fix(release): refresh v0.22 image advisories - #776
Conversation
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 007a4e0925
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "mint": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", | ||
| } | ||
| LIVE_REFERENCE_SOURCE_REVISION = "b9f6d12d7d4b62199558351087487550eedb2bdc" | ||
| LIVE_REFERENCE_SOURCE_REVISION = "0ddd1fa6481ef0154d9f11a13815ba35ab942053" |
There was a problem hiding this comment.
Commit 7eac9b8d808a325e3651026fc5391da629865906 has no Signed-off-by trailer, so the repository's DCO workflow will reject it. Recreate the commit with git commit -s or otherwise add a valid sign-off trailer.
AGENTS.md reference: AGENTS.md:L272-L274
Useful? React with 👍 / 👎.
| ], | ||
| "application_layer_ids": [ | ||
| "sha256:595ce1178134b3b30b0f17ae2af5d5340dec1402357815446ca25767486000be", | ||
| "sha256:dd3c98586309126e1a7daf7864a2fd4f39706f5d571d830b4ea1590cbb35e964", |
There was a problem hiding this comment.
Split the change along ownership boundaries
This commit combines a products/relay-v2 baseline update with release-owned Evidence/Mint baselines and release tests. The repository explicitly requires each change to remain within one owning area, so separate the Relay product update from the release/ update.
AGENTS.md reference: AGENTS.md:L280-L282
Useful? React with 👍 / 👎.
| "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", | ||
| "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", | ||
| "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", | ||
| "reference_provenance": "official_candidate", |
There was a problem hiding this comment.
Align the release runbook with the new provenance
Changing Evidence and Mint to official_candidate makes release/OPERATIONS.md:241-244 false: it still says Relay uses the v0.20.1 official candidate while Evidence and Mint use local v0.20.1 reproductions because official reports were unavailable. Update that operational description to reflect the reviewed v0.22.0 candidates so later advisory renewals and security reviews do not rely on obsolete provenance.
Useful? React with 👍 / 👎.
What changed
Why
The v0.22.0 application layers and service binaries changed while the reviewed base image, libc component layer, runtime process contracts, and four shared runtime-library fingerprints remained unchanged. The three existing Debian Trixie libc findings still have no compatible fix and remain bound to exact reviewed bytes.
Validation
actionlintpassedgit diff --checkpassed