From 860a6666359447305e67e6a7fbc831c399464880 Mon Sep 17 00:00:00 2001 From: Remylus Losius Date: Sun, 27 Sep 2026 20:53:03 -0400 Subject: [PATCH] chore(release): prepare v0.8.0-rc.6 Eyrie Stage 1 for the sixth 0.8.0 candidate, from main fc1117dc. VERSION is 0.8.0-rc.6 in packaging/version.env, the README phrase and the newest CHANGELOG heading; CODENAME stays Eyrie. The hygiene test binds the three. The changelog section records rc.5 on facts: built, every machine gate passed, assets published as a pre-release, no human verdict recorded for its fleet checks, documentation review or release-captain signature, tag and assets preserved. Since rc.5: #870 to #881, #883 and #882. The [Unreleased] notes move into the rc.6 section unchanged. Known limitations gain the two the readiness record lists as shipping with v0.8: drift does not distinguish a corpus change from a host change (D-2 S-3, accepted 2026-09-26), and scan variable values are not type checked (OW-080). Next unused candidate number verified: no v0.8.0-rc.6 tag on the remote or locally, and no release or draft of that name. No tag, publication or attestation. --- CHANGELOG.md | 21 +++++++++++++++++++++ README.md | 2 +- packaging/version.env | 2 +- 3 files changed, 23 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b5ceb1b..f76f8530 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,19 @@ Versioning: [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ## [Unreleased] +## [0.8.0-rc.6] Eyrie (2026-09-27) + +`v0.8.0-rc.5` built, passed every machine gate, and its assets were +published as a pre-release. Its fleet checks, documentation review and +release-captain signature were not attested: no human verdict was recorded +for it. Since rc.5, the credential and session fixes (#870 to #881), the +documentation corrections (#883) and the Kensa 0.10.0 integration (#882) +landed on `main`. Under the release policy the rc.5 tag and assets stay +where they are, and this candidate carries the changes. The sections for +rc.5 and earlier candidates below remain the record of what each changed; +everything in them is in this candidate as well. Nothing is inherited from +rc.5: every gate runs again against this candidate. + **Upgrade notes.** Read these before upgrading. - **Upgrading signs everyone out.** Migration 0065 revokes every live session @@ -48,6 +61,14 @@ Versioning: [Semantic Versioning](https://semver.org/spec/v2.0.0.html). configure a Kensa package repository on an OpenWatch host. The upgrade runbook shows how to tell the packages apart and restore OpenWatch's. (CP `bugs/OW-081`) +- **Drift does not distinguish a corpus change from a host change.** A + Kensa update can move scores on hosts that did not change, and when the + movement crosses a drift threshold it alerts as ordinary drift. Nothing + marks it as corpus-driven, and no alert is suppressed. Each scan records + its Kensa engine version, so the upgrade is traceable by inspection. + Accepted as a v0.8 limitation. (CP `shared/sprint/prd/D-2-feature`, S-3) +- **Scan variable values are not type checked when saved.** A value of the + wrong type is stored and applied as entered. (CP `bugs/OW-080`) ### Security diff --git a/README.md b/README.md index 043161c6..e647ac36 100644 --- a/README.md +++ b/README.md @@ -30,7 +30,7 @@ and how it is built. > Python/FastAPI implementation was archived out of the repo on 2026-06-05). The > Go tree lives at the **repo root**: Go 1.26 backend (`cmd/`, `internal/`), > React 19 + TanStack frontend (`frontend/`), PostgreSQL-only. The current -> version is `0.8.0-rc.5`, on the general-availability line that opened with `0.2.0`. +> version is `0.8.0-rc.6`, on the general-availability line that opened with `0.2.0`. ![OpenWatch Host Management: a fleet of RHEL and Ubuntu hosts with per-host compliance scores against the Kensa corpus](docs/images/host-management.png) diff --git a/packaging/version.env b/packaging/version.env index 2d2d907a..5dddf634 100644 --- a/packaging/version.env +++ b/packaging/version.env @@ -2,5 +2,5 @@ # # The Go binary's ldflags read this file via the Makefile; build scripts # in packaging/{rpm,deb}/ source it for spec macros. -VERSION="0.8.0-rc.5" +VERSION="0.8.0-rc.6" CODENAME="Eyrie"