Skip to content

stable-20260720: LTS

Choose a tag to compare

@github-actions github-actions released this 20 Jul 05:15
e44fb4b

Variants promoted

Variant Tag Digest
bluefin-lts :stable sha256:c6dbad5db01b
bluefin-lts-nvidia :stable sha256:d9e0b0ef0304

bluefin-lts and bluefin-lts-nvidia use the Fedora CoreOS stable kernel. The Kernel (LTS) version above applies to both.


Release card

Key components

Component Version Change
Kernel (LTS) 7.0.12-201
GNOME Shell 50.0-3.el10
Flatpak 1.18.0-1.el10
bootc 1.16.2-1.el10

1 updated since the previous release. 1497 packages total.

Package changes

↑ 1 updated packages
Package From To
mbedtls 3.6.6-1.el10_3 3.6.7-1.el10_3

Desktop Screenshot

Bluefin LTS desktop — stable-20260720

Captured from bluefin-lts:testing during automated e2e validation — testsuite

Supply chain verification

Supply chain

This image is signed, attested, and ships a full SPDX-JSON SBOM.
Every artifact below is verifiable without trusting this release page.

Tools required — install via Homebrew or see links in each section:

brew install cosign oras slsa-verifier

1 — Verify the image signature

cosign (Sigstore) verifies the keyless
OIDC signature created by GitHub Actions at build time.

cosign verify \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c6dbad5db01b40dbb196de82d941c9454dbe3e89a437960770c8d5878c98f4a2

A valid response lists the certificate subject and OIDC issuer. Any tampered
image will produce a verification error.


2 — Fetch and inspect the SBOM

The SBOM (SPDX 2.3 JSON) is attached to the image as an
OCI referrer using
ORAS (CNCF graduated project).

# Discover the attached SBOM referrer
oras discover \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c6dbad5db01b40dbb196de82d941c9454dbe3e89a437960770c8d5878c98f4a2

# Pull the SBOM to disk (replace SBOM_DIGEST with the digest from above)
oras pull \
  --artifact-type application/vnd.spdx+json \
  ghcr.io/projectbluefin/bluefin-lts@<SBOM_DIGEST>

The SBOM is also attached to this release as
bluefin-lts.spdx.json.


3 — Verify the SBOM attestation

The SBOM is also stored as a signed
GitHub SBOM attestation
in the Sigstore transparency log.

cosign verify-attestation \
  --type https://spdx.dev/Document \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c6dbad5db01b40dbb196de82d941c9454dbe3e89a437960770c8d5878c98f4a2 \
  | jq -r '.payload | @base64d | fromjson | .predicate.name'

4 — Verify SLSA Build L2 provenance

slsa-verifier (OpenSSF)
checks that this image was built by the expected workflow on the expected
source repository — not on a developer's laptop or a forked CI runner.

slsa-verifier verify-image \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c6dbad5db01b40dbb196de82d941c9454dbe3e89a437960770c8d5878c98f4a2 \
  --source-uri 'github.com/projectbluefin/bluefin-lts' \
  --source-versioned-tag 'stable-20260720'

You can also inspect the raw provenance:

cosign verify-attestation \
  --type slsaprovenance1 \
  --certificate-identity-regexp '^https://github\.com/projectbluefin/(bluefin-lts|actions)/\.github/workflows/' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  ghcr.io/projectbluefin/bluefin-lts@sha256:c6dbad5db01b40dbb196de82d941c9454dbe3e89a437960770c8d5878c98f4a2 \
  | jq -r '.payload | @base64d | fromjson | .predicate'

Full changelog and verification guide → https://docs.projectbluefin.io/changelogs

Full changelog → https://docs.projectbluefin.io/changelogs