Bind Python fixed assertions to published agent532 images - #46
Merged
Merged
Conversation
LouisLotter
approved these changes
Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bind the approved CVE-2026-82049 backport and retained StringPrep CVE-2026-17084 fix to published
quay.io/stackstate/stackstate-k8s-agent:dd1cba03: index28255d2b…, AMD6473aa7c19…, ARM64f3010e4f…(full digests in the VEX). Keep prior products and all other dispositions unchanged; no tag-only, generic Python or mirror assertion.Reuse independent published-artifact acceptance, completion
3ffca03d90ba4e64b724d4619a8e0d98: signed index, both packaged hashes and published regressions passed. Both installed tarfile hashes match7ad04a66bb92373bd6d2552a2f01fce8a4ca95463ebf661612fd574465977929; no producer rebuild or repeat audit.Validation: Grype0.118.0 (same DB built 2026-09-20) consumes both
vex-status: fixedassertions on tag/index/AMD64/ARM64; merged baseline leaves both active. Prior0812a1b8retains only StringPrep fixed; unpatched13451dceand same-content unrelated-identity SBOM retain both active. Non-target dispositions are unchanged. Trivy0.74.0 actual repository-filter controls pass for both CVEs, including unpatched/unrelated/unverified-Rancher negatives; controlled findings prove consumption, not scanner absence. All 32 other statements/prior products preserved; head index CI passes.Tracking: cve-reporter#29. Human VEX/merge decision required. After approval/merge, verify published-hub consumption; Rancher migration/parity remains separate. No whole-image clearance or hold change.