Privateerr v1.0.2 is a backward-compatible maintenance release that synchronizes the stable release line with the latest passing main commit.
Fresh Provenance Rigging 🧾
- Refreshes the pinned
actions/attest-build-provenancedigest used by the multi-architecture release workflow. - Keeps the provenance step on its reviewed v4 release while preserving the existing SBOM, attestation, GHCR, Docker Hub, and Buccaneerr publication flow.
- Retains exact Action digest pinning so the release supply chain cannot drift silently.
Runtime and Upgrade Impact ⚓
Privateerr runtime behavior is unchanged from v1.0.1. There are no environment-variable, generated-file, WireGuard, Gluetun metadata, mount, healthcheck, or port-forwarding changes, and no migration or regeneration is required.
The release remains compatible with current Plundarr stacks that use the image-owned privateerr-healthcheck command introduced in v1.0.1.
Published Images 📦
The release workflow published Privateerr tags 1.0.2, latest, and sha-26c86b4 to GHCR and mirrored them to Docker Hub. The registries expose matching Privateerr manifest digest sha256:12842009d40dc0b080958be6bdbbaa06a4627513273be97f40f501756079034e.
The companion Buccaneerr image was published to GHCR with matching release, latest, and commit-SHA channels at manifest digest sha256:eb19cf5ff229166199a8c68b3ffdc6bbb00261f4ba71e555750cae9b5204d163. Both images support linux/amd64, linux/arm64, and linux/arm/v7 with SBOM and provenance.
Validation 🧪
The release target is the passing main commit 26c86b4. The Actions validation, registry build, and OpenSSF Scorecard workflows completed successfully for that commit.
Merged Change 📜
- #43: Update the build-provenance Action digest.
Full Changelog: v1.0.1...v1.0.2