latest-dev
Pre-release
Pre-release
π¦ weave-gitops β v0.38.0-dev+5e3cd5d
Release type: prerelease β’ Commit:
5e3cd5d
Security: π‘οΈ β Critical β 1 critical and 7 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/weave-gitops |
dev-5e3cd5d latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/weave-gitops
docker pull docker.io/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
cr.pcfae.com/hlhd/weave-gitops
docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
ghcr.io/homelabhd/weave-gitops
docker pull ghcr.io/homelabhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
Notable Changes
Features
- config: toolchains flag-day: want: wrapper + retention (SoFMeRight)
Bug Fixes
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
- build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
- ui: restore the dashboard β fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
- build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
- build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
- ci: select gitops-server.dockerfile as the image build target (SoFMeRight) Γ2
- deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
- deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
- deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
- deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
- deps: clear audition freshness gate and restore the Go build (SoFMeRight)
- deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
- logger: pass built message as argument, not format string (SoFMeRight)
- deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
- deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
- commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
- build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
- config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)
Documentation
- readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
- refresh generated badges (stagefreight) Γ4
Tests
- http: generate self-signed localhost cert at test time (SoFMeRight)
CI/CD
- exclude vendored website/ docs tree from lint (SoFMeRight)
- add StageFreight pipeline β build the weave-gitops webapp from upstream main (SoFMeRight)
- do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ15
- deps: update managed dependencies (stagefreight) Γ6
- deps: bump frontend CVE deps within-major (SoFMeRight)
- deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
Other Changes
- Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)
Security
π‘οΈ β Critical β 1 critical and 7 high vulnerabilities detected
Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-31789 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a... |
| High | CVE-2025-15467 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may... |
| High | CVE-2025-69421 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a... |
| High | CVE-2026-28387 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or... |
| High | CVE-2026-28388 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary... |
| High | CVE-2026-28389 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-28390 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-45447 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process... |
| Medium | CVE-2026-0915 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0... |
| Medium | CVE-2026-18374 | libc6 | 2.36-9+deb12u13 | β | Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow... |
| Medium | CVE-2026-19499 | libc6 | 2.36-9+deb12u13 | β | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding... |
| Medium | CVE-2026-19542 | libc6 | 2.36-9+deb12u13 | β | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application... |
| Medium | CVE-2026-4046 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to... |
| Medium | CVE-2026-4437 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response... |
| Medium | CVE-2026-5435 | libc6 | 2.36-9+deb12u13 | β | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds... |
| Medium | CVE-2026-5450 | libc6 | 2.36-9+deb12u13 | β | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024... |
| Medium | CVE-2026-5928 | libc6 | 2.36-9+deb12u13 | β | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library... |
| Medium | CVE-2026-6238 | libc6 | 2.36-9+deb12u13 | β | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when... |
| Medium | CVE-2026-6368 | libc6 | 2.36-9+deb12u13 | β | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43Β can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may... |
| Medium | CVE-2026-6791 | libc6 | 2.36-9+deb12u13 | β | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation... |
| Medium | CVE-2026-77117 | libc6 | 2.36-9+deb12u13 | β | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no... |
| Medium | CVE-2026-80489 | libc6 | 2.36-9+deb12u13 | β | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no... |
| Medium | CVE-2026-8674 | libc6 | 2.36-9+deb12u13 | β | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library... |
| Medium | CVE-2026-86805 | libc6 | 2.36-9+deb12u13 | β | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges... |
| Medium | CVE-2026-89092 | libc6 | 2.36-9+deb12u13 | β | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS... |
| Medium | CVE-2026-95818 | libc6 | 2.36-9+deb12u13 | β | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid... |
| Medium | CVE-2025-69419 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte... |
| Medium | CVE-2026-31790 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The... |
| Medium | CVE-2026-34182 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various... |
| Medium | CVE-2026-45445 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact... |
| Medium | CVE-2026-63072 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that... |
| Medium | CVE-2026-63076 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter... |
| Medium | GO-2026-5491 | github.com/tomwright/dasel/v2 | v2.8.1 | β | Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string in github.com/tomwright/dasel |
| Medium | GO-2026-4768 | github.com/tomwright/dasel/v2 | v2.8.1 | β | Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service in github.com/tomwright/dasel |
| Medium | GO-2026-5493 | github.com/tomwright/dasel/v2 | v2.8.1 | β | Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal in github.com/tomwright/dasel |
