Is it safe to update Portainer?

Tracking portainer/portainer

Update with care.

The replacement of the Docker binary with libstack is a notable internal behavioral change that may affect environment-specific workflows, warranting review before upgrading. The security fixes — particularly the Kubernetes resource enumeration bypass and the restore endpoint admin-takeover vulnerability — make updating advisable, but the libstack substitution means the update is worth reading about rather than applying blindly. No explicit breaking changes, required migrations, or manual upgrade steps are called out in the notes.

Latest version
2.39.4
Last checked

What changed

Portainer 2.39.4 is primarily a security and bug-fix release. It addresses multiple CVEs in the go-git and Go standard library dependencies, covering a broad range of vulnerabilities. Notable bug fixes include a security patch preventing users without environment access from enumerating Kubernetes resources, a fix for a restore endpoint that could allow admin takeover on uninitialised instances, and a resolution for standard users being unable to redeploy team stacks or delete registry images. The Docker binary has been replaced with libstack, and a new API endpoint for refreshing Team/Group membership has been added.

Source

Every verdict on Bumplog traces back to a GitHub release. No invented details.