diff --git a/Cargo.lock b/Cargo.lock index 39f88f886..cd2aedae1 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -4914,7 +4914,7 @@ checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4" [[package]] name = "registry-breg" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -4978,7 +4978,7 @@ dependencies = [ [[package]] name = "registry-breg-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -5003,7 +5003,7 @@ dependencies = [ [[package]] name = "registry-breg-client-node" -version = "0.35.0" +version = "0.36.0" dependencies = [ "napi", "napi-build", @@ -5020,7 +5020,7 @@ dependencies = [ [[package]] name = "registry-breg-client-py" -version = "0.35.0" +version = "0.36.0" dependencies = [ "pyo3", "pyo3-build-config", @@ -5036,7 +5036,7 @@ dependencies = [ [[package]] name = "registry-bregctl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anstream", "anstyle", @@ -5087,7 +5087,7 @@ dependencies = [ [[package]] name = "registry-casework" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -5139,7 +5139,7 @@ dependencies = [ [[package]] name = "registry-casework-breg" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "base64 0.23.1", @@ -5165,7 +5165,7 @@ dependencies = [ [[package]] name = "registry-casework-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -5190,7 +5190,7 @@ dependencies = [ [[package]] name = "registry-casework-client-node" -version = "0.35.0" +version = "0.36.0" dependencies = [ "napi", "napi-build", @@ -5205,7 +5205,7 @@ dependencies = [ [[package]] name = "registry-casework-client-py" -version = "0.35.0" +version = "0.36.0" dependencies = [ "pyo3", "pyo3-build-config", @@ -5219,7 +5219,7 @@ dependencies = [ [[package]] name = "registry-casework-core" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "chrono", @@ -5240,7 +5240,7 @@ dependencies = [ [[package]] name = "registry-caseworkctl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anyhow", "base64 0.23.1", @@ -5275,7 +5275,7 @@ dependencies = [ [[package]] name = "registry-cli-docs" -version = "0.35.0" +version = "0.36.0" dependencies = [ "clap", "registry-breg", @@ -5297,7 +5297,7 @@ dependencies = [ [[package]] name = "registry-cli-reference" -version = "0.35.0" +version = "0.36.0" dependencies = [ "clap", "serde", @@ -5305,7 +5305,7 @@ dependencies = [ [[package]] name = "registry-discovery" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "axum-test", @@ -5333,7 +5333,7 @@ dependencies = [ [[package]] name = "registry-discovery-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "base64 0.23.1", @@ -5365,7 +5365,7 @@ dependencies = [ [[package]] name = "registry-discovery-client-node" -version = "0.35.0" +version = "0.36.0" dependencies = [ "napi", "napi-build", @@ -5378,7 +5378,7 @@ dependencies = [ [[package]] name = "registry-discovery-client-py" -version = "0.35.0" +version = "0.36.0" dependencies = [ "pyo3", "pyo3-build-config", @@ -5391,7 +5391,7 @@ dependencies = [ [[package]] name = "registry-discovery-profile" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-platform-canonical-json", "serde", @@ -5403,7 +5403,7 @@ dependencies = [ [[package]] name = "registry-discoveryctl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "clap", @@ -5429,7 +5429,7 @@ dependencies = [ [[package]] name = "registry-evidence" -version = "0.35.0" +version = "0.36.0" dependencies = [ "assert-json-diff", "async-trait", @@ -5488,7 +5488,7 @@ dependencies = [ [[package]] name = "registry-evidence-authoring" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anyhow", "jsonschema", @@ -5502,7 +5502,7 @@ dependencies = [ [[package]] name = "registry-evidence-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -5530,7 +5530,7 @@ dependencies = [ [[package]] name = "registry-evidence-client-node" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -5554,7 +5554,7 @@ dependencies = [ [[package]] name = "registry-evidence-client-py" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -5578,7 +5578,7 @@ dependencies = [ [[package]] name = "registry-evidence-oid4vci" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -5615,7 +5615,7 @@ dependencies = [ [[package]] name = "registry-evidence-verifier" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -5635,7 +5635,7 @@ dependencies = [ [[package]] name = "registry-evidencectl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anyhow", "axum", @@ -5679,7 +5679,7 @@ dependencies = [ [[package]] name = "registry-language-server" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anyhow", "futures", @@ -5698,7 +5698,7 @@ dependencies = [ [[package]] name = "registry-linkml" -version = "0.35.0" +version = "0.36.0" dependencies = [ "serde", "serde_json", @@ -5708,7 +5708,7 @@ dependencies = [ [[package]] name = "registry-manifest-cli" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-manifest-core", "serde", @@ -5719,7 +5719,7 @@ dependencies = [ [[package]] name = "registry-manifest-core" -version = "0.35.0" +version = "0.36.0" dependencies = [ "oxiri 0.3.1", "oxjsonld", @@ -5734,7 +5734,7 @@ dependencies = [ [[package]] name = "registry-platform-audit" -version = "0.35.0" +version = "0.36.0" dependencies = [ "hmac 0.13.0", "regex", @@ -5754,7 +5754,7 @@ dependencies = [ [[package]] name = "registry-platform-authcommon" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "proptest", @@ -5771,11 +5771,11 @@ dependencies = [ [[package]] name = "registry-platform-buildinfo" -version = "0.35.0" +version = "0.36.0" [[package]] name = "registry-platform-calendar" -version = "0.35.0" +version = "0.36.0" dependencies = [ "chrono", "chrono-tz", @@ -5784,7 +5784,7 @@ dependencies = [ [[package]] name = "registry-platform-canonical-json" -version = "0.35.0" +version = "0.36.0" dependencies = [ "ryu-js", "serde", @@ -5794,7 +5794,7 @@ dependencies = [ [[package]] name = "registry-platform-config" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-platform-canonical-json", "rustix 1.1.5", @@ -5812,7 +5812,7 @@ dependencies = [ [[package]] name = "registry-platform-crypto" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "aws-lc-rs", @@ -5839,7 +5839,7 @@ dependencies = [ [[package]] name = "registry-platform-hooks" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "hex", @@ -5859,7 +5859,7 @@ dependencies = [ [[package]] name = "registry-platform-httpsec" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "http", @@ -5875,7 +5875,7 @@ dependencies = [ [[package]] name = "registry-platform-httputil" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -5909,7 +5909,7 @@ dependencies = [ [[package]] name = "registry-platform-oidc" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "base64 0.23.1", @@ -5925,7 +5925,7 @@ dependencies = [ [[package]] name = "registry-platform-script" -version = "0.35.0" +version = "0.36.0" dependencies = [ "rhai", "serde", @@ -5935,7 +5935,7 @@ dependencies = [ [[package]] name = "registry-platform-sdjwt" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "base64 0.23.1", @@ -5953,7 +5953,7 @@ dependencies = [ [[package]] name = "registry-platform-sqlite" -version = "0.35.0" +version = "0.36.0" dependencies = [ "rusqlite", "rustix 1.1.5", @@ -5966,7 +5966,7 @@ dependencies = [ [[package]] name = "registry-platform-testing" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "base64 0.23.1", @@ -5988,7 +5988,7 @@ dependencies = [ [[package]] name = "registry-record" -version = "0.35.0" +version = "0.36.0" dependencies = [ "serde", "serde_json", @@ -5998,7 +5998,7 @@ dependencies = [ [[package]] name = "registry-relay-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -6018,7 +6018,7 @@ dependencies = [ [[package]] name = "registry-relay-client-node" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "napi", @@ -6035,7 +6035,7 @@ dependencies = [ [[package]] name = "registry-relay-client-py" -version = "0.35.0" +version = "0.36.0" dependencies = [ "pyo3", "pyo3-build-config", @@ -6051,11 +6051,11 @@ dependencies = [ [[package]] name = "registry-relay-http-contract" -version = "0.35.0" +version = "0.36.0" [[package]] name = "registry-relay-v2" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "base64 0.23.1", @@ -6111,7 +6111,7 @@ dependencies = [ [[package]] name = "registry-relayctl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "clap", "hex", @@ -6128,7 +6128,7 @@ dependencies = [ [[package]] name = "registry-render" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "base64 0.23.1", @@ -6165,7 +6165,7 @@ dependencies = [ [[package]] name = "registry-review-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "chrono", @@ -6184,7 +6184,7 @@ dependencies = [ [[package]] name = "registry-review-protocol" -version = "0.35.0" +version = "0.36.0" dependencies = [ "chrono", "registry-platform-canonical-json", @@ -6197,7 +6197,7 @@ dependencies = [ [[package]] name = "registry-scheduling" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "axum", @@ -6244,7 +6244,7 @@ dependencies = [ [[package]] name = "registry-scheduling-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "axum", "chrono", @@ -6261,7 +6261,7 @@ dependencies = [ [[package]] name = "registry-scheduling-core" -version = "0.35.0" +version = "0.36.0" dependencies = [ "chrono", "registry-platform-calendar", @@ -6277,7 +6277,7 @@ dependencies = [ [[package]] name = "registry-schedulingctl" -version = "0.35.0" +version = "0.36.0" dependencies = [ "anyhow", "chrono", @@ -6300,7 +6300,7 @@ dependencies = [ [[package]] name = "registry-stack-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-breg-client", "registry-casework-client", @@ -6313,7 +6313,7 @@ dependencies = [ [[package]] name = "registry-thunderid-tooling" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "getrandom 0.4.3", diff --git a/Cargo.toml b/Cargo.toml index 4fea1c5b5..d9f83f0ef 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -72,7 +72,7 @@ exclude = [ resolver = "2" [workspace.package] -version = "0.35.0" +version = "0.36.0" edition = "2021" rust-version = "1.95" license = "Apache-2.0" @@ -83,67 +83,67 @@ repository = "https://github.com/registrystack/registry-stack" unsafe_code = "forbid" [workspace.dependencies] -registry-review-client = { path = "crates/registry-review-client", version = "0.35.0" } -registry-review-protocol = { path = "crates/registry-review-protocol", version = "0.35.0" } -registry-thunderid-tooling = { path = "crates/registry-thunderid-tooling", version = "0.35.0" } -registry-casework = { path = "crates/registry-casework", version = "0.35.0" } -registry-casework-client-node = { path = "crates/registry-casework-client-node", version = "0.35.0" } -registry-casework-client-py = { path = "crates/registry-casework-client-py", version = "0.35.0" } -registry-caseworkctl = { path = "crates/registry-caseworkctl", version = "0.35.0" } -registry-casework-client = { path = "crates/registry-casework-client", version = "0.35.0" } -registry-casework-breg = { path = "crates/registry-casework-breg", version = "0.35.0" } -registry-casework-core = { path = "crates/registry-casework-core", version = "0.35.0" } -registry-discovery = { path = "crates/registry-discovery", version = "0.35.0", default-features = false } -registry-discovery-client = { path = "crates/registry-discovery-client", version = "0.35.0" } -registry-discovery-client-node = { path = "crates/registry-discovery-client-node", version = "0.35.0" } -registry-discovery-client-py = { path = "crates/registry-discovery-client-py", version = "0.35.0" } -registry-discovery-profile = { path = "crates/registry-discovery-profile", version = "0.35.0" } -registry-discoveryctl = { path = "crates/registry-discoveryctl", version = "0.35.0" } -registry-evidence = { path = "crates/registry-evidence", version = "0.35.0" } -registry-evidence-authoring = { path = "crates/registry-evidence-authoring", version = "0.35.0" } -registry-evidence-client = { path = "crates/registry-evidence-client", version = "0.35.0" } -registry-evidence-client-node = { path = "crates/registry-evidence-client-node", version = "0.35.0" } -registry-evidence-client-py = { path = "crates/registry-evidence-client-py", version = "0.35.0" } -registry-evidence-oid4vci = { path = "crates/registry-evidence-oid4vci", version = "0.35.0" } -registry-evidence-verifier = { path = "crates/registry-evidence-verifier", version = "0.35.0" } -registry-evidencectl = { path = "crates/registry-evidencectl", version = "0.35.0" } -registry-language-server = { path = "crates/registry-language-server", version = "0.35.0" } -registry-linkml = { path = "crates/registry-linkml", version = "0.35.0" } -registry-manifest-core = { path = "crates/registry-manifest-core", version = "0.35.0" } -registry-record = { path = "crates/registry-record", version = "0.35.0" } -registry-render = { path = "crates/registry-render", version = "0.35.0" } -registry-breg-client = { path = "crates/registry-breg-client", version = "0.35.0" } -registry-breg-client-node = { path = "crates/registry-breg-client-node", version = "0.35.0" } -registry-breg-client-py = { path = "crates/registry-breg-client-py", version = "0.35.0" } -registry-relay-http-contract = { path = "crates/registry-relay-http-contract", version = "0.35.0" } -registry-relay-client = { path = "crates/registry-relay-client", version = "0.35.0" } -registry-relay-client-node = { path = "crates/registry-relay-client-node", version = "0.35.0" } -registry-relay-client-py = { path = "crates/registry-relay-client-py", version = "0.35.0" } -registry-relay-v2 = { path = "crates/registry-relay-v2", version = "0.35.0" } -registry-relayctl = { path = "crates/registry-relayctl", version = "0.35.0" } -registry-scheduling = { path = "crates/registry-scheduling", version = "0.35.0" } -registry-scheduling-core = { path = "crates/registry-scheduling-core", version = "0.35.0" } -registry-schedulingctl = { path = "crates/registry-schedulingctl", version = "0.35.0" } -registry-scheduling-client = { path = "crates/registry-scheduling-client", version = "0.35.0" } -registry-breg = { path = "crates/registry-breg", version = "0.35.0", default-features = false } -registry-bregctl = { path = "crates/registry-bregctl", version = "0.35.0" } -registry-stack-client = { path = "crates/registry-stack-client", version = "0.35.0" } -registry-platform-audit = { path = "crates/registry-platform-audit", version = "0.35.0" } -registry-platform-authcommon = { path = "crates/registry-platform-authcommon", version = "0.35.0" } -registry-platform-buildinfo = { path = "crates/registry-platform-buildinfo", version = "0.35.0" } -registry-platform-calendar = { path = "crates/registry-platform-calendar", version = "0.35.0" } -registry-cli-reference = { path = "crates/registry-cli-reference", version = "0.35.0" } -registry-platform-canonical-json = { path = "crates/registry-platform-canonical-json", version = "0.35.0" } -registry-platform-config = { path = "crates/registry-platform-config", version = "0.35.0" } -registry-platform-crypto = { path = "crates/registry-platform-crypto", version = "0.35.0" } -registry-platform-hooks = { path = "crates/registry-platform-hooks", version = "0.35.0" } -registry-platform-httpsec = { path = "crates/registry-platform-httpsec", version = "0.35.0", default-features = false } -registry-platform-httputil = { path = "crates/registry-platform-httputil", version = "0.35.0" } -registry-platform-oidc = { path = "crates/registry-platform-oidc", version = "0.35.0" } -registry-platform-script = { path = "crates/registry-platform-script", version = "0.35.0" } -registry-platform-sdjwt = { path = "crates/registry-platform-sdjwt", version = "0.35.0" } -registry-platform-sqlite = { path = "crates/registry-platform-sqlite", version = "0.35.0" } -registry-platform-testing = { path = "crates/registry-platform-testing", version = "0.35.0" } +registry-review-client = { path = "crates/registry-review-client", version = "0.36.0" } +registry-review-protocol = { path = "crates/registry-review-protocol", version = "0.36.0" } +registry-thunderid-tooling = { path = "crates/registry-thunderid-tooling", version = "0.36.0" } +registry-casework = { path = "crates/registry-casework", version = "0.36.0" } +registry-casework-client-node = { path = "crates/registry-casework-client-node", version = "0.36.0" } +registry-casework-client-py = { path = "crates/registry-casework-client-py", version = "0.36.0" } +registry-caseworkctl = { path = "crates/registry-caseworkctl", version = "0.36.0" } +registry-casework-client = { path = "crates/registry-casework-client", version = "0.36.0" } +registry-casework-breg = { path = "crates/registry-casework-breg", version = "0.36.0" } +registry-casework-core = { path = "crates/registry-casework-core", version = "0.36.0" } +registry-discovery = { path = "crates/registry-discovery", version = "0.36.0", default-features = false } +registry-discovery-client = { path = "crates/registry-discovery-client", version = "0.36.0" } +registry-discovery-client-node = { path = "crates/registry-discovery-client-node", version = "0.36.0" } +registry-discovery-client-py = { path = "crates/registry-discovery-client-py", version = "0.36.0" } +registry-discovery-profile = { path = "crates/registry-discovery-profile", version = "0.36.0" } +registry-discoveryctl = { path = "crates/registry-discoveryctl", version = "0.36.0" } +registry-evidence = { path = "crates/registry-evidence", version = "0.36.0" } +registry-evidence-authoring = { path = "crates/registry-evidence-authoring", version = "0.36.0" } +registry-evidence-client = { path = "crates/registry-evidence-client", version = "0.36.0" } +registry-evidence-client-node = { path = "crates/registry-evidence-client-node", version = "0.36.0" } +registry-evidence-client-py = { path = "crates/registry-evidence-client-py", version = "0.36.0" } +registry-evidence-oid4vci = { path = "crates/registry-evidence-oid4vci", version = "0.36.0" } +registry-evidence-verifier = { path = "crates/registry-evidence-verifier", version = "0.36.0" } +registry-evidencectl = { path = "crates/registry-evidencectl", version = "0.36.0" } +registry-language-server = { path = "crates/registry-language-server", version = "0.36.0" } +registry-linkml = { path = "crates/registry-linkml", version = "0.36.0" } +registry-manifest-core = { path = "crates/registry-manifest-core", version = "0.36.0" } +registry-record = { path = "crates/registry-record", version = "0.36.0" } +registry-render = { path = "crates/registry-render", version = "0.36.0" } +registry-breg-client = { path = "crates/registry-breg-client", version = "0.36.0" } +registry-breg-client-node = { path = "crates/registry-breg-client-node", version = "0.36.0" } +registry-breg-client-py = { path = "crates/registry-breg-client-py", version = "0.36.0" } +registry-relay-http-contract = { path = "crates/registry-relay-http-contract", version = "0.36.0" } +registry-relay-client = { path = "crates/registry-relay-client", version = "0.36.0" } +registry-relay-client-node = { path = "crates/registry-relay-client-node", version = "0.36.0" } +registry-relay-client-py = { path = "crates/registry-relay-client-py", version = "0.36.0" } +registry-relay-v2 = { path = "crates/registry-relay-v2", version = "0.36.0" } +registry-relayctl = { path = "crates/registry-relayctl", version = "0.36.0" } +registry-scheduling = { path = "crates/registry-scheduling", version = "0.36.0" } +registry-scheduling-core = { path = "crates/registry-scheduling-core", version = "0.36.0" } +registry-schedulingctl = { path = "crates/registry-schedulingctl", version = "0.36.0" } +registry-scheduling-client = { path = "crates/registry-scheduling-client", version = "0.36.0" } +registry-breg = { path = "crates/registry-breg", version = "0.36.0", default-features = false } +registry-bregctl = { path = "crates/registry-bregctl", version = "0.36.0" } +registry-stack-client = { path = "crates/registry-stack-client", version = "0.36.0" } +registry-platform-audit = { path = "crates/registry-platform-audit", version = "0.36.0" } +registry-platform-authcommon = { path = "crates/registry-platform-authcommon", version = "0.36.0" } +registry-platform-buildinfo = { path = "crates/registry-platform-buildinfo", version = "0.36.0" } +registry-platform-calendar = { path = "crates/registry-platform-calendar", version = "0.36.0" } +registry-cli-reference = { path = "crates/registry-cli-reference", version = "0.36.0" } +registry-platform-canonical-json = { path = "crates/registry-platform-canonical-json", version = "0.36.0" } +registry-platform-config = { path = "crates/registry-platform-config", version = "0.36.0" } +registry-platform-crypto = { path = "crates/registry-platform-crypto", version = "0.36.0" } +registry-platform-hooks = { path = "crates/registry-platform-hooks", version = "0.36.0" } +registry-platform-httpsec = { path = "crates/registry-platform-httpsec", version = "0.36.0", default-features = false } +registry-platform-httputil = { path = "crates/registry-platform-httputil", version = "0.36.0" } +registry-platform-oidc = { path = "crates/registry-platform-oidc", version = "0.36.0" } +registry-platform-script = { path = "crates/registry-platform-script", version = "0.36.0" } +registry-platform-sdjwt = { path = "crates/registry-platform-sdjwt", version = "0.36.0" } +registry-platform-sqlite = { path = "crates/registry-platform-sqlite", version = "0.36.0" } +registry-platform-testing = { path = "crates/registry-platform-testing", version = "0.36.0" } anstream = { version = "1" } anstyle = { version = "1" } diff --git a/crates/registry-breg-client-node/index.js b/crates/registry-breg-client-node/index.js index e8b14c23b..28b4fd1dc 100644 --- a/crates/registry-breg-client-node/index.js +++ b/crates/registry-breg-client-node/index.js @@ -77,8 +77,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-android-arm64') const bindingPackageVersion = require('@registrystack/breg-client-native-android-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -93,8 +93,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-android-arm-eabi') const bindingPackageVersion = require('@registrystack/breg-client-native-android-arm-eabi/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -114,8 +114,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-win32-x64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-win32-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -130,8 +130,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-win32-x64-msvc') const bindingPackageVersion = require('@registrystack/breg-client-native-win32-x64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -147,8 +147,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-win32-ia32-msvc') const bindingPackageVersion = require('@registrystack/breg-client-native-win32-ia32-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -163,8 +163,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-win32-arm64-msvc') const bindingPackageVersion = require('@registrystack/breg-client-native-win32-arm64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -182,8 +182,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-darwin-universal') const bindingPackageVersion = require('@registrystack/breg-client-native-darwin-universal/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -198,8 +198,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-darwin-x64') const bindingPackageVersion = require('@registrystack/breg-client-native-darwin-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -214,8 +214,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-darwin-arm64') const bindingPackageVersion = require('@registrystack/breg-client-native-darwin-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -234,8 +234,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-freebsd-x64') const bindingPackageVersion = require('@registrystack/breg-client-native-freebsd-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -250,8 +250,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-freebsd-arm64') const bindingPackageVersion = require('@registrystack/breg-client-native-freebsd-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -271,8 +271,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-x64-musl') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-x64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -287,8 +287,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-x64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -305,8 +305,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-arm64-musl') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-arm64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -321,8 +321,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-arm64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-arm64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -339,8 +339,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-arm-musleabihf') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-arm-musleabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -355,8 +355,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-arm-gnueabihf') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-arm-gnueabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -373,8 +373,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-loong64-musl') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-loong64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -389,8 +389,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-loong64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-loong64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -407,8 +407,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-riscv64-musl') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-riscv64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -423,8 +423,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-riscv64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-riscv64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -440,8 +440,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-ppc64-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-ppc64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -456,8 +456,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-linux-s390x-gnu') const bindingPackageVersion = require('@registrystack/breg-client-native-linux-s390x-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -476,8 +476,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-openharmony-arm64') const bindingPackageVersion = require('@registrystack/breg-client-native-openharmony-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -492,8 +492,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-openharmony-x64') const bindingPackageVersion = require('@registrystack/breg-client-native-openharmony-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -508,8 +508,8 @@ function requireNative() { try { const binding = require('@registrystack/breg-client-native-openharmony-arm') const bindingPackageVersion = require('@registrystack/breg-client-native-openharmony-arm/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -648,8 +648,8 @@ if (!nativeBinding || forceWasi) { if (!candidateFailed) { if (process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { const bindingPackageVersion = require('@registrystack/breg-client-native-wasm32-wasi/package.json').version - if (bindingPackageVersion !== '0.35.0') { - throw new Error(`WASI binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0') { + throw new Error(`WASI binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } } wasiBinding = require('@registrystack/breg-client-native-wasm32-wasi') diff --git a/crates/registry-breg-client-node/package-lock.json b/crates/registry-breg-client-node/package-lock.json index 8b1ba0a10..7c8530928 100644 --- a/crates/registry-breg-client-node/package-lock.json +++ b/crates/registry-breg-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/breg-client-native", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/breg-client-native", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@napi-rs/cli": "3.10.5", diff --git a/crates/registry-breg-client-node/package.json b/crates/registry-breg-client-node/package.json index 833808527..abbb6e513 100644 --- a/crates/registry-breg-client-node/package.json +++ b/crates/registry-breg-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/breg-client-native", - "version": "0.35.0", + "version": "0.36.0", "description": "Internal Node.js native binding used by @registrystack/client.", "private": true, "license": "Apache-2.0", diff --git a/crates/registry-breg-client-py/Cargo.toml b/crates/registry-breg-client-py/Cargo.toml index df1ba3594..09576e982 100644 --- a/crates/registry-breg-client-py/Cargo.toml +++ b/crates/registry-breg-client-py/Cargo.toml @@ -22,7 +22,7 @@ extension-module = ["pyo3/extension-module"] pyo3.workspace = true # Keep the Rust SDK name distinct from this extension's Python module name. # Cargo passes both crates to Rustdoc, so sharing a name makes doctests ambiguous. -breg-client-sdk = { package = "registry-breg-client", path = "../registry-breg-client", version = "0.35.0" } +breg-client-sdk = { package = "registry-breg-client", path = "../registry-breg-client", version = "0.36.0" } registry-platform-crypto.workspace = true registry-platform-httputil.workspace = true serde.workspace = true diff --git a/crates/registry-breg-client-py/pyproject.toml b/crates/registry-breg-client-py/pyproject.toml index b5a366a88..dd76ad47f 100644 --- a/crates/registry-breg-client-py/pyproject.toml +++ b/crates/registry-breg-client-py/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "registry-breg-client-native" -version = "0.35.0" +version = "0.36.0" description = "Internal Base Registry Engine binding used by registry-stack-client." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-casework-client-node/index.js b/crates/registry-casework-client-node/index.js index 71fa493de..f6eb4dc90 100644 --- a/crates/registry-casework-client-node/index.js +++ b/crates/registry-casework-client-node/index.js @@ -77,8 +77,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-android-arm64') const bindingPackageVersion = require('@registrystack/casework-client-native-android-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -93,8 +93,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-android-arm-eabi') const bindingPackageVersion = require('@registrystack/casework-client-native-android-arm-eabi/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -114,8 +114,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-win32-x64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-win32-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -130,8 +130,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-win32-x64-msvc') const bindingPackageVersion = require('@registrystack/casework-client-native-win32-x64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -147,8 +147,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-win32-ia32-msvc') const bindingPackageVersion = require('@registrystack/casework-client-native-win32-ia32-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -163,8 +163,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-win32-arm64-msvc') const bindingPackageVersion = require('@registrystack/casework-client-native-win32-arm64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -182,8 +182,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-darwin-universal') const bindingPackageVersion = require('@registrystack/casework-client-native-darwin-universal/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -198,8 +198,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-darwin-x64') const bindingPackageVersion = require('@registrystack/casework-client-native-darwin-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -214,8 +214,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-darwin-arm64') const bindingPackageVersion = require('@registrystack/casework-client-native-darwin-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -234,8 +234,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-freebsd-x64') const bindingPackageVersion = require('@registrystack/casework-client-native-freebsd-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -250,8 +250,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-freebsd-arm64') const bindingPackageVersion = require('@registrystack/casework-client-native-freebsd-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -271,8 +271,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-x64-musl') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-x64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -287,8 +287,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-x64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -305,8 +305,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-arm64-musl') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-arm64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -321,8 +321,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-arm64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-arm64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -339,8 +339,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-arm-musleabihf') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-arm-musleabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -355,8 +355,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-arm-gnueabihf') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-arm-gnueabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -373,8 +373,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-loong64-musl') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-loong64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -389,8 +389,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-loong64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-loong64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -407,8 +407,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-riscv64-musl') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-riscv64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -423,8 +423,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-riscv64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-riscv64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -440,8 +440,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-ppc64-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-ppc64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -456,8 +456,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-linux-s390x-gnu') const bindingPackageVersion = require('@registrystack/casework-client-native-linux-s390x-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -476,8 +476,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-openharmony-arm64') const bindingPackageVersion = require('@registrystack/casework-client-native-openharmony-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -492,8 +492,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-openharmony-x64') const bindingPackageVersion = require('@registrystack/casework-client-native-openharmony-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -508,8 +508,8 @@ function requireNative() { try { const binding = require('@registrystack/casework-client-native-openharmony-arm') const bindingPackageVersion = require('@registrystack/casework-client-native-openharmony-arm/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -648,8 +648,8 @@ if (!nativeBinding || forceWasi) { if (!candidateFailed) { if (process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { const bindingPackageVersion = require('@registrystack/casework-client-native-wasm32-wasi/package.json').version - if (bindingPackageVersion !== '0.35.0') { - throw new Error(`WASI binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0') { + throw new Error(`WASI binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } } wasiBinding = require('@registrystack/casework-client-native-wasm32-wasi') diff --git a/crates/registry-casework-client-node/package-lock.json b/crates/registry-casework-client-node/package-lock.json index 0d63ed5db..9c7a4fbd5 100644 --- a/crates/registry-casework-client-node/package-lock.json +++ b/crates/registry-casework-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/casework-client-native", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/casework-client-native", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@napi-rs/cli": "3.10.5", diff --git a/crates/registry-casework-client-node/package.json b/crates/registry-casework-client-node/package.json index b75ede528..8ca4e62ad 100644 --- a/crates/registry-casework-client-node/package.json +++ b/crates/registry-casework-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/casework-client-native", - "version": "0.35.0", + "version": "0.36.0", "description": "Internal Node.js native binding used by @registrystack/client.", "private": true, "license": "Apache-2.0", diff --git a/crates/registry-casework-client-py/Cargo.toml b/crates/registry-casework-client-py/Cargo.toml index b35a0ccc8..777541f0b 100644 --- a/crates/registry-casework-client-py/Cargo.toml +++ b/crates/registry-casework-client-py/Cargo.toml @@ -21,7 +21,7 @@ extension-module = ["pyo3/extension-module"] [dependencies] pyo3.workspace = true # Keep the SDK name distinct from this extension's Python module name. -casework-client-sdk = { package = "registry-casework-client", path = "../registry-casework-client", version = "0.35.0" } +casework-client-sdk = { package = "registry-casework-client", path = "../registry-casework-client", version = "0.36.0" } serde.workspace = true serde_json.workspace = true tokio.workspace = true diff --git a/crates/registry-casework-client-py/pyproject.toml b/crates/registry-casework-client-py/pyproject.toml index 1f088d382..b7ef151cc 100644 --- a/crates/registry-casework-client-py/pyproject.toml +++ b/crates/registry-casework-client-py/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "registry-casework-client-native" -version = "0.35.0" +version = "0.36.0" description = "Internal Casework binding used by registry-stack-client." