Skip to content

Releases: IABTechLab/uid2-optout

v4.10.15

v4.10.15 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 31 Jul 00:44
82e309e

📦 Uncategorized

  • UID2-6905: upgrade libcrypto3/libssl3 to fix CVE-2026-28390 (HIGH) - ( PR: #393 )
  • UID2-6929: CVE-2026-40200 upgrade musl/musl-utils to 1.2.5-r23 - ( PR: #394 )
  • UID2-6799 Use 'ci-auto-merge' environment - ( PR: #395 )
  • [CI Pipeline] Released Patch version: 4.9.50 - ( PR: #397 )
  • [CI Pipeline] Released Patch version: 4.9.51 - ( PR: #398 )
  • UID2-7008: Suppress CVE-2026-33845 in .trivyignore — gnutls not used by our service - ( PR: #399 )
  • suppress CVE-2026-33846: gnutls DTLS heap overflow DoS in Alpine base image - ( PR: #400 )
  • UID2-7030: Upgrade gnutls + netty (CVE-2026-3833 + 4 netty CVEs) - ( PR: #401 )
  • UID2-6764: enable SLSA provenance attestation - ( PR: #402 )
  • [CI Pipeline] Released Patch version: 4.9.64 - ( PR: #403 )
  • docs: clarify in attestation verify command (UID2-6764) - ( PR: #404 )
  • UID2-7278: upgrade Netty to 4.1.135.Final (CVE-2026-44249/45416/45674/47691) - ( PR: #405 )
  • [CI Pipeline] Released Snapshot version: 4.9.65-alpha-230-SNAPSHOT - ( PR: #407 )
  • UID2-7335: upgrade libexpat to patch CVE-2026-45186 (DoS) - ( PR: #408 )
  • sch-UID2-7270 update shared jar to allow eks pod identity - ( PR: #406 )
  • [CI Pipeline] Released Minor version: 4.10.0 - ( PR: #409 )
  • UID2-7335: bump base image to sha256:3f08b138 (retire explicit libexpat upgrade) - ( PR: #410 )
  • [CI Pipeline] Released Patch version: 4.10.3 - ( PR: #411 )
  • UID2-7364: Suppress CVE-2026-54512 / CVE-2026-54513 (jackson-databind) - ( PR: #412 )
  • UID2-7376: suppress CVE-2026-2100 (p11-kit) — not exploitable - ( PR: #413 )
  • UID2-7011: add zizmor workflow-security scan (report-only) - ( PR: #414 )
  • UID2-7426: add check_jira_key required-status-check caller - ( PR: #415 )
  • UID2-7456: Suppress CVE-2026-56131/56407/56408 (libexpat) in .trivyignore - ( PR: #416 )
  • UID2-7557: suppress jackson-core GHSA-r7wm-3cxj-wff9 (async parser, not reachable) - ( PR: #417 )
  • [Security] UID2-7569/7570/7571-7574: Upgrade jackson to 2.21.4 and Netty to 4.1.136.Final - ( PR: #418 )
  • UID2-7580: add graceful termination support to opt-out - ( PR: #419 )
  • [CI Pipeline] Released Patch version: 4.10.15 - ( PR: #422 )

Installation

docker pull ghcr.io/iabtechlab/uid2-optout:4.10.15
ghcr.io/iabtechlab/uid2-optout:latest

Image reference to deploy:

4.10.15

Changelog

  • UID2-6905: upgrade libcrypto3/libssl3 to fix CVE-2026-28390 (HIGH) - ( PR: #393 )
  • UID2-6929: CVE-2026-40200 upgrade musl/musl-utils to 1.2.5-r23 - ( PR: #394 )
  • UID2-6799 Use 'ci-auto-merge' environment - ( PR: #395 )
  • [CI Pipeline] Released Patch version: 4.9.50 - ( PR: #397 )
  • [CI Pipeline] Released Patch version: 4.9.51 - ( PR: #398 )
  • UID2-7008: Suppress CVE-2026-33845 in .trivyignore — gnutls not used by our service - ( PR: #399 )
  • suppress CVE-2026-33846: gnutls DTLS heap overflow DoS in Alpine base image - ( PR: #400 )
  • UID2-7030: Upgrade gnutls + netty (CVE-2026-3833 + 4 netty CVEs) - ( PR: #401 )
  • UID2-6764: enable SLSA provenance attestation - ( PR: #402 )
  • [CI Pipeline] Released Patch version: 4.9.64 - ( PR: #403 )
  • docs: clarify in attestation verify command (UID2-6764) - ( PR: #404 )
  • UID2-7278: upgrade Netty to 4.1.135.Final (CVE-2026-44249/45416/45674/47691) - ( PR: #405 )
  • [CI Pipeline] Released Snapshot version: 4.9.65-alpha-230-SNAPSHOT - ( PR: #407 )
  • UID2-7335: upgrade libexpat to patch CVE-2026-45186 (DoS) - ( PR: #408 )
  • sch-UID2-7270 update shared jar to allow eks pod identity - ( PR: #406 )
  • [CI Pipeline] Released Minor version: 4.10.0 - ( PR: #409 )
  • UID2-7335: bump base image to sha256:3f08b138 (retire explicit libexpat upgrade) - ( PR: #410 )
  • [CI Pipeline] Released Patch version: 4.10.3 - ( PR: #411 )
  • UID2-7364: Suppress CVE-2026-54512 / CVE-2026-54513 (jackson-databind) - ( PR: #412 )
  • UID2-7376: suppress CVE-2026-2100 (p11-kit) — not exploitable - ( PR: #413 )
  • UID2-7011: add zizmor workflow-security scan (report-only) - ( PR: #414 )
  • UID2-7426: add check_jira_key required-status-check caller - ( PR: #415 )
  • UID2-7456: Suppress CVE-2026-56131/56407/56408 (libexpat) in .trivyignore - ( PR: #416 )
  • UID2-7557: suppress jackson-core GHSA-r7wm-3cxj-wff9 (async parser, not reachable) - ( PR: #417 )
  • [Security] UID2-7569/7570/7571-7574: Upgrade jackson to 2.21.4 and Netty to 4.1.136.Final - ( PR: #418 )
  • UID2-7580: add graceful termination support to opt-out - ( PR: #419 )
  • [CI Pipeline] Released Patch version: 4.10.15 - ( PR: #422 )

