Complete RC6 supply chain gate
This commit is contained in:
@@ -19,6 +19,11 @@
|
||||
dependency audits, a digest-pinned container scan and an SPDX SBOM.
|
||||
- Added a hashed Linux/Python 3.11 GIS/dev lock with an enforced input
|
||||
fingerprint while keeping PyTorch and Ultralytics out of base CI.
|
||||
- Completed live SBOM and vulnerability-policy evidence for the configured AI
|
||||
image. The final runtime replaces the Postgres base image's Go `gosu`
|
||||
executable with an audited `setpriv` wrapper; the complete report still
|
||||
retains the shadowed base-layer findings while the executable policy gate
|
||||
reports zero reachable fixed HIGH/CRITICAL vulnerabilities.
|
||||
- Folded fresh-install, upgrade, rollback and runtime proof into RC-5 and
|
||||
RC-11 instead of creating a separate RC-12 phase.
|
||||
- Added a read-only release-evidence manifest command with Git, migration,
|
||||
|
||||
Reference in New Issue
Block a user