Skip to content

0.3.332

Choose a tag to compare

@github-actions github-actions released this 30 Sep 01:52
· 76 commits to main since this release
42088fe

0.3.332

Security fix — JWT credential leak in snowplow (upgrade recommended)

snowplow 1.12.21 → 1.12.22 closes a live credential leak (#271). When a
nil endpoint-ref PREWARM stage carried a Krateo authn JWT and targeted the
ServiceAccount endpoint, bearerAppendForStage injected that JWT into the
Authorization header before the SA token round-tripper ran. Because
client-go's bearer transport will not overwrite an existing Authorization
header, the k8s BearerTokenFile token was never sent — the apiserver received
a user's RS256 JWT instead, logged it in the audit log, and returned 401.
Measured at ~720 SAR-401s per 20 minutes from a single pod. The fix gates the
JWT append on isSA=false; SA paths are unaffected in behaviour.

Three additional snowplow fixes in the same release:

  • #216 — fires the gone-forget hook on a confirmed-404 self-eviction, so a
    deleted resource no longer continues to be served from the harvested copy.
  • #279 — records the LIST fanout edge on an iterator-empty resolve; the
    ns="" scope over-marks but is never incorrect (a design hardening is planned
    separately).
  • #288 — guards empty-interpolated and DNS-invalid dial targets, closing
    two of three shapes of a //-fallback bug whose source is portal content
    (~1 026 futile apiserver round trips per 20 minutes, all
    continueOnError-swallowed). The sentinel shape (none.krateo.io/v1)
    cannot be closed in snowplow.

Other component bumps

  • frontend 1.6.78 → 1.6.79 — one CSS change: 8 px spacing before the rail
    brief.
  • krateo-autopilot 0.6.0 → 0.6.1 — one prompt paragraph: the orchestrator
    now briefs a page to frontend-agent in the user's words rather than widget
    kind names. Pairs with frontend-agent 1.5.3 (already live).

All five pins are in chart/files/component-pins.yaml.