Skip to content

Dapple 0.4.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 23:26
7ee1ba7

A security release. How Dapple is built now uses only exact, verified ingredients, so a compromised download or build tool somewhere upstream can't slip code into your install. Nothing about how Dapple works has changed.

What's changed

  • Every part of the build is locked to an exact, checked version. That covers the build tools GitHub uses to make the image, the base images, and every Python and JavaScript package. Each download has to match a fingerprint recorded in advance, or the build stops. Before, some of these always fetched whatever was newest.

  • Each image says what it was built from. Images now carry a record of the exact source code and build that produced them, plus a list of every package inside. Most people never need this, but it lets anyone check an image, or see straight away whether a newly announced security problem affects Dapple:

    docker buildx imagetools inspect afraley/dapple:0.4.1 --format '{{ json .Provenance }}'
  • latest now means the newest release. The latest image changes only when a new version comes out, with release notes saying what changed. Before, other behind-the-scenes changes could update it with no release at all.

  • Updates only when you choose. The README now explains how to stay on a particular version instead of taking the newest one every time you run docker compose up -d.

Upgrading

docker compose up -d picks this up if you have pull_policy: always. Otherwise run docker compose pull && docker compose up -d. Your settings and saved presets carry over. To stay on this release, set the image line to:

    image: afraley/dapple:0.4.1