Releases: ori-platform/ori-runtime
Release list
v2.5.0-rc.10
Signed Ori Runtime release v2.5.0-rc.10.
v2.5.0-rc.8
Signed Ori Runtime release v2.5.0-rc.8.
Security
This candidate exists to carry one fix, coordinated as GHSA-rv38-92xc-7xq8.
A trust anchor is authority only while its private half is secret. This repository commits Ed25519 seeds as test material, and two trust boundaries accepted a public key derived from one. The runtime now refuses such a key at every deployment profile, because a development runtime drives the same relay as a production one.
What your release means for you. Configuration-signature verification has existed since v2.0.0 and is unguarded in every published release up to v2.5.0-rc.7. The commissioning anchor arrived after rc.7 was tagged and first ships here, already guarded — so a device on v2.4.x or earlier has no commissioned safety binding to forge.
This is a guard against a misconfiguration, not a shipped default. No installer, document or example ever configured such a key; anchors are written out of band. You are affected only if you deliberately put test material into a real deployment.
Upgrade-breaking if you did. A device whose commissioning anchor is a published key now refuses to start rather than starting on a forgeable authority, which costs detection and alerting as well as actuation. Rotate to a key that has never left the producer, and remove the old one from both the current and previous anchor slots. A published configuration-signing anchor refuses when a signed configuration is required or present — audit that value directly rather than inferring from a clean start, since an unsigned development config may never reach that verification.
The issue was found during an internal audit of a bench device's anchor configuration, not reported from outside the project. The one device known to carry a published anchor was rotated, and no other device is known to have been configured with one.
Two sibling boundaries in the same class are tracked openly rather than quietly: #545 and #546. Neither has run in a production deployment.
v2.5.0-rc.7
Signed Ori Runtime release v2.5.0-rc.7.
v2.5.0-rc.6
Signed Ori Runtime release v2.5.0-rc.6.
v2.5.0-rc.5
Signed Ori Runtime release v2.5.0-rc.5.
v2.5.0-rc.3
Signed Ori Runtime release v2.5.0-rc.3.
v2.4.0
v2.4.0-rc.6
Signed Ori Runtime release v2.4.0-rc.6.
v2.4.0-rc.4
Signed Ori Runtime release v2.4.0-rc.4.
v2.4.0-rc.3
Signed Ori Runtime release v2.4.0-rc.3.