Security
- Alpine 3.23 base image: Runtime base image upgraded from Alpine 3.21 to 3.23
for reduced CVE surface and latest security patches - CI security hardening:
security:trivy(filesystem scan) and
security:govulnchecknow block pipeline on CRITICAL/HIGH findings instead
of running in warn-only mode.govulncheckuses a wrapper that allows
known-unfixed upstream vulnerabilities (docker/docker SDK) while blocking
on any new findings - SECURITY.md: Added responsible vulnerability disclosure policy with
supported versions, reporting process, and security practices
Changed
- Alpine base image upgraded from 3.21 to 3.23
.trivyignoreentries now include explicit review dates
Docker Images
docker pull ghcr.io/maxfield-allison/dnsweaver:v1.0.4
docker pull docker.io/maxamill/dnsweaver:v1.0.4