ExitLane v0.2.0-beta.5
Summary
ExitLane 0.2.0-beta.5 is a release-assurance and installation-hardening prerelease.
This release:
- contains the complete beta.4 UX, accessibility, design-system and integrated-documentation baseline;
- restores the release-governance chain that prevented beta.4 from being published;
- strengthens required checks and automatic CodeQL validation on
main; - adds clean-install evidence for the supported Debian 13
amd64appliance baseline; - therefore marks an important beta milestone.
The candidate was qualified through required hosted checks, an independent pre-merge APPROVE, a clean installation on Debian 13 amd64, and repeated local, hosted and appliance validation on the exact merged main commit.
Release governance and security
- The active
mainruleset requires the exact CI, CodeQL, supply-chain and ZAP job contexts and requires the branch to be current before merge. - CI, CodeQL, supply-chain and ZAP validation run on pull requests and automatically on every relevant push to
main. - Repository Actions policy requires full commit-SHA references, permits GitHub-owned actions and explicitly allowlists only the external Gitleaks action used by the current workflows.
- A deterministic workflow-security check prevents mutable Action references and accidental removal of any required final-main trigger.
- The release record distinguishes pre-merge PR evidence from new hosted final-main evidence and does not reuse older green runs for a newer commit.
Supported installation evidence
- The supported beta.5 appliance baseline is Debian 13 on
amd64. Debian 12 is not a supported beta.5 release target. - Clean-install evidence covers prerequisites, installer and package versions, first service start, health, first-run routing, database initialization, filesystem permissions, systemd units, WireGuard prerequisites, onboarding entry, stop/start resume, injected rollback and idempotent rerun.
- The installer explicitly supplies
procpsand thesysctl.dpath required to configure IPv4 forwarding on an otherwise minimal supported Debian installation. - The existing beta.4 appliance was upgraded transactionally with exact merged-main source and retained its database, key, user/session/settings state, VPN cache and WireGuard configurations. An idempotent rerun and injected-failure automatic rollback also passed.
- No real Speedtest was run during this release qualification.
Inherited beta.4 baseline
Beta.5 includes beta.4's Cobalt / Slate interface theme, UX and accessibility polish, authenticated integrated documentation, contextual help links, Diagnostics hierarchy improvements and related security regressions. These are inherited capabilities rather than new beta.5 feature claims.
Release evidence
- Pull request: #57
- Final PR head:
dd0d781f5b99ead8f83887947939c835655675b7 - Merged
main:6f00b346bfd39b6ae4ed2970728d3589f67b39ed - Qualified tree:
3a9176c3840c8eac60b052876782feae6e568600 - Annotated tag object:
3d137872b81410e48b838a809ee9a5910580f817 - Independent review:
APPROVEon the exact final PR head - Debian 13 clean-install evidence: LXC 123 evidence
- Final merged-main and appliance evidence: qualification record
- Final-main runs: CI 32860427841, CodeQL 32860427724, supply chain 32860427758, ZAP 32860427726
Limitations
ExitLane remains beta software for a trusted management network and must not be exposed directly to the public Internet. There is no signed automatic-update channel. A real Safari/WebKit runtime was not available for the inherited browser qualification; no compatibility defect is known and the existing responsive regression evidence remains the recorded residual limitation.