v4.9.42

Choose a tag to compare

@github-actions github-actions released this 31 Mar 07:46
e2c91bc

📦 Uncategorized

  • [CI Pipeline] Released Patch version: 4.9.39
  • [CI Pipeline] Released Patch version: 4.9.42

What's Changed

  • [CI Pipeline] Released Patch version: 4.9.39 by @github-actions[bot] in #391
  • [CI Pipeline] Released Patch version: 4.9.42 by @github-actions[bot] in #392

Full Changelog: v4.9.39...v4.9.42

v4.8.0

Choose a tag to compare

@Ian-Nara Ian-Nara released this 21 Jan 21:28
37899c0

What's Changed

Full Changelog: v4.7.5...v4.8.0

v4.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Jun 01:05
876c423

📦 Uncategorized

  • Update uid2-shared version
  • [CI Pipeline] Released Minor version: 4.1.0

What's Changed

  • Update uid2-shared version by @caroline-ttd in #184
  • [CI Pipeline] Released Minor version: 4.1.0 by @github-actions in #185

Full Changelog: v4.0.0...v4.1.0

2.10.9

Choose a tag to compare

@github-actions github-actions released this 11 Aug 21:50
00daae4

What's Changed

  • [CI Pipeline] Released Snapshot version: 2.10.1-alpha-29-SNAPSHOT by @github-actions in #108
  • [CI Pipeline] Released Snapshot version: 2.10.2-alpha-30-SNAPSHOT by @github-actions in #109
  • Upgraded to Java 21 by @Ian-Nara in #107
  • [CI Pipeline] Released Patch version: 2.10.9 by @github-actions in #110

Full Changelog: v2.10.0...v2.10.9

v2.10.0

Choose a tag to compare

@sunnywu sunnywu released this 11 Jul 05:23
a5f3d9e

What's Changed

  • Remove enforce https by @thomasm-ttd in #74
  • [CI Pipeline] Released Patch version: 2.7.50-30d7874346 by @github-actions in #75
  • UID2-2864 Update failure severity to CRITICAL by @cYKatherine in #76
  • Fixed core_public_url and optout_url by @gmsdelmundo in #77
  • Updating optout url in config for Core e2e Tests by @thomasm-ttd in #78
  • [CI Pipeline] Released Snapshot version: 2.7.58-SNAPSHOT by @github-actions in #79
  • Rename workflow to shared-publish-java-to-docker-versioned by @cYKatherine in #80
  • Address HIGH vulnerabilities by @cYKatherine in #82
  • Run e2e tests on publish by @thomasm-ttd in #81
  • [CI Pipeline] Released Patch version: 2.7.62-cf45a6ec7d by @github-actions in #84
  • [CI Pipeline] Released Patch version: 2.7.64-7901912c9d by @github-actions in #85
  • Send optouts to webhooks in series instead of parallel. by @lionell-pack-ttd in #88
  • Update shared to get new file event for all workers instead of just one each time. by @lionell-pack-ttd in #89
  • [CI Pipeline] Released Minor version: 2.8.0-6b479f197d by @github-actions in #90
  • [CI Pipeline] Released Minor version: 2.9.0-685b9893b7 by @github-actions in #91
  • Update automatic PR scan to HIGH level by @cYKatherine in #96
  • Revert "Update automatic PR scan to HIGH level" by @cYKatherine in #97
  • UID2-3042 scan vulnerability on pr by @cYKatherine in #98
  • Address CVE-2023-52425 vulnerability by @alex-yau-ttd in #95
  • Optout delta sending fixes by @mcollins-ttd in #100
  • [CI Pipeline] Released Patch version: 2.9.12-f5c0715ae6 by @github-actions in #101
  • Fix vulnerabilities by @cYKatherine in #102
  • Removed extra validation steps by @thomasm-ttd in #103
  • Removed pre-commit and trivy-secret.yaml by @gmsdelmundo in #104
  • Do not lowercase webhook URL as the path can be case sensitive by @sunnywu in #105
  • [CI Pipeline] Released Minor version: 2.10.0 by @github-actions in #106

New Contributors

Full Changelog: v2.7.44-5bb2a9e23c...v2.10.0

v2.7.44-5bb2a9e23c

Choose a tag to compare

@thomasm-ttd thomasm-ttd released this 22 Jan 04:12
2abb5ea

What's Changed

Pipeline changes:

New Contributors

Full Changelog: v2.7.27-6d64b104e2...v2.7.44-5bb2a9e23c