Skip to content

distributed-cache-runtime 5.7.3-pasturestack.2

Choose a tag to compare

@chen21019 chen21019 released this 24 Aug 07:07
· 5 commits to main since this release
Immutable release. Only release title and notes can be modified.

distributed-cache-runtime 5.7.3-pasturestack.2

This release is built from commit 520a6d217e8809bd2a0d44ecbae5a8bcdb958b2c and the SSH-signed annotated tag v5.7.3-pasturestack.2.

Runtime baseline

  • Apache Kafka: 4.3.1
  • Spring Boot primary lane: 4.1.1
  • Spring Framework primary lane: 7.0.9
  • Spring Boot compatibility lane: 3.5.16
  • Spring Framework compatibility lane: 6.2.19
  • Elasticsearch Java Client: 9.5.1
  • Debezium: 3.6.1.Final
  • Hadoop: 3.5.0
  • Build and verification JDK: Eclipse Temurin 25.0.4.1 LTS
  • Jetty artifacts in the resolved dependency graph: 0

Verified artifacts

  • JAR SHA-256: 6abb7d619f6ea57c52f04e8d4ebace83e731cfe89e6f5cd528ca7e6ce6b7b83b
  • OCI archive SHA-256: 9ab9633e10d2356b653c08700f46dfb1c75e5e44fb3873d73649793c343da570
  • GHCR manifest digest: sha256:80ee5f3f8f835c7f31e21100fb758d9632a5d239c3f7f4a379df7f9f4bcfab12
  • Image config ID: 3a07a0a491105206c83c3ea90d9eaea93defdc668333602a56af4c828d55fe68
  • Image revision label: 520a6d217e8809bd2a0d44ecbae5a8bcdb958b2c
  • GHCR tags: 5.7.3-pasturestack.2 and 5.7.3

The OCI artifact is a deterministic JAR carrier for this library/runtime distribution. It is not the PastureStack HTTP server image and must not replace the service on port 8080.

Validation

Supply-chain controls

  • main requires the security gate and all four CodeQL checks, strict status checks, one approving review, CODEOWNERS, last-push approval, signed commits, administrator enforcement and linear history.

  • Force pushes and branch deletion are disabled.

  • Repository immutable releases are enabled.

  • The release tag is SSH signed. Verify it with:

    git -c gpg.format=ssh -c gpg.ssh.allowedSignersFile=RELEASE-ALLOWED-SIGNERS tag -v v5.7.3-pasturestack.2

Honest limits

  • GitHub currently displays the commit signature as unknown_key because the public SSH key is not registered with GitHub as a signing key. Independent verification succeeds with the included RELEASE-ALLOWED-SIGNERS file.
  • GitHub SLSA provenance is not emitted by this release pipeline. The signed tag, immutable release, artifact hashes, SBOMs, Trivy results and CI evidence are the available provenance controls.
  • Cloud provisioning and multi-node production upgrade tests are conditional deployment checks and were not run because this release does not provision AWS, Azure or GCP infrastructure.