Skip to content

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 17 Jul 23:34
· 13 commits to main since this release

Cloud one-click trial deploys, first-review product tour, and Scorecard publish fix.

Added

  • First-review product tour — guided spotlight walkthrough (driver.js) after first login:
    Models → Connectors → Gate → Findings. Completion/skip dual-written to users.preferences
    (productTour.firstReviewStatus) and browser localStorage (hard-refresh safe); replay from
    Account → Replay product tour. Closing mid-tour (X) toasts how to restart.
    Migration 014_user_preferences.sql; PATCH /v1/auth/me/preferences (all signed-in roles).
    Popover follows light/dark theme tokens.
  • Cloud one-click trial deploys — shared single-VM stack under deploy/cloud/
    (nginx edge HTTPS + Keycloak OIDC + API/worker/UI + Postgres). No LLM key at install (Models UI).
    Self-signed TLS by default (PKCE / crypto.subtle); optional DOMAIN for cert CN.
    • AWS CloudFormation Launch Stack (deploy/cloud/aws/)
    • Azure Bicep/ARM Deploy (deploy/cloud/azure/)
    • GCP Cloud Shell + gcloud (deploy/cloud/gcp/)
    • DigitalOcean Marketplace 1-Click vendor assets (deploy/cloud/do/)

Fixed

  • Cloud trial deploys (deploy/cloud/): production-shaped single-VM path hardened after Azure pilot:
    • nginx edge (HTTPS self-signed) instead of Traefik (Docker Engine 29 API incompatibility)
    • SPA OIDC: ignore bake-time localhost issuer off-loopback; empty UI Dockerfile OIDC defaults
    • nginx routes /auth/callback to UI (Keycloak is under /auth/*)
    • Keycloak Admin issuer parse supports path-based /auth/realms/... (org create)
    • first-boot: quoted .env, IaC placeholder sanitization, Azure IMDS, always-HTTPS for PKCE
    • Azure cloud-init via Bicep format() + NSG on NIC
  • Product tour UX — sidebar nav scroll for Models/Connectors; step counter no longer resets on
    SPA navigation; “Configure a provider” targets provider API keys (not the stage matrix);
    dark-mode button hover contrast on popover controls.
  • CI — OpenSSF Scorecard job uses only uses: steps when publish_results: true (OpenSSF
    workflow verification; shell retry steps caused 400 “scorecard job must only have steps with uses”).
  • Code scanning — pin Docker base images and Keycloak workflow actions by digest/SHA;
    Confluence HTML strip handles </script…> end tags; git clone SHA fetch restricted to object ids +
    checkout --; remove empty Keycloak password field from Helm values; drop unused locals flagged by CodeQL.

Container images

docker pull ghcr.io/codesteward/codesteward:1.3.0
docker pull ghcr.io/codesteward/codesteward/ui:1.3.0
docker pull ghcr.io/codesteward/codesteward/keycloak:26.7.0   # tag = upstream Keycloak, not product 1.3.0

App image runs API by default (SERVICE=api). Worker:

docker run --rm -e SERVICE=worker ghcr.io/codesteward/codesteward:1.3.0

Keycloak image tags match upstream Keycloak (theme + realm baked in; no git mounts):

docker run --rm -p 8083:8083 -e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin \
  ghcr.io/codesteward/codesteward/keycloak:26.7.0 start-dev --import-realm --http-port=8083

Helm chart (OCI on GHCR)

helm install codesteward oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.3.0
# or: helm pull oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.3.0

Chart package is also attached to this release as codesteward-1.3.0.tgz.
Docs: Kubernetes quick start in the product documentation site.

Images are signed with cosign keyless via GitHub OIDC.
Verify with:

cosign verify ghcr.io/codesteward/codesteward:1.3.0 \
  --certificate-identity-regexp 'https://github.com/Codesteward/codesteward/.*' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com