What bunkerity/bunkerweb shipped
Written by FoxPlug from public releases; not affiliated with Bunkerweb. An automatic summary of the public release, pull request and commit data of github.com/bunkerity/bunkerweb. Bunkerweb did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- v1.6.16-rc2 released with Docker images available on Docker Hub and GHCR. Release
- Fixed BROTLI_MIN_LENGTH regex validation to properly anchor and reject trailing input that could inject NGINX configuration. Pull request #3959
- v1.6.16-rc1 released with documentation and Docker images available. Release
- v1.6.15 stable release published with full documentation and container images. Release
Why it matters
Two release candidates for v1.6.16 are available for testing, including a critical fix for BROTLI_MIN_LENGTH validation that prevents configuration injection. The stable v1.6.15 release is now available for production deployments.
Changelog entry
- Fixed BROTLI_MIN_LENGTH regex pattern to anchor to end of string, preventing trailing input from being injected into NGINX configuration Pull request #3959
v1.6.16-rc2 is out with a fix for BROTLI_MIN_LENGTH regex validation. Test it now and report issues. v1.6.15 stable also available.
This week Bunkerweb released v1.6.16-rc2 and v1.6.15 stable. A security-relevant fix in v1.6.16-rc2 addresses BROTLI_MIN_LENGTH validation to prevent configuration injection. Both release candidates and stable versions are available on Docker Hub and GHCR for testing and production deployment.
Week of September 14, 2026
What shipped
- Release candidate v1.6.15-rc3 is available for testing across all-in-one and individual scheduler images. Release
- ModSecurity validation no longer requires concurrent storage directory configuration on inactive scopes. Pull request #3907
- Tar extraction is now compatible with older Python versions. Pull request #3922
- Kapsule Kubernetes tests now use CoreDNS resolver for improved test reliability. Pull request #3921
- Ansible target interpreter is pinned in CI pipeline. Pull request #3940
- Passbolt tests temporarily disabled pending further investigation. Pull request #3929
Why it matters
v1.6.15-rc3 is ready for testing with fixes addressing ModSecurity configuration validation, Python compatibility, and Kubernetes test infrastructure. These changes improve configuration flexibility and test reliability for users deploying across different environments.
Changelog entry
- Release v1.6.15-rc3 Release
- Fix ModSecurity: don't require concurrent storage directory on inactive scopes Pull request #3907
- Fix: make safe tar extraction compatible with older Python Pull request #3922
- Fix tests: use CoreDNS resolver for Kapsule Kubernetes tests Pull request #3921
- Fix CI: pin Ansible target interpreter Pull request #3940
- Fix tests: temporarily disable passbolt tests Pull request #3929
v1.6.15-rc3 is available for testing. This release includes ModSecurity validation fixes, improved Python compatibility for tar extraction, and enhanced Kubernetes test infrastructure.
v1.6.15-rc3 of Bunkerweb is now available for testing. This release candidate includes fixes for ModSecurity configuration validation that previously rejected valid configurations on inactive scopes, improved tar extraction compatibility with older Python versions, and upgraded Kubernetes test infrastructure using CoreDNS resolver.