Skip to content

v0.39.1

Latest

Choose a tag to compare

@SoFMeRight SoFMeRight released this 28 Sep 12:58
· 15 commits to main since this release

πŸ“¦ weave-gitops β€” v0.39.1

Release type: latest β€’ Commit: 5e3cd5d

Security: πŸ›‘οΈ ❌ Critical β€” 1 critical and 7 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/weave-gitops v0.39.1 latest
cr.pcfae.com cr.pcfae.com/hlhd/weave-gitops v0.39.1 latest
GitHub Container Registry ghcr.io/homelabhd/weave-gitops v0.39.1 latest
Digest pull commands & supply chain artifacts

docker.io/hlhd/weave-gitops

docker pull docker.io/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

cr.pcfae.com/hlhd/weave-gitops

docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

ghcr.io/homelabhd/weave-gitops

docker pull ghcr.io/homelabhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

Highlights

  • config: toolchains flag-day: want: wrapper + retention
  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version
  • build: forward version metadata build args to make (stop reporting v0.0.0)
  • ui: restore the dashboard β€” fix MUI 9 Tabs render loop on detail pages
  • build: enable corepack for yarn in the node 26 UI stage
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module
  • ci: select gitops-server.dockerfile as the image build target
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket)

Notable Changes

Features

  • config: toolchains flag-day: want: wrapper + retention (SoFMeRight)

Bug Fixes

  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • ui: restore the dashboard β€” fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
  • build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
  • ci: select gitops-server.dockerfile as the image build target (SoFMeRight) Γ—2
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
  • deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
  • deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
  • deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
  • deps: clear audition freshness gate and restore the Go build (SoFMeRight)
  • deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
  • logger: pass built message as argument, not format string (SoFMeRight)
  • deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
  • deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
  • commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
  • build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
  • config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)

Documentation

  • readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
  • refresh generated badges (stagefreight) Γ—4

Tests

  • http: generate self-signed localhost cert at test time (SoFMeRight)

CI/CD

  • exclude vendored website/ docs tree from lint (SoFMeRight)
  • add StageFreight pipeline β€” build the weave-gitops webapp from upstream main (SoFMeRight)
  • do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ—15
  • deps: update managed dependencies (stagefreight) Γ—6
  • deps: bump frontend CVE deps within-major (SoFMeRight)
  • deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)

Other Changes

  • Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)

