What liquibase/liquibase shipped
Written by FoxPlug from public releases; not affiliated with Liquibase. An automatic summary of the public release, pull request and commit data of github.com/liquibase/liquibase. Liquibase did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- OSS released assets now publish to Cloudflare R2 instead of the legacy S3 bucket
liquibaseorg-origin. Pull request #8005 - OSS released assets now route to their own dedicated R2 bucket instead of a shared prefix. Pull request #8018
- Javadocs publishing now writes to Cloudflare R2 directly rather than relying on lazy copy-on-read from S3. Pull request #8004
- S3 sync step removed from javadocs workflow since R2 is now the primary target. Pull request #8017
- Stopped writing XSD schema files to the legacy S3 bucket as part of decommissioning efforts. Pull request #8006
- Dispatched dry-run releases can now pass the green-SHA gate without blocking on themselves. Pull request #8015
- Ubuntu security patches now applied during Docker image build time for the noble-based image. Pull request #8007
- Added Grype ignore rule for zlib CVE-2026-85091 where no fix version exists. Pull request #8013
- Fixed Docker security scanning rule to match Grype's actual empty fix-state field instead of
not-fixed. Pull request #8014 - Removed outdated documentation claiming dry-run releases produce ECR images. Pull request #8009
Why it matters
This week consolidated artifact storage by migrating from legacy S3 buckets to Cloudflare R2, removing intermediate copy steps so that javadocs and release assets serve directly from their final destination. The changes also fix release workflow dispatch gates and improve Docker image security scanning rules.
Changelog entry
- OSS released assets now publish to Cloudflare R2 bucket instead of S3 Pull request #8005
- OSS released assets use their own dedicated R2 bucket for proper access scoping Pull request #8018
- Javadocs now publish directly to Cloudflare R2 without S3 intermediate storage Pull request #8004
- Removed XSD publishing to legacy liquibaseorg-origin S3 bucket Pull request #8006
- Dispatched dry-run releases can now pass CI gates Pull request #8015
- Ubuntu security patches applied during Docker build time Pull request #8007
- Docker security scanning rule corrected for empty Grype fix states Pull request #8014
Release infrastructure now publishes javadocs and OSS assets directly to Cloudflare R2. Removed legacy S3 sync steps and fixed dry-run release gates. Docker security scanning rules now match Grype behavior.
This week's infrastructure improvements streamline how Liquibase publishes its artifacts. We've migrated javadocs and OSS release assets to Cloudflare R2, eliminating legacy S3 bucket dependencies and removing unnecessary copy-on-read bridges. We also fixed release workflow gates to unblock dispatched dry runs and improved Docker security scanning to correctly identify unfixed vulnerabilities.
Week of September 14, 2026
What shipped
- Release creation now builds from a pinned commit instead of an operator-supplied run ID, establishing a verifiable link between released bytes and the version being released. Pull request #7990
- Fixed the release gate workflow that was incorrectly counting its own runs, preventing accurate validation of release readiness. Pull request #8000
- Package cleanup now removes branch-named SNAPSHOT versions in addition to commit-shaped ones, eliminating installable fork-built artifacts from public registries. Pull request #7989
- Stopped automatic creation of nightly pre-releases on every push to the repository. Pull request #8001
- Fixed the automated Jira ticket creation workflow to trigger on merge commits from community PRs instead of pull request close events. Pull request #8003
- Updated the Alpine container image to patch 9 high-severity CVEs in libcrypto3 and libssl3. Pull request #7999
- Removed an unreachable dispatch-only workflow that held inherited secrets without any review or trigger mechanism. Pull request #7966
Why it matters
This week's changes harden the release and build infrastructure by establishing traceable commits for releases, fixing gate logic that was blocking releases, cleaning up stale artifacts from public registries, and removing security risks from orphaned workflows. These improvements make the release process more reliable and secure.
Changelog entry
- Release creation now pins to a specific commit for reproducibility and traceability Pull request #7990
- Fixed release gate workflow self-counting logic Pull request #8000
- Package cleanup expanded to remove branch-named SNAPSHOT versions Pull request #7989
- Disabled automatic nightly pre-release creation on every push Pull request #8001
- Fixed Jira ticket automation to trigger on merge commits from community PRs Pull request #8003
- Updated Alpine image to patch high-severity OpenSSL CVEs Pull request #7999
- Removed unreachable
fossa_ai.ymlworkflow Pull request #7966
Release infrastructure hardening: pinned commits for releases, fixed validation gates, cleaned up orphaned artifacts, and removed unreachable workflows holding inherited secrets.
This week we strengthened Liquibase's release and build infrastructure with several critical improvements: releases now build from pinned commits instead of operator-supplied IDs, establishing full traceability; the release validation gate was fixed to avoid counting its own runs; package cleanup now removes all branch-named SNAPSHOT versions from public registries; and we removed an unreachable workflow that held inherited secrets. These changes make our release process more reliable and secure.