What goharbor/harbor shipped
Written by FoxPlug from public releases; not affiliated with Goharbor. An automatic summary of the public release, pull request and commit data of github.com/goharbor/harbor. Goharbor did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Released v2.15.3-rc2 with fixes for user audit event resolution, registry ping endpoint constraint, and other component updates. Release
- Fixed retention policy metadata leak when deleting projects, which previously left orphaned
retention_idreferences in the database. Pull request #23942 - Fixed garbage collection to not report blobs missing from storage as freed space, preventing inaccurate size reporting in GC jobs. Pull request #23972
- Corrected grammar, formatting, and error messages in user-facing strings across middleware, REST API handlers, core controllers, jobservice, and portal. Pull request #23974
- Added
merge_grouptrigger to CI and CodeQL workflows to support merge queue functionality. Pull request #23986
Why it matters
This week addresses data consistency issues in retention policies and garbage collection reporting, while improving the clarity of user-facing messages. These fixes reduce database leaks and ensure GC operations report accurate freed space metrics.
Changelog entry
- v2.15.3-rc2 released with multiple bug fixes and component updates Release
- fix(retention): drop
retention_idmetadata on project delete Pull request #23942 - fix(gc): do not count blobs missing from storage as freed space Pull request #23972
- fix: correct grammar, formatting, and non-actionable error messages Pull request #23974
- ci: add
merge_grouptrigger to CI and CodeQL workflows Pull request #23986
Harbor v2.15.3-rc2 is out. This release fixes retention policy metadata leaks, corrects GC freed space reporting, and improves error messages across the platform.
Harbor v2.15.3-rc2 is available. Key improvements include fixing retention policy metadata that leaked after project deletion, correcting garbage collection to accurately report freed space without counting missing blobs, and refining error messages for better clarity. These fixes improve data consistency and operational reliability.
Week of September 14, 2026
What shipped
- Retention settings are now exposed during proxy-cache project creation [0]. Pull request #23863
- HTTPS URL scheme checking for CA download is now case-insensitive per RFC 3986 [2]. Pull request #23888
- Cache prefix handling fixed to prevent double prefixing when removing expired entries [4]. Pull request #23913
- Graceful shutdown no longer produces misleading error logs from http.ErrServerClosed [3]. Pull request #23296
- GitHub CodeQL action updates are now applied in a single Dependabot PR instead of separate ones [1]. Pull request #23929
- Dependabot is configured to ignore major Angular and TypeScript updates in the portal [5]. Pull request #23858
- Documentation typo corrected in member component [6]. Pull request #23807
Why it matters
This week's changes improve proxy-cache configuration options, fix protocol handling edge cases, and address cache consistency issues. The fixes ensure cleaner shutdown behavior and more reliable dependency management for the project.
Changelog entry
- Feature: Expose retention setting during proxy-cache project creation Pull request #23863
- Fix: HTTPS URL scheme check for CA download is now case-insensitive Pull request #23888
- Fix: Avoid double prefix when removing expired cache entries Pull request #23913
- Fix: Ignore http.ErrServerClosed on graceful shutdown to prevent misleading error logs Pull request #23296
- CI: Consolidate GitHub CodeQL action updates into single Dependabot PR Pull request #23929
- CI: Ignore Angular and TypeScript major updates in portal Dependabot groups Pull request #23858
- Docs: Fix typo in member component Pull request #23807
Harbor's latest updates include retention settings for proxy-cache projects, RFC-compliant URL scheme checking, and fixes for cache handling and graceful shutdown behavior.
Harbor continues improving with this week's releases: retention settings are now configurable during proxy-cache project creation, URL scheme checking for CA downloads is now RFC 3986 compliant, cache prefix handling is fixed to prevent entry duplication, and graceful shutdown produces cleaner logs. Plus updated dependency management strategies for better CI stability.