Skip to content

fix(release): refresh v0.22 image advisories - #776

Merged
jeremi merged 1 commit into
mainfrom
security/refresh-v022-image-advisories
Aug 14, 2026
Merged

fix(release): refresh v0.22 image advisories#776
jeremi merged 1 commit into
mainfrom
security/refresh-v022-image-advisories

Conversation

@jeremi

@jeremi jeremi commented Aug 14, 2026

Copy link
Copy Markdown
Member

What changed

  • rebind the Relay, Evidence, and Mint advisory baselines to the reviewed v0.22.0 Linux AMD64 candidate bytes
  • preserve the existing policies, invalidation triggers, component layer, owners, severities, and 2026-08-28 expiry
  • update the live whole-image fingerprint test fixtures to the same official candidate provenance

Why

The v0.22.0 application layers and service binaries changed while the reviewed base image, libc component layer, runtime process contracts, and four shared runtime-library fingerprints remained unchanged. The three existing Debian Trixie libc findings still have no compatible fix and remain bound to exact reviewed bytes.

Validation

  • exact Grype, Syft, OCI-config, and rootfs checks for Relay, Evidence, and Mint: 14 findings, 3 blocking findings, 3 matching exceptions, 0 invalidations each
  • advisory baseline unit tests: 45 passed, 1 skipped
  • full release script test discovery passed
  • release gate inventory passed for 151 gates
  • full actionlint passed
  • git diff --check passed
  • independent security diff review found no issues

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi marked this pull request as ready for review August 14, 2026 03:29
@jeremi
jeremi merged commit d9a278a into main Aug 14, 2026
34 checks passed
@jeremi
jeremi deleted the security/refresh-v022-image-advisories branch August 14, 2026 03:29

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 007a4e0925

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"mint": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12",
}
LIVE_REFERENCE_SOURCE_REVISION = "b9f6d12d7d4b62199558351087487550eedb2bdc"
LIVE_REFERENCE_SOURCE_REVISION = "0ddd1fa6481ef0154d9f11a13815ba35ab942053"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add the required DCO sign-off

Commit 7eac9b8d808a325e3651026fc5391da629865906 has no Signed-off-by trailer, so the repository's DCO workflow will reject it. Recreate the commit with git commit -s or otherwise add a valid sign-off trailer.

AGENTS.md reference: AGENTS.md:L272-L274

Useful? React with 👍 / 👎.

],
"application_layer_ids": [
"sha256:595ce1178134b3b30b0f17ae2af5d5340dec1402357815446ca25767486000be",
"sha256:dd3c98586309126e1a7daf7864a2fd4f39706f5d571d830b4ea1590cbb35e964",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Split the change along ownership boundaries

This commit combines a products/relay-v2 baseline update with release-owned Evidence/Mint baselines and release tests. The repository explicitly requires each change to remain within one owning area, so separate the Relay product update from the release/ update.

AGENTS.md reference: AGENTS.md:L280-L282

Useful? React with 👍 / 👎.

"runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814",
"reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3",
"reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053",
"reference_provenance": "official_candidate",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Align the release runbook with the new provenance

Changing Evidence and Mint to official_candidate makes release/OPERATIONS.md:241-244 false: it still says Relay uses the v0.20.1 official candidate while Evidence and Mint use local v0.20.1 reproductions because official reports were unavailable. Update that operational description to reflect the reviewed v0.22.0 candidates so later advisory renewals and security reviews do not rely on obsolete provenance.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant