Pre-release build
Release candidate for the upcoming stable release. Not published as latest.
Commits since v2.0.0:
- ci(docker): gate releases on green CI and drop the GH_PAT fallback (#308) (9d77446)
- feat(config): add optional NetworkPolicy, image digest and Secret-backed headers to the Helm chart (#307) (56e2623)
- ci(docker): publish one complete SBOM and attest it to the image digest (#306) (ae20997)
- fix(docker): verify release signatures with the exact workflow identity (#305) (1ac9586)
- ci(docker): scan the built image and Containerfiles with Trivy (#304) (98b5de7)
- test(ws): wait for client registration in dialIdentified (#303) (309f1bb)
- chore(docker): pin base images by digest and pnpm by version (#298) (aa22bcc)
- fix(api): limit manual polls and WebSocket connections (#297) (97ddeb5)
- fix(api): strip credentials from cluster URLs and add optional metrics token (#296) (a0d11c3)
- fix(api): add optional Host allow-list and trusted-proxy client IP (#295) (8d71d1a)
- fix(api): reject cross-origin writes, harden response headers and add JARVIS_COOKIE_SECURE (#294) (3758e91)
- fix(api): split liveness and readiness probes and report follower cluster health (#293) (7fa0177)
- fix(api): bind sessions to the database and make logout revocation persistent (#292) (6b45af9)
- docs(frontend): add AI and engineering page (#289) (4f75b32)
- fix(api): create the first admin atomically and add optional setup token (#288) (552c595)
- feat(frontend): show failed loads, stale clusters and lost live connection (#287) (232c936)
- feat(api): report and export the age of each cluster's data (#286) (a23a34c)
- fix(db): keep snapshot alerts when a fresh leader cannot reach Alertmanager (#285) (ccce947)
- fix(config): warn at startup when authentication is disabled (#284) (8b913d9)
- fix(config): enable gitleaks default rules and add scan canary (#283) (74d69f5)
- chore(deps): bump github.com/labstack/echo/v4 from 4.15.4 to 4.16.0 in /backend (#279) (129a22c)
- chore(deps): bump the minor-patch group across 1 directory with 9 updates (#270) (16045b8)
- chore(deps): bump the codeql-action group across 1 directory with 4 updates (#254) (9e2b895)
- feat(comments): show comment count in card and list view (#282) (7bcf99a)
- docs: auto-merge Dependabot PRs only without major or breaking changes (#281) (34ef28b)
- docs: trim AGENTS.md to restore headroom under the byte budget (#280) (1517099)
- docs(frontend): refresh the detail panel details-tab screenshot (#278) (51e6153)
- feat(config): support multiple OIDC admin groups (#277) (6043de5)
- feat(alerts): show alert metadata with fingerprint in the detail sheet (#276) (9befa83)
- chore(docker): add opt-in fast local e2e run (#275) (48191ca)
- feat(alerts): show recently resolved alerts in the active list (#274) (85ba2e8)
- chore(deps): override brace-expansion to a patched release (#273) (23ab8f4)
Container image
docker pull ghcr.io/kj187/jarvis:2.0.1-rc.1Digest: sha256:4cc3a3896a475b1d553ef8d915a1eadd861145f7eac507fe31288b1ceb8e0c74
Verify image signature (cosign)
cosign verify ghcr.io/kj187/jarvis@sha256:4cc3a3896a475b1d553ef8d915a1eadd861145f7eac507fe31288b1ceb8e0c74 \
--certificate-identity="https://github.com/kj187/jarvis/.github/workflows/release.yml@refs/tags/v2.0.1-rc.1" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify build provenance (GitHub attestation)
gh attestation verify oci://ghcr.io/kj187/jarvis:2.0.1-rc.1 --repo kj187/jarvisHelm chart
Release candidates don't publish a chart. To test this RC on Kubernetes, install the current chart with the RC image:
helm install jarvis oci://ghcr.io/kj187/charts/jarvis --version 2.1.0 --set image.tag=2.0.1-rc.1SBOM
The SPDX SBOM covers the image (OS packages and the Go binary's modules) and the frontend production dependencies. It is attached to this release (sbom.spdx.json) together with its keyless signature bundle (sbom.spdx.json.sigstore.json) and attested to the image digest. The image manifest additionally embeds BuildKit's own SBOM (docker buildx imagetools inspect).
cosign verify-blob sbom.spdx.json \
--bundle sbom.spdx.json.sigstore.json \
--certificate-identity="https://github.com/kj187/jarvis/.github/workflows/release.yml@refs/tags/v2.0.1-rc.1" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"
gh attestation verify oci://ghcr.io/kj187/jarvis@sha256:4cc3a3896a475b1d553ef8d915a1eadd861145f7eac507fe31288b1ceb8e0c74 \
--repo kj187/jarvis \
--signer-workflow kj187/jarvis/.github/workflows/release.yml \
--predicate-type https://spdx.dev/Document/v2.3