distributed-cache-runtime 5.7.3-pasturestack.2
·
5 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
distributed-cache-runtime 5.7.3-pasturestack.2
This release is built from commit 520a6d217e8809bd2a0d44ecbae5a8bcdb958b2c and the SSH-signed annotated tag v5.7.3-pasturestack.2.
Runtime baseline
- Apache Kafka:
4.3.1 - Spring Boot primary lane:
4.1.1 - Spring Framework primary lane:
7.0.9 - Spring Boot compatibility lane:
3.5.16 - Spring Framework compatibility lane:
6.2.19 - Elasticsearch Java Client:
9.5.1 - Debezium:
3.6.1.Final - Hadoop:
3.5.0 - Build and verification JDK: Eclipse Temurin
25.0.4.1LTS - Jetty artifacts in the resolved dependency graph:
0
Verified artifacts
- JAR SHA-256:
6abb7d619f6ea57c52f04e8d4ebace83e731cfe89e6f5cd528ca7e6ce6b7b83b - OCI archive SHA-256:
9ab9633e10d2356b653c08700f46dfb1c75e5e44fb3873d73649793c343da570 - GHCR manifest digest:
sha256:80ee5f3f8f835c7f31e21100fb758d9632a5d239c3f7f4a379df7f9f4bcfab12 - Image config ID:
3a07a0a491105206c83c3ea90d9eaea93defdc668333602a56af4c828d55fe68 - Image revision label:
520a6d217e8809bd2a0d44ecbae5a8bcdb958b2c - GHCR tags:
5.7.3-pasturestack.2and5.7.3
The OCI artifact is a deterministic JAR carrier for this library/runtime distribution. It is not the PastureStack HTTP server image and must not replace the service on port 8080.
Validation
- Security release gate: 38 suites, 385 tests, 0 failures, 0 errors, 0 skipped.
- Source, artifact, dependency and secret scans: Critical 0, High 0.
- Final local Trivy image and JAR scans: Critical 0, High 0, Medium 0, Low 0, Unknown 0.
- CycloneDX image and JAR SBOMs: specification 1.7, serial numbers present, 23 components, 24 dependency nodes, 0 vulnerability records.
- Maven runtime SBOM: 15 components, 16 dependency nodes, no missing, unexpected or dangling references.
- Default CodeQL workflow passed for actions, C/C++, Java/Kotlin and Python; open code-scanning alerts: 0.
- Security release gate: https://github.com/PastureStack/distributed-cache-runtime/actions/runs/32698363829
- CodeQL: https://github.com/PastureStack/distributed-cache-runtime/actions/runs/32698363371
Supply-chain controls
-
mainrequires the security gate and all four CodeQL checks, strict status checks, one approving review, CODEOWNERS, last-push approval, signed commits, administrator enforcement and linear history. -
Force pushes and branch deletion are disabled.
-
Repository immutable releases are enabled.
-
The release tag is SSH signed. Verify it with:
git -c gpg.format=ssh -c gpg.ssh.allowedSignersFile=RELEASE-ALLOWED-SIGNERS tag -v v5.7.3-pasturestack.2
Honest limits
- GitHub currently displays the commit signature as
unknown_keybecause the public SSH key is not registered with GitHub as a signing key. Independent verification succeeds with the includedRELEASE-ALLOWED-SIGNERSfile. - GitHub SLSA provenance is not emitted by this release pipeline. The signed tag, immutable release, artifact hashes, SBOMs, Trivy results and CI evidence are the available provenance controls.
- Cloud provisioning and multi-node production upgrade tests are conditional deployment checks and were not run because this release does not provision AWS, Azure or GCP infrastructure.