Developer Hub 1.10.3 updates the portal, operator and AI content images
The Important security release spans 14 CVEs and also corrects catalog image and dynamic-plugin resolution problems from 1.10.2.
Red Hat Developer Hub 1.10.3 is an Important security update covering 14 CVEs. Operators should treat it as a portal-stack update rather than a single application patch: Red Hat publishes replacement images for the Developer Hub application, operator, operator bundle, must-gather utility and RAG content service.
What is affected
The primary runtime image is rhdh-hub-rhel9, which carries the Backstage-based portal used for the software catalog, templates, TechDocs and installed dynamic plugins. The rhdh-rhel9-operator and rhdh-operator-bundle control deployment and upgrades. The advisory also replaces rhdh-rag-content-rhel9, used by Developer Hub’s AI-oriented content path, and rhdh-must-gather-rhel9, the support-data collector.
Red Hat lists 14 CVEs but does not reduce the advisory to one exploit path. Exposure triage should start with what is actually enabled and reachable: portal routes and authentication, catalog ingestion, software templates, TechDocs, dynamic plugins, and any Lightspeed or RAG integration. Clusters that retained 1.10.2 catalog metadata deserve extra attention because the same release fixes two non-CVE packaging defects.
One fix corrects outdated catalog digests and references that pointed Lightspeed at ghcr.io images and supplied invalid Orchestrator digests. A second corrects {{inherit}} resolution that could select older Orchestrator frontend, backend and form-widget plugin versions than the preceding 1.10.1 operator. Those defects make image provenance and plugin inventory part of the post-update check, not an optional cleanup.
Operator checklist
- Inventory the current Developer Hub CSV, application image digest and enabled dynamic plugins. Record whether Lightspeed, Orchestrator or RAG content is deployed.
- Update through the supported operator channel to 1.10.3 and wait for the operator and Developer Hub custom resource to settle without reconciliation errors.
- Compare running image IDs with the amd64 digests in RHSA-2026:49642 for the hub, operator, bundle, must-gather and RAG content images.
- Inspect catalog-source and subscription status. Confirm the deployment no longer resolves Lightspeed to unexpected
ghcr.iocontent or Orchestrator plugins to stale versions. - Exercise the exposed paths: sign in, read the catalog, render TechDocs, create a test component from an approved template and load each business-critical dynamic plugin.
- If AI features are enabled, test Lightspeed or RAG retrieval separately and verify the
rhdh-rag-content-rhel9image was replaced. - Review network and identity logs for unusual portal access during the pre-update window; prioritize public routes and highly privileged template actions.
A successful upgrade is the combination of corrected digests, expected plugin versions and working portal flows. The version label alone cannot prove that the old application or plugin artifacts have left the cluster.
sources
- RHSA-2026:49642 — Red Hat Developer Hub 1.10.3access.redhat.com
comments · 0