Skip to content

v1.8.0

Latest

Choose a tag to compare

@github-actions github-actions released this 29 Sep 21:37
· 4 commits to main since this release
Immutable release. Only release title and notes can be modified.
v1.8.0
c8bc050

v1.8.0 adds an animated wizard gopher to the login page.

Animated wizard on the login page

The login page shows a cel-shaded wizard gopher that follows the pointer and performs a staff strike when it is activated or the login form is submitted (#690 by @jonasgwozdz). On submit the native POST waits for 1.4 seconds of animation progress and then replays once with its original submitter and CSRF field. A four-second safety deadline releases the login if rendering stalls, and hidden, removed, paused or failed avatars release it at the next timer check, so the animation cannot block authentication. Reduced motion and unavailable WebGL 2 submit immediately, and the application logo stays as the fallback without JavaScript. The avatar reads no credentials. Three.js 0.186.1 is vendored and served locally under the existing CSP.

Tests and CI

@CybotTM added the companion's browser checks to CI and changed the E2E login helper to wait for the resulting navigation instead of sleeping a fixed 500 ms, which the delayed submit had broken (#690). The repository also carries an OpenSSF Best Practices answer file (#692).

Full changelog: v1.7.0...v1.8.0

Container image

ghcr.io/netresearch/ldap-manager:1.8.0
ghcr.io/netresearch/ldap-manager:1.8
ghcr.io/netresearch/ldap-manager:1

Verify your download

Per-asset signatures are bundled. Verify any single file:

cosign verify-blob \
  --bundle ldap-manager-linux-amd64.sigstore.json \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ldap-manager-linux-amd64

Verify checksums against the signed manifest:

cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  checksums.txt
sha256sum -c checksums.txt --ignore-missing

Verify build provenance. Releases are built by a reusable
workflow, so the signing identity is that workflow rather than
this repository -- --signer-workflow is required and
verification fails without it:

gh attestation verify <artifact> \
  --repo netresearch/ldap-manager \
  --signer-workflow netresearch/.github/.github/workflows/release-go-app.yml

Verify container image:

cosign verify ghcr.io/netresearch/ldap-manager:1.8.0 \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"
gh attestation verify oci://ghcr.io/netresearch/ldap-manager:1.8.0 \
  --repo netresearch/ldap-manager \
  --signer-workflow netresearch/.github/.github/workflows/release-go-app.yml