Repository navigation
Conversation
Backfill changelog and upgrading-guide entries for commits that landed after the changelog was last touched: execution lifecycle unification, bounded shutdown/provider reads, diagnostic redaction and auth/MCP work limits, container image CVE hardening, and the Helm chart single-process enforcement (chart version bumped to 0.2.0). Correct the stale svelte-check baseline claim and drop the leftover beta suffix from the frontend version badge. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Changes are still required before approval.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This pull request finalizes Pabawi 1.5.0 release metadata and documents Helm upgrade requirements.
Changes:
- Updates the displayed frontend version.
- Bumps the Helm chart version to 0.2.0.
- Adds upgrade guidance and changelog notes.
File summaries
| File | Description |
|---|---|
frontend/src/components/Navigation.svelte |
Updates the displayed version to 1.5.0. |
docs/upgrading.md |
Documents Helm upgrade requirements. |
charts/pabawi/Chart.yaml |
Bumps the chart version to 0.2.0. |
CHANGELOG.md |
Adds 1.5.0 release notes. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…dual one concurrent-ruby, faraday, jwt and resolv are pinned past openbolt 5.6.0's vendored, vulnerable versions, verified against every installed gem's declared dependency constraint (e.g. r10k needs jwt < 3). rubyzip stays at 2.4.1: its fix requires >= 3.4.0, but winrm-fs 1.3.5 (still the latest upstream release) hard-pins rubyzip ~> 2.0, and bumping it would break Bolt's WinRM transport. The release-image scan step now tolerates that one known, currently-unfixable finding instead of blocking publish. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Release scanning is non-blocking, and Docker gem replacement validation has unresolved issues.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (1)
Dockerfile:60
- This introduces security-critical gem replacement in the default Bookworm image, but the CI Ruby dependency/version checks are only run for the Ubuntu variant; Bookworm is covered only by generic Bolt task discovery and the now-nonblocking image scan. A wrong install path, unresolved version, or leftover vulnerable default gem can therefore reach publishing without a failing check. Add a Bookworm-specific assertion of the active patched versions and absence of the replaced versions before release.
/opt/puppetlabs/bolt/bin/gem install --no-document \
concurrent-ruby:1.3.8 \
faraday:2.14.3 \
jwt:2.10.3 \
resolv:0.7.2 \
- Files reviewed: 6/6 changed files
- Comments generated: 2
- Review effort level: Lite
| mkdir -p artifacts | ||
| docker run --rm -i --entrypoint node pabawi:candidate < scripts/supply-chain/dependency-graph.cjs > artifacts/dependencies.json | ||
| - name: Scan release candidate | ||
| continue-on-error: true |
Comment on lines
+61
to
+62
| && /opt/puppetlabs/bolt/bin/gem uninstall --force --ignore-dependencies \ | ||
| concurrent-ruby:1.3.6 faraday:2.14.2 jwt:2.10.2 \ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.