Across Orchestrator v0.10.8
Relay security remediation release.
- Refreshes Alpine packages in the final Relay image before runtime installation.
- Resolves the SQLite vulnerabilities that correctly blocked v0.10.7 Relay publication.
- Preserves the strict HIGH/CRITICAL Trivy publication gate, signed digest, SBOM, and provenance requirements.
- Keeps the portable MCP schema, provenance, and sandbox hardening from v0.10.7.
Validated by 311 tests, 14 subtests, CLI smoke, sensitive-path scanning, uv lock consistency, package dry-run, CodeQL, and GitHub Quality CI. The tag targets the exact origin/main release commit.