chore: sync published workspace versions - #499
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Reopening to trigger exact-head hosted validation because GitHub suppresses workflow recursion for PRs created by the release workflow token. |
|
Follow-up on exact-head CI: the first hosted image scan detected CVE-2026-14456 in the pinned Alpine runtime (OpenSSL 3.5.7-r0; fixed in 3.5.8-r0). Commit 2cad81c installs the reviewed fixed libcrypto3/libssl3 packages in the affected Chaintracks, Message Box, WAB, and Wallet Infrastructure runtime stages. UHRP Basic and Cloud already carry the same fix. Local validation on this head passed: |
|
ty-everett
left a comment
There was a problem hiding this comment.
Approved after exact-head review: version reconciliation is coherent; the Alpine OpenSSL remediation removes CVE-2026-14456 without suppressions; local governance/lint/format/typecheck/audit checks pass; hosted Linux/amd64 runtime, Trivy, CodeQL, Sonar zero-findings, dependency, conformance, and merge gates are green at a2c84c1.



Program and scope
Impact
Affected services and intended patch versions are the changed infra package manifests in this PR.
Verification
Security and dependencies
Dependency evidence
Release and operations
The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.
Completion evidence