Repository navigation
Releases: foundata/conclear
Releases · foundata/conclear
Release list
v2.0.0
Changed
- The release profile names the signing passphrase file
cosign_passphrase_file
instead ofpassphrase_file, and the option supplying it on the command line
is--cosign-passphrase-fdinstead of--passphrase-fd. Both now say which
key they unlock, so a further passphrase can be added later without renaming
this one. - The release profile schema is version 2. Rename the key in
~/.config/conclear/<profile>.tomland setschema_version = 2; a profile
still declaring version 1 is rejected and names the edit it needs.
Fixed
- Reading a published image graph back from the registry retries a transient
transport error like every other registry read. A single interrupted download
no longer fails a release whose candidate was already published.
v1.1.0
Added
- Trivy and Hadolint can run from their publishers' images instead of host
executables: name them inCONCLEAR_TOOL_IMAGES. Each image is pinned by its
index digest, Trivy's publisher signature is verified, and records name the
pinned index and the platform manifest that ran. The supported-tools table and
the compatibility inventory name each pinned image. - Commands narrate what they do on stderr: the phase under way and every
external command that ran, verb first, coloured only on a terminal. Stdout
stays the result.-q/--quietbefore the command drops the narration but
never an error.python -m conclear.release_checkannounces its steps there
too instead of on stdout, so its stdout is now empty. - The compatibility inventory lists the root group as
conclearwith its own
options,--versionand--quiet, which it had left out. CC0507rejects Java artifacts assessed against an expired Trivy Java
database, and--accept-stale-java-databaseonqualify,releaseand
rescanaccepts that risk for one invocation. Qualification,
release-candidate and rescan records carry the verdict asjavaDatabase
beside the artifact count.doctor --scope qualifyand--scope releasereport the installed Trivy
database's freshness asdatabaseand warn withCC0507when the Java
database has expired, before any image is built. The snapshot is only read,
never refreshed.- Rescan records name the Java artifacts of each platform as
scanResults[].javaArtifacts, so a multi-platform image shows which platform
the Java database verdict applies to.
Fixed
rescanreports the record's findings in its command result, located by
platform. A rejected rescan previously returned the rejection status with an
empty findings list, so the reason was only in the record.
Changed
- The real-tool tested versions are Buildah 1.43.4, Podman 5.8.7 and Skopeo
1.22.3, the versions this release's real-tool tier ran against. The accepted
ranges are unchanged. - The Java database's freshness gates a qualification only when the SBOM
inventories Java artifacts (pkg:mavenpackage URLs). An expired Java
database no longer blocks images that contain no Java.CC0505continues to
require a fresh vulnerability database and now names it. - A database refresh that cannot reach its publisher no longer fails a run whose
installed snapshot already carries a fresh vulnerability database. The
snapshot is kept and its Java component's age stays recorded. A refresh
failure without such a snapshot still fails the run. - The release gate runs the Markdown style guide's current invocation and needs
rumdl0.2.72 or later, the version the guide documents.MD090and the
front-matter key order are now enforced, andMD080anchor collisions are
limited to heading levels 1 and 2.
v1.0.2
Changed
python -m conclear.release_checkwritesartifacts.jsonin the shared
releasingmanifest format. It now names the version and the repository, and
spells digests as bare hex the way a package index serves them.
conclearRevisionbecamesourceRevision;guideRevisionstayed.
v1.0.1
Fixed
- The package page on PyPI resolves its links. The description shipped with
1.0.0 kept the README's repository-relative destinations, so all links and
images on that page pointed nowhere. No functional or runtime code changes.
v1.0.0
First public release, added all functionality and files.