| Low | CVE-2010-4756 | libc6 | 2.36-9+deb12u13 | β | The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do... |
| Low | CVE-2018-20796 | libc6 | 2.36-9+deb12u13 | β | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\1\1|t1|\\2537)+' in grep. |
| Low | CVE-2019-1010022 | libc6 | 2.36-9+deb12u13 | β | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl... |
| Low | CVE-2019-1010023 | libc6 | 2.36-9+deb12u13 | β | GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld... |
| Low | CVE-2019-1010024 | libc6 | 2.36-9+deb12u13 | β | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc... |
| Low | CVE-2019-1010025 | libc6 | 2.36-9+deb12u13 | β | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc... |
| Low | CVE-2019-9192 | libc6 | 2.36-9+deb12u13 | β | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\1\1)*' in grep, a different issue than... |
| Low | CVE-2025-15281 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member... |
| Low | CVE-2026-0861 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could... |
| Low | CVE-2026-4438 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS... |
| Low | CVE-2025-27587 | libssl3 | 3.0.17-1~deb12u3 | β | OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then... |
| Low | CVE-2025-68160 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact... |
| Low | CVE-2025-69418 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial... |
| Low | CVE-2025-69420 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid... |
| Low | CVE-2026-22795 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be... |
| Low | CVE-2026-22796 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an... |
| Low | CVE-2026-34180 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like... |
| Low | CVE-2026-42766 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an... |
| Low | CVE-2026-42767 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference... |
| Low | CVE-2026-42770 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which... |
| Low | CVE-2026-45446 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery... |
| Low | CVE-2026-54874 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use... |
| Low | CVE-2026-63074 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If... |
| Low | CVE-2026-7383 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow... |
| Low | CVE-2026-75803 | libssl3 | 3.0.17-1~deb12u3 | 3.0.22-1~deb12u1 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the... |
| Low | CVE-2026-9076 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read... |
Full changelog
- [
5e3cd5d] reconcile README with scribe blocks; keep local tweaks (SoFMeRight) - [
f6637da] use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight) - [
e4d636d] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a843330] refresh generated badges (stagefreight) - [
141dc7a] forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight) - [
2d01b3e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
63b7fe4] refresh generated badges (stagefreight) - [
1b58d1b] restore the dashboard β fix MUI 9 Tabs render loop on detail pages (SoFMeRight) - [
f9ea201] update managed dependencies (stagefreight) - [
6b1552e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
83c47d4] update managed dependencies (stagefreight) - [
7a3145c] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e9c1997] refresh generated badges (stagefreight) - [
f95daa2] refresh generated badges (stagefreight) - [
dbc0c76] enable corepack for yarn in the node 26 UI stage (SoFMeRight) - [
c6fbb5d] bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight) - [
93cef0f] select gitops-server.dockerfile as the image build target (SoFMeRight) - [
d47c8c8] select gitops-server.dockerfile as the image build target (SoFMeRight) - [
aff8418] hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight) - [
7235b2f] scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight) - [
ff94b32] add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight) - [
a9ee3c2] update managed dependencies (stagefreight) - [
0cc101a] pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight) - [
f3bd9f8] update managed dependencies (stagefreight) - [
8e8158a] clear audition freshness gate and restore the Go build (SoFMeRight) - [
d58a8c1] remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight) - [
11663cd] update managed dependencies (stagefreight) - [
850ce24] update managed dependencies (stagefreight) - [
6fcfa61] pass built message as argument, not format string (SoFMeRight) - [
00b0c48] modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight) - [
d20c1ba] bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight) - [
d989edd] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
fad3e14] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
63d63a8] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
816e81a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
119a0f1] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6dc2a8d] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
b4c60d5] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
57e79ed] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e1aecd2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
5171c3e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
2fb494f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
918585a] fall back to chore, not docs, when a commit has no type (SoFMeRight) - [
f335f0a] generate self-signed localhost cert at test time (SoFMeRight) - [
091d849] bump frontend CVE deps within-major (SoFMeRight) - [
7f754cf] bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight) - [
c207c1e] Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight) - [
fdffb2b] name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight) - [
8a39fa4] toolchains flag-day: want: wrapper + retention (SoFMeRight) - [
1ed18d6] exclude vendored website/ docs tree from lint (SoFMeRight) - [
ad83f84] prerelease publishes to all registries (match stable/dev) (SoFMeRight) - [
ce0c4df] migrate to current stagefreight schema + canonical suite (SoFMeRight) - [
cc6668d] add StageFreight pipeline β build the weave-gitops webapp from upstream main (SoFMeRight) - [
936e848] do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)