Skip to content

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 16:51
· 51 commits to main since this release
0784eef

Praxis 1.0.0 release index

Container images

Image Digest Tags
ghcr.io/cytechlabs/praxis-backend sha256:c3b6f2c608f6c944c50a946aeb232a8c54e173131d0414f59c9212e526d62dae 1.0.0, 1.0, latest
ghcr.io/cytechlabs/praxis-frontend sha256:0a46197797605525465f23182ffb02d9d6f3056985bd664b2a6dce9bcedf5b12 1.0.0, 1.0, latest

Tags move between releases; digests do not. Deploy the digest:

docker pull ghcr.io/cytechlabs/praxis-backend@sha256:c3b6f2c608f6c944c50a946aeb232a8c54e173131d0414f59c9212e526d62dae
docker pull ghcr.io/cytechlabs/praxis-frontend@sha256:0a46197797605525465f23182ffb02d9d6f3056985bd664b2a6dce9bcedf5b12

Image SBOMs

  • sbom-backend-1.0.0.cdx.json (CycloneDX 1.6) for praxis-backend
  • sbom-frontend-1.0.0.cdx.json (CycloneDX 1.6) for praxis-frontend

Verifying an image

gh attestation verify oci://ghcr.io/cytechlabs/praxis-backend@sha256:c3b6f2c608f6c944c50a946aeb232a8c54e173131d0414f59c9212e526d62dae \
    --repo cytechlabs/praxis

The same command verifies each image above. It checks the build
provenance and the SBOM attestation, both issued to this repository's
release workflow through GitHub OIDC. There is no long lived signing
key to distribute or rotate.

Fleet agent

Published under agent-v1.0.0: https://github.com/cytechlabs/praxis/releases/tag/agent-v1.0.0

Artifact SHA-256
praxis-agent-v1.0.0-linux-amd64-sbom.cdx.json 78ab682be729d4326e5b71f6960b01e4e0639efc4af8a22b2b4708592c5f04e8
praxis-agent-v1.0.0-linux-amd64.tar.gz 5cb932f6c899e78dc7e9fe1c470b8654dcb3a09f8243ccd6a53606eb3edcf071
praxis-agent-v1.0.0-linux-arm64-sbom.cdx.json cd80459957605087c6f50cd4448bd67c1bbf8c47b328e25496ff76588dd49991
praxis-agent-v1.0.0-linux-arm64.tar.gz 76ceb67de5164f04e42753dd114d7da97d3d0338393499f4be1055e9fc6cab93

checksums.txt is signed with keyless Sigstore. Verify it with checksums.txt.sig and checksums.txt.pem from that release before trusting the checksums above.

Security gates

Gate Status Detail
source verification passed Backend migrations and tests plus frontend lint and type check ran against this commit.
release readiness passed Package metadata across the repository matches the release version.
container vulnerability scan passed Trivy found no unaccepted CRITICAL findings in the archived images that were promoted.
image sbom binding passed Each SBOM was generated from, and checked against, the published image digest.

Reports

What's Changed

  • ci: bump the github-actions group with 10 updates by @dependabot[bot] in #4
  • Harden the 1.0 security baseline and enforce DeepSource cleanup by @cfreeman29 in #7
  • Harden dependencies and complete semantic UI migration by @cfreeman29 in #8
  • Prepare reproducible Praxis release artifacts by @cfreeman29 in #12
  • Publish the Praxis documentation experience by @cfreeman29 in #13
  • Correct the production broker healthcheck by @cfreeman29 in #17
  • Align the default group ID sequence by @cfreeman29 in #18

New Contributors

Full Changelog: https://github.com/cytechlabs/praxis/commits/v1.0.0