Security

πŸ›‘οΈ ❌ Critical β€” 1 critical and 7 high vulnerabilities detected

Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-31789 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a...
High CVE-2025-15467 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may...
High CVE-2025-69421 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a...
High CVE-2026-28387 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or...
High CVE-2026-28388 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary...
High CVE-2026-28389 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-28390 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-45447 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process...
Medium CVE-2026-0915 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0...
Medium CVE-2026-18374 libc6 2.36-9+deb12u13 β€” Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow...
Medium CVE-2026-19499 libc6 2.36-9+deb12u13 β€” Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding...
Medium CVE-2026-19542 libc6 2.36-9+deb12u13 β€” Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application...
Medium CVE-2026-4046 libc6 2.36-9+deb12u13 2.36-9+deb12u14 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to...
Medium CVE-2026-4437 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response...
Medium CVE-2026-5435 libc6 2.36-9+deb12u13 β€” The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds...
Medium CVE-2026-5450 libc6 2.36-9+deb12u13 β€” Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024...
Medium CVE-2026-5928 libc6 2.36-9+deb12u13 β€” Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library...
Medium CVE-2026-6238 libc6 2.36-9+deb12u13 β€” The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when...
Medium CVE-2026-6368 libc6 2.36-9+deb12u13 β€” Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43Β can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may...
Medium CVE-2026-6791 libc6 2.36-9+deb12u13 β€” When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation...
Medium CVE-2026-77117 libc6 2.36-9+deb12u13 β€” Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no...
Medium CVE-2026-80489 libc6 2.36-9+deb12u13 β€” Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no...
Medium CVE-2026-8674 libc6 2.36-9+deb12u13 β€” Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library...
Medium CVE-2026-86805 libc6 2.36-9+deb12u13 β€” A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges...
Medium CVE-2026-89092 libc6 2.36-9+deb12u13 β€” The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS...
Medium CVE-2026-95818 libc6 2.36-9+deb12u13 β€” A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid...
Medium CVE-2025-69419 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte...
Medium CVE-2026-31790 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The...
Medium CVE-2026-34182 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various...
Medium CVE-2026-45445 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact...
Medium CVE-2026-63072 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that...
Medium CVE-2026-63076 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter...
Medium GO-2026-5491 github.com/tomwright/dasel/v2 v2.8.1 β€” Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string in github.com/tomwright/dasel
Medium GO-2026-4768 github.com/tomwright/dasel/v2 v2.8.1 β€” Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service in github.com/tomwright/dasel
Medium GO-2026-5493 github.com/tomwright/dasel/v2 v2.8.1 β€” Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal in github.com/tomwright/dasel
Low CVE-2010-4756 libc6 2.36-9+deb12u13 β€” The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do...
Low CVE-2018-20796 libc6 2.36-9+deb12u13 β€” In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\1\1|t1|\\2537)+' in grep.
Low CVE-2019-1010022 libc6 2.36-9+deb12u13 β€” GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl...
Low CVE-2019-1010023 libc6 2.36-9+deb12u13 β€” GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld...
Low CVE-2019-1010024 libc6 2.36-9+deb12u13 β€” GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc...
Low CVE-2019-1010025 libc6 2.36-9+deb12u13 β€” GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc...
Low CVE-2019-9192 libc6 2.36-9+deb12u13 β€” In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\1\1)*' in grep, a different issue than...
Low CVE-2025-15281 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member...
Low CVE-2026-0861 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could...
Low CVE-2026-4438 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS...
Low CVE-2025-27587 libssl3 3.0.17-1~deb12u3 β€” OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then...
Low CVE-2025-68160 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact...
Low CVE-2025-69418 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial...
Low CVE-2025-69420 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid...
Low CVE-2026-22795 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be...
Low CVE-2026-22796 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an...
Low CVE-2026-34180 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like...
Low CVE-2026-42766 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an...
Low CVE-2026-42767 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference...
Low CVE-2026-42770 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which...
Low CVE-2026-45446 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery...
Low CVE-2026-54874 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use...
Low CVE-2026-63074 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If...
Low CVE-2026-7383 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow...
Low CVE-2026-75803 libssl3 3.0.17-1~deb12u3 3.0.22-1~deb12u1 Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the...
Low CVE-2026-9076 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read...
---
Full changelog
  • [5e3cd5d] reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
  • [f6637da] use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • [e4d636d] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [a843330] refresh generated badges (stagefreight)
  • [141dc7a] forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • [2d01b3e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [63b7fe4] refresh generated badges (stagefreight)
  • [1b58d1b] restore the dashboard β€” fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
  • [f9ea201] update managed dependencies (stagefreight)
  • [6b1552e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [83c47d4] update managed dependencies (stagefreight)
  • [7a3145c] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [e9c1997] refresh generated badges (stagefreight)
  • [f95daa2] refresh generated badges (stagefreight)
  • [dbc0c76] enable corepack for yarn in the node 26 UI stage (SoFMeRight)
  • [c6fbb5d] bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
  • [93cef0f] select gitops-server.dockerfile as the image build target (SoFMeRight)
  • [d47c8c8] select gitops-server.dockerfile as the image build target (SoFMeRight)
  • [aff8418] hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
  • [7235b2f] scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
  • [ff94b32] add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
  • [a9ee3c2] update managed dependencies (stagefreight)
  • [0cc101a] pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
  • [f3bd9f8] update managed dependencies (stagefreight)
  • [8e8158a] clear audition freshness gate and restore the Go build (SoFMeRight)
  • [d58a8c1] remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
  • [11663cd] update managed dependencies (stagefreight)
  • [850ce24] update managed dependencies (stagefreight)
  • [6fcfa61] pass built message as argument, not format string (SoFMeRight)
  • [00b0c48] modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
  • [d20c1ba] bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
  • [d989edd] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [fad3e14] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [63d63a8] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [816e81a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [119a0f1] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [6dc2a8d] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [b4c60d5] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [57e79ed] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [e1aecd2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [5171c3e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [2fb494f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [918585a] fall back to chore, not docs, when a commit has no type (SoFMeRight)
  • [f335f0a] generate self-signed localhost cert at test time (SoFMeRight)
  • [091d849] bump frontend CVE deps within-major (SoFMeRight)
  • [7f754cf] bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
  • [c207c1e] Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)
  • [fdffb2b] name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
  • [8a39fa4] toolchains flag-day: want: wrapper + retention (SoFMeRight)
  • [1ed18d6] exclude vendored website/ docs tree from lint (SoFMeRight)
  • [ad83f84] prerelease publishes to all registries (match stable/dev) (SoFMeRight)
  • [ce0c4df] migrate to current stagefreight schema + canonical suite (SoFMeRight)
  • [cc6668d] add StageFreight pipeline β€” build the weave-gitops webapp from upstream main (SoFMeRight)
  • [936e848] do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)