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-discovery-client-node/index.js b/crates/registry-discovery-client-node/index.js index 031734013..dd6894743 100644 --- a/crates/registry-discovery-client-node/index.js +++ b/crates/registry-discovery-client-node/index.js @@ -77,8 +77,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-android-arm64') const bindingPackageVersion = require('@registrystack/discovery-client-android-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -93,8 +93,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-android-arm-eabi') const bindingPackageVersion = require('@registrystack/discovery-client-android-arm-eabi/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -114,8 +114,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-win32-x64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-win32-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -130,8 +130,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-win32-x64-msvc') const bindingPackageVersion = require('@registrystack/discovery-client-win32-x64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -147,8 +147,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-win32-ia32-msvc') const bindingPackageVersion = require('@registrystack/discovery-client-win32-ia32-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -163,8 +163,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-win32-arm64-msvc') const bindingPackageVersion = require('@registrystack/discovery-client-win32-arm64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -182,8 +182,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-darwin-universal') const bindingPackageVersion = require('@registrystack/discovery-client-darwin-universal/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -198,8 +198,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-darwin-x64') const bindingPackageVersion = require('@registrystack/discovery-client-darwin-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -214,8 +214,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-darwin-arm64') const bindingPackageVersion = require('@registrystack/discovery-client-darwin-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -234,8 +234,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-freebsd-x64') const bindingPackageVersion = require('@registrystack/discovery-client-freebsd-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -250,8 +250,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-freebsd-arm64') const bindingPackageVersion = require('@registrystack/discovery-client-freebsd-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -271,8 +271,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-x64-musl') const bindingPackageVersion = require('@registrystack/discovery-client-linux-x64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -287,8 +287,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-x64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -305,8 +305,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-arm64-musl') const bindingPackageVersion = require('@registrystack/discovery-client-linux-arm64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -321,8 +321,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-arm64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-arm64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -339,8 +339,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-arm-musleabihf') const bindingPackageVersion = require('@registrystack/discovery-client-linux-arm-musleabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -355,8 +355,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-arm-gnueabihf') const bindingPackageVersion = require('@registrystack/discovery-client-linux-arm-gnueabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -373,8 +373,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-loong64-musl') const bindingPackageVersion = require('@registrystack/discovery-client-linux-loong64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -389,8 +389,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-loong64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-loong64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -407,8 +407,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-riscv64-musl') const bindingPackageVersion = require('@registrystack/discovery-client-linux-riscv64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -423,8 +423,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-riscv64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-riscv64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -440,8 +440,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-ppc64-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-ppc64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -456,8 +456,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-linux-s390x-gnu') const bindingPackageVersion = require('@registrystack/discovery-client-linux-s390x-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -476,8 +476,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-openharmony-arm64') const bindingPackageVersion = require('@registrystack/discovery-client-openharmony-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -492,8 +492,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-openharmony-x64') const bindingPackageVersion = require('@registrystack/discovery-client-openharmony-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -508,8 +508,8 @@ function requireNative() { try { const binding = require('@registrystack/discovery-client-openharmony-arm') const bindingPackageVersion = require('@registrystack/discovery-client-openharmony-arm/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -648,8 +648,8 @@ if (!nativeBinding || forceWasi) { if (!candidateFailed) { if (process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { const bindingPackageVersion = require('@registrystack/discovery-client-wasm32-wasi/package.json').version - if (bindingPackageVersion !