Skip to content

Refresh BCI minimal base to 15.7-26.58 - #22

Merged
LouisLotter merged 1 commit into
mainfrom
refresh-bci-minimal-acl-attr
Sep 16, 2026
Merged

LouisLotter merged 1 commit into
mainfrom
refresh-bci-minimal-acl-attr

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Refresh the BCI minimal base to 15.7-26.58 and keep the OCI base label aligned. This stays on SUSE 15.7 and retains the existing non-root StackPack delivery contract; no content version bump is needed.

Tracking: https://github.com/StackVista/cve-reporter/issues/91

Validation: candidate CI passed all three StackPack validations/packages/version checks, image smoke test, Trivy vulnerability/secret scans, Grype and both architecture publications. Published amd64 and arm64 images also have zero local Grype matches. The published amd64 image passed the chart copy script with all three packages, UID 1001 and a read-only root. Repository pre-commit checks passed.

Awaiting independent review and human merge; production publication/adoption and a later delivery scan remain outside this candidate validation.

@ai-collaboration-app

Copy link
Copy Markdown
Author

Validation for signed head 47ad833acd618e31d050bbcb56453be55637e067 (CI merge revision 6b9d610): run 35084940260, including its downloadable StackPack/build artifacts. The all-severity scan evaluator reports 0 findings and 0 suppressions; the separate secret scan reports no secrets.

Published candidate: quay.io/stackstate/contrib-stackpacks:20260916102552-refresh-bci-minimal-acl-attr-6b9d610, index sha256:8052dd0a0136d33f8cd48d693b96c042ce23289082356f94ce8a0344d419ea65.

  • amd64 manifest: sha256:880d370f81762194285e8c7d88ad8757137766d491798b313b0c8e6166f5d761
  • arm64 manifest: sha256:6559b0f57f7c78e52e3eaec1bef148f79b7ced58e60562c160b072fafe8f0742

Local Grype 0.117.0 scans of both published architectures returned 0 matches using the database built 2026-09-16T06:30:57Z. CI independently covers Trivy vulnerability/secret scanning and Grype on amd64; arm64 runtime execution was not tested locally.

The chart copy script passed against the published amd64 image with UID 1001, read-only root and a writable /var/stackpacks tmpfs: all three package SHA-256 checksums match after both --clear and append, and a stale destination package is removed by --clear. This checks copy-out compatibility, not installation into a live platform.

@LouisLotter
LouisLotter merged commit 1502a2f into main Sep 16, 2026
12 checks passed
@LouisLotter
LouisLotter deleted the refresh-bci-minimal-acl-attr branch September 16, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants