Skip to content

Upgrade container security packages and gate image promotion - #24

Merged
brspoon merged 7 commits into
mainfrom
brspoon/upgrade-runtime-packages
Oct 7, 2026
Merged

brspoon merged 7 commits into
mainfrom
brspoon/upgrade-runtime-packages

Conversation

@brspoon

@brspoon brspoon commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Update the container to signed Python 3.14.8 and zlib packages, retain the required runtime guards, and refresh matching source and license records. Limit verified-fixed scanner reviews to the three findings still reported for that exact Python package, with the existing October 20 deadline.

Stage native candidates separately from stable promotion. Promotion requires successful original validation, unchanged security evidence, and a fresh review of completed Docker Hub analysis showing zero findings for both exact native digests. Disable the older standalone publishing route.

Validation: 1,275 Python tests ran successfully (11 skipped), 139 JavaScript tests passed, reviewed source hashes and diff checks passed, and required PR checks and CodeQL passed. Complete native amd64 and arm64 qualification passed, including scanners, runtime probes, installation/recovery and matching-source/license verification.

@brspoon
brspoon merged commit 5ecc161 into main Oct 7, 2026
19 checks passed
@brspoon
brspoon deleted the brspoon/upgrade-runtime-packages branch October 7, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant