diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b5ceb1b..f76f8530 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,19 @@ Versioning: [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ## [Unreleased] +## [0.8.0-rc.6] Eyrie (2026-09-27) + +`v0.8.0-rc.5` built, passed every machine gate, and its assets were +published as a pre-release. Its fleet checks, documentation review and +release-captain signature were not attested: no human verdict was recorded +for it. Since rc.5, the credential and session fixes (#870 to #881), the +documentation corrections (#883) and the Kensa 0.10.0 integration (#882) +landed on `main`. Under the release policy the rc.5 tag and assets stay +where they are, and this candidate carries the changes. The sections for +rc.5 and earlier candidates below remain the record of what each changed; +everything in them is in this candidate as well. Nothing is inherited from +rc.5: every gate runs again against this candidate. + **Upgrade notes.** Read these before upgrading. - **Upgrading signs everyone out.** Migration 0065 revokes every live session @@ -48,6 +61,14 @@ Versioning: [Semantic Versioning](https://semver.org/spec/v2.0.0.html). configure a Kensa package repository on an OpenWatch host. The upgrade runbook shows how to tell the packages apart and restore OpenWatch's. (CP `bugs/OW-081`) +- **Drift does not distinguish a corpus change from a host change.** A + Kensa update can move scores on hosts that did not change, and when the + movement crosses a drift threshold it alerts as ordinary drift. Nothing + marks it as corpus-driven, and no alert is suppressed. Each scan records + its Kensa engine version, so the upgrade is traceable by inspection. + Accepted as a v0.8 limitation. (CP `shared/sprint/prd/D-2-feature`, S-3) +- **Scan variable values are not type checked when saved.** A value of the + wrong type is stored and applied as entered. (CP `bugs/OW-080`) ### Security diff --git a/README.md b/README.md index 043161c6..e647ac36 100644 --- a/README.md +++ b/README.md @@ -30,7 +30,7 @@ and how it is built. > Python/FastAPI implementation was archived out of the repo on 2026-06-05). The > Go tree lives at the **repo root**: Go 1.26 backend (`cmd/`, `internal/`), > React 19 + TanStack frontend (`frontend/`), PostgreSQL-only. The current -> version is `0.8.0-rc.5`, on the general-availability line that opened with `0.2.0`. +> version is `0.8.0-rc.6`, on the general-availability line that opened with `0.2.0`. ![OpenWatch Host Management: a fleet of RHEL and Ubuntu hosts with per-host compliance scores against the Kensa corpus](docs/images/host-management.png) diff --git a/packaging/version.env b/packaging/version.env index 2d2d907a..5dddf634 100644 --- a/packaging/version.env +++ b/packaging/version.env @@ -2,5 +2,5 @@ # # The Go binary's ldflags read this file via the Makefile; build scripts # in packaging/{rpm,deb}/ source it for spec macros. -VERSION="0.8.0-rc.5" +VERSION="0.8.0-rc.6" CODENAME="Eyrie"