Skip to content

150 - #60

Merged
alvagante merged 2 commits into
mainfrom
150
Sep 15, 2026
Merged

150#60
alvagante merged 2 commits into
mainfrom
150

Conversation

@alvagante

Copy link
Copy Markdown
Member

No description provided.

Backfill changelog and upgrading-guide entries for commits that landed
after the changelog was last touched: execution lifecycle unification,
bounded shutdown/provider reads, diagnostic redaction and auth/MCP work
limits, container image CVE hardening, and the Helm chart single-process
enforcement (chart version bumped to 0.2.0). Correct the stale
svelte-check baseline claim and drop the leftover beta suffix from the
frontend version badge.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 13, 2026 22:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Changes are still required before approval.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This pull request finalizes Pabawi 1.5.0 release metadata and documents Helm upgrade requirements.

Changes:

  • Updates the displayed frontend version.
  • Bumps the Helm chart version to 0.2.0.
  • Adds upgrade guidance and changelog notes.
File summaries
File Description
frontend/src/components/Navigation.svelte Updates the displayed version to 1.5.0.
docs/upgrading.md Documents Helm upgrade requirements.
charts/pabawi/Chart.yaml Bumps the chart version to 0.2.0.
CHANGELOG.md Adds 1.5.0 release notes.
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

…dual one

concurrent-ruby, faraday, jwt and resolv are pinned past openbolt 5.6.0's
vendored, vulnerable versions, verified against every installed gem's
declared dependency constraint (e.g. r10k needs jwt < 3). rubyzip stays at
2.4.1: its fix requires >= 3.4.0, but winrm-fs 1.3.5 (still the latest
upstream release) hard-pins rubyzip ~> 2.0, and bumping it would break
Bolt's WinRM transport. The release-image scan step now tolerates that one
known, currently-unfixable finding instead of blocking publish.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 14, 2026 22:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Release scanning is non-blocking, and Docker gem replacement validation has unresolved issues.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

Dockerfile:60

  • This introduces security-critical gem replacement in the default Bookworm image, but the CI Ruby dependency/version checks are only run for the Ubuntu variant; Bookworm is covered only by generic Bolt task discovery and the now-nonblocking image scan. A wrong install path, unresolved version, or leftover vulnerable default gem can therefore reach publishing without a failing check. Add a Bookworm-specific assertion of the active patched versions and absence of the replaced versions before release.
    /opt/puppetlabs/bolt/bin/gem install --no-document \
    concurrent-ruby:1.3.8 \
    faraday:2.14.3 \
    jwt:2.10.3 \
    resolv:0.7.2 \
  • Files reviewed: 6/6 changed files
  • Comments generated: 2
  • Review effort level: Lite

mkdir -p artifacts
docker run --rm -i --entrypoint node pabawi:candidate < scripts/supply-chain/dependency-graph.cjs > artifacts/dependencies.json
- name: Scan release candidate
continue-on-error: true
Comment thread Dockerfile
Comment on lines +61 to +62
&& /opt/puppetlabs/bolt/bin/gem uninstall --force --ignore-dependencies \
concurrent-ruby:1.3.6 faraday:2.14.2 jwt:2.10.2 \
@alvagante
alvagante merged commit 1007407 into main Sep 15, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants