Skip to content

revert(release): re-cut v0.75.0 after the image vulnerabilities are fixed - #1701

Merged
FelixTJDietrich merged 1 commit into
mainfrom
revert/version-0.75.0
Sep 1, 2026
Merged

revert(release): re-cut v0.75.0 after the image vulnerabilities are fixed#1701
FelixTJDietrich merged 1 commit into
mainfrom
revert/version-0.75.0

Conversation

@FelixTJDietrich

Copy link
Copy Markdown
Collaborator

Reverts the version commit 8ff1a912a so v0.75.0 can be cut again from a commit that carries the image fixes.

Why

The v0.75.0 release stopped at the evidence gate:

Error: webapp does not satisfy vulnerability policy

The pinned nginx:stable-alpine@sha256:97d490c… base carries four HIGH CVEs — openssl CVE-2026-14456, expat CVE-2026-66046 and CVE-2026-76641 — all fixed in Alpine 3.24, none available in any digest upstream has published. nginx:stable-alpine still resolves to that same digest today, so Renovate's digest management cannot deliver the fix.

Release images are promoted by digest and never rebuilt, so the draft at 8ff1a912a could never pass no matter what landed afterwards. And release.yml refuses to cut version N+1 unless version N is a published release, so the unpublished v0.75.0 draft would have wedged the version line.

The draft has been deleted. No tag was ever materialised — a draft release's tag is not created in git until publish — so no version was burned.

What this restores

  • package.json0.74.0
  • 107 changesets and the .migration/ fragments

Admin bypass

Verify changesets freeze-guards CHANGELOG.md and .migration/, which a revert necessarily touches. This needs the same documented bypass used on #1686 and #1691. Adding a revert exemption to that guard is tracked separately.

Follow-up

The image fixes and the structural changes that stop this recurring are tracked as separate issues, linked from this PR.

…ixed

This reverts commit 8ff1a91.

The v0.75.0 evidence gate rejected the webapp image: the pinned
nginx:stable-alpine base carries four HIGH CVEs (openssl CVE-2026-14456,
expat CVE-2026-66046 and CVE-2026-76641), all fixed in Alpine but not in
any digest upstream has published. Release images are promoted by digest
and never rebuilt, so the draft at that commit could never pass, and the
next version could not cut while an unpublished v0.75.0 draft remained.
The draft is deleted; no tag was ever materialised.

Restoring 0.74.0 and the changesets lets v0.75.0 re-cut from a commit that
carries the image fixes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 116 files, which is 16 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: c29e58f3-5633-4cbe-b009-c6dc41d8fcfe

📥 Commits

Reviewing files that changed from the base of the PR and between 8ff1a91 and 27a6989.

