Skip to content

Kafdeck v0.5.1 — Release Integrity Corrections

Choose a tag to compare

@github-actions github-actions released this 23 Sep 15:59
e5de0ec

Kafdeck v0.5.1 — Release Integrity Corrections

Kafdeck v0.5.1 is a scope-neutral corrective patch for the v0.5 release line. It publishes the already-reviewed release-integrity fixes under a new immutable identity while preserving the original v0.5 tag, GitHub Release and OCI artifacts unchanged.

Corrections

  • backend assembly/package identity is aligned with the governed release manifest at 0.5.1,
  • frontend package and lockfile identity are aligned at 0.5.1,
  • /api/v1/system/info now reports controlledMutations only when mutation mode is actually enabled and otherwise reports readOnly,
  • README/roadmap release-state wording is reconciled with the released v0.5 capability set,
  • release-identity regression coverage verifies manifest/package consistency and preserves prerelease suffixes.

Scope and safety

This patch adds no new mutation class, provider surface or product scope. All v0.5 safety and governance invariants remain unchanged:

  • read access does not imply mutation permission,
  • mutation mode remains opt-in and fail-closed,
  • server-owned risk floors and independent approval for CRITICAL operations remain enforced,
  • durable mutation state/idempotency/claims remain mandatory,
  • ambiguous potentially-applied outcomes remain ExecutionUnknown unless bounded verification proves a stronger state,
  • raw Kafka payloads and secrets are not durably staged by default,
  • no generic Kafka CLI/AdminClient/provider REST proxy or arbitrary server-side code execution is introduced.

Publication integrity

The published v0.5 identity remains immutable and is not moved, replaced or republished. Corrected artifacts are published only as v0.5.1 from the exact protected-main source revision admitted for this patch.

Publication remains gated by the repository release workflow: exact-revision quality checks, Kafka compatibility, SBOM generation, High/Critical vulnerability scanning, keyless signing, immutable OCI digest promotion and GitHub Release creation must all complete successfully.

Immutable OCI image

ghcr.io/araditc/kafdeck@sha256:3204fb92fa800a40c246ee94d279dfb7557cd211f6de7157ebbad8b223da0290

SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA e5de0ec142d5dd06ef52f59718c60c3109d1070a.