This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summaryUpdates Security fixes, Upgrade notes, and https://github.com/kOlapsis/maintenant/blob/main/SECURITY.md across a mixed release.
Full changelog
First release shipped through the new verifiable release chain: the image is built by the CI, carries SLSA build provenance, an attested CycloneDX SBOM, and a keyless Cosign signature. Also fixes a reflected XSS on the status pages and clears every known HIGH/CRITICAL advisory reachable in the binary.
Thanks to @stephrobert for her precious consil
Signed, verifiable releases
Every release image can now be verified by a third party, with no privileged access to the repository:
gh attestation verify oci://ghcr.io/kolapsis/maintenant:1.3.7 --owner kOlapsis
cosign verify ghcr.io/kolapsis/maintenant:1.3.7 \
--certificate-identity-regexp "https://github.com/kOlapsis/maintenant/.github/workflows/release.yml@.*" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
The SBOM (sbom.cdx.json) and the SLSA provenance (provenance.intoto.jsonl) are attached to this release and attested in the registry next to the image. Note: verification requires Cosign 3.x - a local 2.x reports "no signatures found" on a correctly signed image. Full details in the new SECURITY.md, including the vulnerability reporting policy and disclosure timeline.
Security fixes
- Hardened asset serving. Status-page personalization assets (logo, favicon, hero) are served with
X-Content-Type-Options: nosniffand a strictContent-Security-Policy, neutralizing script execution when an allowlisted SVG is opened by direct navigation. - Dependency updates. All known HIGH/CRITICAL advisories reachable in the binary are cleared:
golang.org/x/crypto0.52.0 (nine ssh advisories),x/net0.55.0,x/text0.39.0,google.golang.org/grpc1.82.1,modelcontextprotocol/go-sdk1.4.1, and Go 1.25.12 for the patched standard library. Frontend dev-only tooling (vite, vitest) refreshed likewise. - Telemetry data directory created with
0750instead of0755.
Hardened CI/CD pipeline
The GitHub Actions pipeline is rebuilt on a supply-chain hardening baseline: zero default token permissions, every action pinned to a verified commit SHA, step-security/harden-runner on every job, and a gate ordering of workflow scanners (zizmor, actionlint, poutine) - static analysis (gosec, govulncheck, Trivy) ? lint ? tests. CodeQL runs on every push and pull request, and pull requests scan the built image with Trivy. The full gosec baseline was triaged to zero: real fixes where warranted, per-site justified suppressions otherwise ? no rule disabled.
Code quality
Every golangci-lint finding (~80: errcheck, staticcheck, unused, ineffassign) and every eslint error (29) on the codebase is fixed, a data race in a lifecycle test is corrected, and the deprecated Docker types.*Options APIs moved to their swarm.* replacements. No behaviour changes.
Upgrade notes
- No database migration, no API changes. Pull the new image to upgrade.
- Publishing a release is now what builds and signs the versioned image; pushing a tag alone no longer publishes anything.
Security Fixes
- Hardened asset serving: status‑page assets now have X-Content-Type-Options:nosniff and strict Content-Security-Policy.
- Dependency updates clear all known HIGH/CRITICAL advisories (golang.org/x/crypto, x/net, x/text, google.golang.org/grpc, modelcontextprotocol/go-sdk, Go 1.25.12).
- Telemetry data directory created with 0750 permissions instead of 0755.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]