Complete RC6 supply chain gate
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 04:43:49 +02:00
parent 0bd3934303
commit 8e49b857dd
4 changed files with 62 additions and 3 deletions
+5
View File
@@ -19,6 +19,11 @@
dependency audits, a digest-pinned container scan and an SPDX SBOM.
- Added a hashed Linux/Python 3.11 GIS/dev lock with an enforced input
fingerprint while keeping PyTorch and Ultralytics out of base CI.
- Completed live SBOM and vulnerability-policy evidence for the configured AI
image. The final runtime replaces the Postgres base image's Go `gosu`
executable with an audited `setpriv` wrapper; the complete report still
retains the shadowed base-layer findings while the executable policy gate
reports zero reachable fixed HIGH/CRITICAL vulnerabilities.
- Folded fresh-install, upgrade, rollback and runtime proof into RC-5 and
RC-11 instead of creating a separate RC-12 phase.
- Added a read-only release-evidence manifest command with Git, migration,