Skip to content

M11.3: qualify release runtime by exact OCI digest - #3

Merged
pgousdal merged 5 commits into
mainfrom
work/m11.3-exact-digest-runtime
Sep 5, 2026
Merged

pgousdal merged 5 commits into
mainfrom
work/m11.3-exact-digest-runtime

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Adds an exact-digest release runtime gate. The release workflow now takes the immutable digest emitted by build-push-action, pulls ghcr.io/ploos-as/soju-web@sha256:..., verifies the resolved RepoDigest and OCI revision/version labels, checks UID/GID 1000, and requires /healthz from that exact image before attestation and GitHub Release creation. CI adds fail-closed validation for digest reference syntax and documentation records the M11.3 gate.

@pgousdal
pgousdal merged commit 7badbcf into main Sep 5, 2026
2 checks passed
@pgousdal
pgousdal deleted the work/m11.3-exact-digest-runtime branch September 5, 2026 16:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant