Skip to content

v0.1.20

Choose a tag to compare

@teslashibe teslashibe released this 04 Sep 22:38
· 26 commits to main since this release
1e503fe

Fix public Codex JSON asset permissions so non-root containers can read them regardless of source checkout umask. Harden the image provenance smoke with UID/GID 1000:1000, dropped capabilities, no-new-privileges, and explicit asset readability checks.

Validation: full local Go build/vet/race gate and linux/amd64 image smoke passed with deliberately 0600 source assets and verified build provenance. GitHub Actions could not start because of an account billing lock; the authorized admin merge used this local validation. EU deployment remains a separate operator step.

PR: #164