You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Refresh the BCI minimal base to 15.7-26.58 and keep the OCI base label aligned. This stays on SUSE 15.7 and retains the existing non-root StackPack delivery contract; no content version bump is needed.
Validation: candidate CI passed all three StackPack validations/packages/version checks, image smoke test, Trivy vulnerability/secret scans, Grype and both architecture publications. Published amd64 and arm64 images also have zero local Grype matches. The published amd64 image passed the chart copy script with all three packages, UID 1001 and a read-only root. Repository pre-commit checks passed.
Awaiting independent review and human merge; production publication/adoption and a later delivery scan remain outside this candidate validation.
Validation for signed head 47ad833acd618e31d050bbcb56453be55637e067 (CI merge revision 6b9d610): run 35084940260, including its downloadable StackPack/build artifacts. The all-severity scan evaluator reports 0 findings and 0 suppressions; the separate secret scan reports no secrets.
Published candidate: quay.io/stackstate/contrib-stackpacks:20260916102552-refresh-bci-minimal-acl-attr-6b9d610, index sha256:8052dd0a0136d33f8cd48d693b96c042ce23289082356f94ce8a0344d419ea65.
Local Grype 0.117.0 scans of both published architectures returned 0 matches using the database built 2026-09-16T06:30:57Z. CI independently covers Trivy vulnerability/secret scanning and Grype on amd64; arm64 runtime execution was not tested locally.
The chart copy script passed against the published amd64 image with UID 1001, read-only root and a writable /var/stackpacks tmpfs: all three package SHA-256 checksums match after both --clear and append, and a stale destination package is removed by --clear. This checks copy-out compatibility, not installation into a live platform.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refresh the BCI minimal base to
15.7-26.58and keep the OCI base label aligned. This stays on SUSE 15.7 and retains the existing non-root StackPack delivery contract; no content version bump is needed.Tracking: https://github.com/StackVista/cve-reporter/issues/91
Validation: candidate CI passed all three StackPack validations/packages/version checks, image smoke test, Trivy vulnerability/secret scans, Grype and both architecture publications. Published amd64 and arm64 images also have zero local Grype matches. The published amd64 image passed the chart copy script with all three packages, UID 1001 and a read-only root. Repository pre-commit checks passed.
Awaiting independent review and human merge; production publication/adoption and a later delivery scan remain outside this candidate validation.