Two narrowly scoped release blockers are resolved: (1) bound the pinned Syft scanner Go heap inside the isolated 8 GiB Docker-in-Docker runner while retaining installed-package catalogers and the independent full Trivy scan; (2) bind predeploy backups only to an exact repository root so Tower cannot mistake the parent checkout for the prepared controller source. Includes supply-chain and backup regressions.
Two narrowly scoped release blockers are resolved: (1) bound the pinned Syft scanner Go heap inside the isolated 8 GiB Docker-in-Docker runner while retaining installed-package catalogers and the independent full Trivy scan; (2) bind predeploy backups only to an exact repository root so Tower cannot mistake the parent checkout for the prepared controller source. Includes supply-chain and backup regressions.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two narrowly scoped release blockers are resolved: (1) bound the pinned Syft scanner Go heap inside the isolated 8 GiB Docker-in-Docker runner while retaining installed-package catalogers and the independent full Trivy scan; (2) bind predeploy backups only to an exact repository root so Tower cannot mistake the parent checkout for the prepared controller source. Includes supply-chain and backup regressions.
Stabilize AI SBOM release gateto Stabilize the protected production release