Skip to content

PastureStack Server v1.6.486

Choose a tag to compare

@github-actions github-actions released this 28 Sep 16:21
Immutable release. Only release title and notes can be modified.
ee44a07

Server v1.6.486

Server v1.6.486 packages released Web Console 1.6.152 on the unchanged
Server v1.6.460 runtime base and Orchestration Engine v0.183.326. The
Web Console tag resolves to merged commit
dae731085d00f209ad4ee9419acd21d0b6d64f2a; release asset
web-console-1.6.152.tar.gz has SHA-256
56c147e392d40395690e925e0d8590e44de90bd7d6aaa3e6076ca75f30341486.
The Server build verifies that asset and VERSION.txt=1.6.152. Web Console
main validation run 36446151881 passed its complete source gates and two
production builds on that commit.

The only product behavior change is the required-name error in Stack,
Service, and Container forms: it now uses the same visible translated label
as the input. Isolated Server v1.6.485 browser QA found four Chinese/Japanese
Stack mismatches. Earlier Service/Container browser cases exercised shared
memory errors but did not submit blank names; those cells remain untested.
There is no API, authorization, request-payload, or runtime component change.

Source and Web Console artifact checks are
not proof of a v1.6.486 image, browser acceptance, or six-role QA.
Publication requires an immutable Server
build with final merged-rootfs vulnerability/SBOM checks and first-boot/restart
health. Isolated 8080 browser QA must then verify zh-TW, en-US, and ja-JP
Stack/Service/Container blank-name errors at desktop and narrow widths, with
zero writes on invalid submission. Do not infer a complete all-resource ID
write-permission matrix from that localized check.

The OpenVEX statements are carried forward with a new document identity.
Official publish run 36448043632 stopped at the exact-set
merged-rootfs vulnerability gate before publishing an image: Trivy 0.74.0
reported two additional unresolved Medium occurrences of CVE-2026-86145
in Ubuntu 26.04 libpcre2-8-0 and libpcre2-posix3 at 10.46-1build1,
both with no FixedVersion. The vendor-pending register now records those
exact package/CVE pairs for review by 2026-10-20; the unfiltered scan and
exact-set gate remain required. Canonical marks the Ubuntu 26.04 pcre2
package vulnerable
; the
register's needs-evaluation is this project's expiring review state, not
Canonical's package status. This does not claim the issue is fixed or absent.

Rollback uses the previous immutable Server v1.6.485 digest with the same
volumes, origin, restart policy, and AppArmor configuration. Production
stack.ascdc.tw is outside this isolated QA rollout.