Skip to content

release: 0.15.28 (Azure cloud-platform false-positive sweep)#1122

Merged
maiconburn merged 1 commit into
mainfrom
release/0.15.28
Jun 26, 2026
Merged

release: 0.15.28 (Azure cloud-platform false-positive sweep)#1122
maiconburn merged 1 commit into
mainfrom
release/0.15.28

Conversation

@maiconburn

Copy link
Copy Markdown
Collaborator

Bundles the three NON-IP cloud-platform false-positive fixes from the 7-day Azure decision-log audit, already merged to main. No platform IP is hardcoded in the product (operator policy: "IPs change"). Detector count unchanged (82).

Included (already merged + approved)

PR4 / OpenClaw coexistence = no code: the 6 .env-read endpoint blocks were 2026-06-15..06-21 = the spec-081 cross-uid bug, already fixed by #1094 (0.15.24) + 0.15.27. Zero since 06-21.

This PR

Version bump 0.15.27 -> 0.15.28 (Cargo.toml + workspace lock + agents-install token) + CHANGELOG [0.15.28]. No Rust code change beyond what already merged to main.

After approval: tag v0.15.28 -> release.yml builds + signs both arches -> deploy Azure (scoped-enforce safe flow) + Oracle (watchdog-aware) -> re-run the Azure SQLite audit to confirm the FP drop.

🤖 Generated with Claude Code

Bundles the three NON-IP cloud-platform FP fixes merged from the 7-day
Azure decision-log audit (no platform IP hardcoded in product; detector
count unchanged at 82):

- #1119 fileless:systemd parent-lineage gate (1206 Critical/wk -> 0)
- #1120 cloud-guest-agent provenance (crates/sensor/src/cloud_platform.rs):
  kills the WireServer 168.63.129.16 auto-block + 869 IMDS needs_review;
  DMI auto-detect + non-forgeable /proc identity, downgrade-only
- #1121 dns_tunneling Azure service zones windows.net/azure.net (667 -> 0)

Version bump (Cargo.toml + workspace lock + agents-install token) +
CHANGELOG [0.15.28]. No code change beyond what already merged to main.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@maiconburn maiconburn requested a review from esteves-uk as a code owner June 26, 2026 22:54
@maiconburn maiconburn merged commit b3a9bd5 into main Jun 26, 2026
19 checks passed
@codecov

codecov Bot commented Jun 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants