Skip to content

PastureStack Server v1.6.493

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:46
Immutable release. Only release title and notes can be modified.
dc17c6f

Server v1.6.493 candidate

This candidate packages Web Console 1.6.159 on the unchanged Server
v1.6.460 runtime base and Orchestration Engine v0.183.326, with a narrow
official Ubuntu OpenSSL security-package refresh described below.
Web Console source commit aab95cf41ebc45e4c51513d9589602ab990399c9
includes merged PR #135
and PR #136.
Official validation run 36686121660 passed with 723/723 tests and matching
deterministic production builds. Its published release asset is
web-console-1.6.159.tar.gz, containing VERSION.txt=1.6.159.
The official archive SHA-256 is f014083480e10430701e3a08588cf617242188938d9f935fbaac42a3b5feeb90.
No v1.6.493 image or packaged browser acceptance is established yet.

Isolated v1.6.492 QA caught an existing Registry credential GET returning
secretValue: null on both API versions. The old editor sent that masked value
back even on a username-only edit. The fixed browser editor omits blank,
missing and null passwords, sends only an explicitly entered nonempty
replacement, and preserves its literal whitespace through form validation.
It explains blank-keeps-existing behavior in English, Traditional Chinese and
Japanese. Fresh credential, parent-registry, selected-project and current
capability guards remain unchanged, as do missing-credential POST recovery,
Server authorization, OIDC/MFA, sessions and proxy behavior.

The first candidate publication run 36688080817 was correctly stopped before
push by the rootfs security gate. Ubuntu USN-8847-1
provides fixed OpenSSL packages at 3.5.5-1ubuntu3.6, including the High
CVE-2026-84782. The signed HTTPS Ubuntu snapshot 20260930T000000Z
pins openssl, libssl3t64 and openssl-provider-legacy at that exact version.
Installing all three replaces the previously source-built 3.5.8 CLI,
libraries, engines and legacy provider, rather than only changing package
metadata. Assembly and post-build gates verify the seven runtime files against
SHA-256 checksums extracted from the signed official packages,
matching CLI/library version, provider paths and curl/MariaDB linkage. The
existing curl 8.18.0-1ubuntu2.7 fix is retained in the same package stage.
This is not a new VEX exclusion or a vendor-pending exception; the existing
eight Medium vendor-pending findings and security thresholds are unchanged.
The replacement candidate still requires the normal artifact/runtime gates.

Focused headless Chrome QUnit tests passed 7/7, and localization source checks
passed. Same-major build/test patches for brace-expansion and Engine.IO passed
the unchanged High/Critical audit threshold and focused compatibility probes;
remaining Moderate findings are not declared fixed. The official archive is
published at the numeric 1.6.159 tag; the immutable Server image,
first start/restart, isolated
browser cancel/save/refresh, DB password preservation, dual-root exact-ID
authorization and disposable fixture cleanup are separate pending gates.
No full role/resource matrix completion or formal company-site deployment is
claimed. Keep the prior immutable image with its original volumes and runtime
settings for rollback. Vendor-pending findings remain registered unchanged;
they are not declared fixed by this release.