  • Bumped Go to 1.27.1.
  • Bumped golangci-lint to v2.13.2.
  • Minor performance improvements in outbound filtering, access logging, and Chromium event handling.
  • Updated Go dependencies.

Read more

Me on Mastodon - This link is here for verification purposes.