Release CanastaBase 1.3.15 with Debian security updates - #209
Conversation
|
🐳 The image based on b86982c1 commit has been built with |
|
@copilot Does this fix all 168 high/critical security issues? |
Yes—for all 168 findings reported against |
|
Mechanically this is a correct security-rebuild release, and it's the step the observed drift called for. A few things to weigh, one of which is a governance question that matters more than the diff. The mechanism is rightVERSION Governance: this is an auto-PR'd releaseThis is a bot-drafted VERSION bump opened off the rescan tracking issue — the pattern the project has decided against (rescan is a trigger/reminder, not automation that cuts releases; the version bump stays a deliberate human action). A human still reviews and merges, but the PR itself is the automation in question. Worth a conscious decision before accepting, rather than treating it as a routine PR — it sets the "rescan auto-cuts releases" precedent.
|
The immutable
1.3.14images contain 24 fixable HIGH/CRITICAL findings across amd64 and arm64. Current rolling images already include the patched Debian 12 packages.Patch release
VERSIONto1.3.15, triggering publication of a new immutable image.1.3.14tag.Release notes