📒 Files selected for processing (116)
  • .changeset/a-practice-says-why-it-has-nothing-to-say.md
  • .changeset/a-review-stands-as-written.md
  • .changeset/accessible-navigation.md
  • .changeset/adopt-without-leaving-practice-setup.md
  • .changeset/adoption-leads-with-the-reason.md
  • .changeset/an-answer-keeps-the-words-that-came-with-it.md
  • .changeset/areas-get-an-icon-and-criteria-render.md
  • .changeset/bind-release-security-evidence.md
  • .changeset/bright-feedback-inbox.md
  • .changeset/bright-jobs-observe.md
  • .changeset/bright-ravens-check.md
  • .changeset/calm-mentors-welcome.md
  • .changeset/calm-otters-guard.md
  • .changeset/calm-practices-adopt.md
  • .changeset/calm-practices-expand.md
  • .changeset/clean-pnpm-toolchain.md
  • .changeset/clear-ai-feedback-disclosure.md
  • .changeset/clear-nails-begin.md
  • .changeset/complete-practice-coverage.md
  • .changeset/compose-feedback-for-real-reviews.md
  • .changeset/consume-release-image-lock.md
  • .changeset/core-web-vitals-reach-analytics.md
  • .changeset/current-web-runtime.md
  • .changeset/curvy-corners-heal.md
  • .changeset/docs-live-at-their-own-address.md
  • .changeset/drawers-move-like-drawers.md
  • .changeset/evidence-boundary-withholds-the-claim.md
  • .changeset/fair-falcons-attend.md
  • .changeset/fair-practice-budgets.md
  • .changeset/feedback-reaches-people-who-never-set-a-preference.md
  • .changeset/feedback-says-which-kind-of-good-or-bad-it-is.md
  • .changeset/feedback-survives-an-interrupted-review.md
  • .changeset/footer-branch-links-to-a-branch.md
  • .changeset/funky-yaks-wonder.md
  • .changeset/harden-runtime-envelope.md
  • .changeset/heph-avatar-brand-export.md
  • .changeset/hot-crews-rhyme.md
  • .changeset/huge-seals-do.md
  • .changeset/long-reviews-finish.md
  • .changeset/mentor-notes-say-what-was-already-said.md
  • .changeset/modern-bun-package-manager.md
  • .changeset/modern-node-agent-runtime.md
  • .changeset/move-image-namespace.md
  • .changeset/new-apes-make.md
  • .changeset/node-repository-tooling.md
  • .changeset/one-recovery-for-a-stale-plan.md
  • .changeset/oxlint-replaces-biomes-linter.md
  • .changeset/panels-behind-show-more.md
  • .changeset/practice-editors-fill-their-panel.md
  • .changeset/practice-forms-fit-a-phone.md
  • .changeset/practice-group-detail-page.md
  • .changeset/practice-group-empty-states-and-severity-wording.md
  • .changeset/practice-group-response-hardening.md
  • .changeset/practice-group-review-runs.md
  • .changeset/practice-group-standing-cards.md
  • .changeset/practice-standing-feedback-api.md
  • .changeset/practice-standing-recent-evidence.md
  • .changeset/practice-surfaces-one-vocabulary.md
  • .changeset/practice-surfaces-say-what-they-mean.md
  • .changeset/practice-trend-evidence.md
  • .changeset/preview-notes-say-what-the-code-does.md
  • .changeset/preview-oauth-note.md
  • .changeset/previews-deploy-on-purpose.md
  • .changeset/previews-reach-their-own-services.md
  • .changeset/previews-serve-their-frontend.md
  • .changeset/private-actionable-errors.md
  • .changeset/proud-rooms-move.md
  • .changeset/puny-teeth-bathe.md
  • .changeset/qualify-postgresql-eighteen.md
  • .changeset/quiet-dragons-observe.md
  • .changeset/quiet-forges-format.md
  • .changeset/quiet-metric-boundaries.md
  • .changeset/quiet-owls-consent.md
  • .changeset/quiet-oxfmt-migration.md
  • .changeset/quiet-pandas-review.md
  • .changeset/reconcile-sweeps-live-previews.md
  • .changeset/redacted-configuration-readiness.md
  • .changeset/removing-an-area-asks-what-to-keep.md
  • .changeset/retire-legacy-dependencies.md
  • .changeset/review-comments-read-better.md
  • .changeset/reviewer-practice-occurrences.md
  • .changeset/reviews-land-beside-the-code.md
  • .changeset/reviews-lead-with-what-matters.md
  • .changeset/reviews-open-in-their-own-words.md
  • .changeset/reviews-stop-quoting-the-catalogue.md
  • .changeset/rotate-credential-keys-online.md
  • .changeset/safe-automatic-feedback-promotion.md
  • .changeset/safe-profile-membership.md
  • .changeset/safer-oauth-boundaries.md
  • .changeset/secure-release-evidence.md
  • .changeset/secure-tenancy-default.md
  • .changeset/signal-blue-heph.md
  • .changeset/solid-ends-decide.md
  • .changeset/solid-socks-smash.md
  • .changeset/sorted-columns-say-so.md
  • .changeset/sparkly-islands-read.md
  • .changeset/spring-contracts-hold.md
  • .changeset/stable-postgres-volume-name.md
  • .changeset/startup-report-survives-a-missing-variable.md
  • .changeset/structured-safe-logs.md
  • .changeset/tidy-job-jwts.md
  • .changeset/tidy-vite-plus.md
  • .changeset/trace-every-request.md
  • .changeset/typescript-seven-stands-alone.md
  • .changeset/version-banner-sits-inside-the-panel.md
  • .changeset/warm-runners-start.md
  • .migration/bright-feedback-inbox.md
  • .migration/harden-runtime-envelope.md
  • .migration/move-image-namespace.md
  • .migration/practice-standing-feedback-api.md
  • .migration/stable-postgres-volume-name.md
  • CHANGELOG.md
  • MIGRATION.md
  • README.md
  • docs/admin/install.mdx
  • package.json

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added documentation Improvements or additions to documentation security Authentication, authorization, vulnerability fixes dependencies Package updates, version bumps, lock file changes revert Rolls back a previous change labels Sep 1, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved automatically: @FelixTJDietrich is listed in the REVIEW_POLICY_MAINTAINERS repository variable, which the repository treats as satisfying the review requirement. See the review policy in docs/contributor/ci-cd.mdx.

@github-project-automation github-project-automation Bot moved this from Backlog to In Review in Hephaestus Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

📚 Documentation Preview

Preview has been removed (PR closed)

@FelixTJDietrich

Copy link
Copy Markdown
Collaborator Author

Merging with an admin bypass. The only failing check is Verify changesets, with a single annotation:

Do not edit MIGRATION.md in a feature PR; add a .migration/<changeset-slug>.md fragment instead.

A revert of the version commit necessarily restores MIGRATION.md to its pre-version state, so the freeze guard cannot pass on this path by construction. Every other check passes. Same rationale as #1686 and #1691 — the third occurrence, which is why the revert exemption is now tracked in #1705.

@FelixTJDietrich
FelixTJDietrich merged commit 33f30c2 into main Sep 1, 2026
20 of 23 checks passed
@FelixTJDietrich
FelixTJDietrich deleted the revert/version-0.75.0 branch September 1, 2026 13:52
@github-project-automation github-project-automation Bot moved this from In Review to Done in Hephaestus Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

🧩 Storybook Preview

Preview has been removed (PR closed)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Package updates, version bumps, lock file changes documentation Improvements or additions to documentation revert Rolls back a previous change security Authentication, authorization, vulnerability fixes

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant