Commit 27a6989
revert(release): re-cut v0.75.0 after the image vulnerabilities are fixed
This reverts commit 8ff1a91.
The v0.75.0 evidence gate rejected the webapp image: the pinned
nginx:stable-alpine base carries four HIGH CVEs (openssl CVE-2026-14456,
expat CVE-2026-66046 and CVE-2026-76641), all fixed in Alpine but not in
any digest upstream has published. Release images are promoted by digest
and never rebuilt, so the draft at that commit could never pass, and the
next version could not cut while an unpublished v0.75.0 draft remained.
The draft is deleted; no tag was ever materialised.
Restoring 0.74.0 and the changesets lets v0.75.0 re-cut from a commit that
carries the image fixes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>1 parent 8ff1a91 commit 27a6989
116 files changed
Lines changed: 757 additions & 358 deletions
File tree
- .changeset
- .migration
- docs/admin
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
0 commit comments