Skip to content

Privateerr v1.0.2 — Provenance Gets a Fresh Coat 🏴‍☠️

Latest

Choose a tag to compare

@scottgigawatt scottgigawatt released this 12 Aug 03:33
Immutable release. Only release title and notes can be modified.
26c86b4

Privateerr v1.0.2 is a backward-compatible maintenance release that synchronizes the stable release line with the latest passing main commit.

Fresh Provenance Rigging 🧾

  • Refreshes the pinned actions/attest-build-provenance digest used by the multi-architecture release workflow.
  • Keeps the provenance step on its reviewed v4 release while preserving the existing SBOM, attestation, GHCR, Docker Hub, and Buccaneerr publication flow.
  • Retains exact Action digest pinning so the release supply chain cannot drift silently.

Runtime and Upgrade Impact ⚓

Privateerr runtime behavior is unchanged from v1.0.1. There are no environment-variable, generated-file, WireGuard, Gluetun metadata, mount, healthcheck, or port-forwarding changes, and no migration or regeneration is required.

The release remains compatible with current Plundarr stacks that use the image-owned privateerr-healthcheck command introduced in v1.0.1.

Published Images 📦

The release workflow published Privateerr tags 1.0.2, latest, and sha-26c86b4 to GHCR and mirrored them to Docker Hub. The registries expose matching Privateerr manifest digest sha256:12842009d40dc0b080958be6bdbbaa06a4627513273be97f40f501756079034e.

The companion Buccaneerr image was published to GHCR with matching release, latest, and commit-SHA channels at manifest digest sha256:eb19cf5ff229166199a8c68b3ffdc6bbb00261f4ba71e555750cae9b5204d163. Both images support linux/amd64, linux/arm64, and linux/arm/v7 with SBOM and provenance.

Validation 🧪

The release target is the passing main commit 26c86b4. The Actions validation, registry build, and OpenSSF Scorecard workflows completed successfully for that commit.

Merged Change 📜

  • #43: Update the build-provenance Action digest.

Full Changelog: v1.0.1...v1.0.2