== '0.35.0') { - throw new Error(`WASI binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0') { + throw new Error(`WASI binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } } wasiBinding = require('@registrystack/discovery-client-wasm32-wasi') diff --git a/crates/registry-discovery-client-node/npm/darwin-arm64/package.json b/crates/registry-discovery-client-node/npm/darwin-arm64/package.json index 79d9a96a9..87b6062da 100644 --- a/crates/registry-discovery-client-node/npm/darwin-arm64/package.json +++ b/crates/registry-discovery-client-node/npm/darwin-arm64/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/discovery-client-darwin-arm64", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["arm64"], "main": "discovery-client.darwin-arm64.node", "files": ["discovery-client.darwin-arm64.node"], diff --git a/crates/registry-discovery-client-node/npm/linux-arm64-gnu/package.json b/crates/registry-discovery-client-node/npm/linux-arm64-gnu/package.json index befe612a5..9399debf8 100644 --- a/crates/registry-discovery-client-node/npm/linux-arm64-gnu/package.json +++ b/crates/registry-discovery-client-node/npm/linux-arm64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/discovery-client-linux-arm64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["arm64"], "main": "discovery-client.linux-arm64-gnu.node", "files": ["discovery-client.linux-arm64-gnu.node"], diff --git a/crates/registry-discovery-client-node/npm/linux-x64-gnu/package.json b/crates/registry-discovery-client-node/npm/linux-x64-gnu/package.json index 378b85979..09e16088f 100644 --- a/crates/registry-discovery-client-node/npm/linux-x64-gnu/package.json +++ b/crates/registry-discovery-client-node/npm/linux-x64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/discovery-client-linux-x64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["x64"], "main": "discovery-client.linux-x64-gnu.node", "files": ["discovery-client.linux-x64-gnu.node"], diff --git a/crates/registry-discovery-client-node/package-lock.json b/crates/registry-discovery-client-node/package-lock.json index 7dcef81af..b180fa0ee 100644 --- a/crates/registry-discovery-client-node/package-lock.json +++ b/crates/registry-discovery-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/discovery-client", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/discovery-client", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@napi-rs/cli": "3.10.5", diff --git a/crates/registry-discovery-client-node/package.json b/crates/registry-discovery-client-node/package.json index 8d0da5d65..7d9562678 100644 --- a/crates/registry-discovery-client-node/package.json +++ b/crates/registry-discovery-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/discovery-client", - "version": "0.35.0", + "version": "0.36.0", "description": "Node.js binding for the Registry Discovery client, via napi-rs.", "license": "Apache-2.0", "publishConfig": { "access": "public", "provenance": true }, diff --git a/crates/registry-discovery-client-py/Cargo.toml b/crates/registry-discovery-client-py/Cargo.toml index a2ca94f58..5479362ad 100644 --- a/crates/registry-discovery-client-py/Cargo.toml +++ b/crates/registry-discovery-client-py/Cargo.toml @@ -19,7 +19,7 @@ workspace = true extension-module = ["pyo3/extension-module"] [dependencies] -discovery-client-sdk = { package = "registry-discovery-client", path = "../registry-discovery-client", version = "0.35.0" } +discovery-client-sdk = { package = "registry-discovery-client", path = "../registry-discovery-client", version = "0.36.0" } pyo3.workspace = true serde.workspace = true serde_json.workspace = true diff --git a/crates/registry-discovery-client-py/pyproject.toml b/crates/registry-discovery-client-py/pyproject.toml index cb55a687d..45324d029 100644 --- a/crates/registry-discovery-client-py/pyproject.toml +++ b/crates/registry-discovery-client-py/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "registry-discovery-client" -version = "0.35.0" +version = "0.36.0" description = "Python binding for the Registry Discovery client, via PyO3." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-evidence-client-node/index.js b/crates/registry-evidence-client-node/index.js index bfc2366ec..25c2f8e0a 100644 --- a/crates/registry-evidence-client-node/index.js +++ b/crates/registry-evidence-client-node/index.js @@ -77,8 +77,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-android-arm64') const bindingPackageVersion = require('@registrystack/evidence-client-android-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -93,8 +93,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-android-arm-eabi') const bindingPackageVersion = require('@registrystack/evidence-client-android-arm-eabi/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -114,8 +114,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-win32-x64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-win32-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -130,8 +130,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-win32-x64-msvc') const bindingPackageVersion = require('@registrystack/evidence-client-win32-x64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -147,8 +147,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-win32-ia32-msvc') const bindingPackageVersion = require('@registrystack/evidence-client-win32-ia32-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -163,8 +163,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-win32-arm64-msvc') const bindingPackageVersion = require('@registrystack/evidence-client-win32-arm64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -182,8 +182,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-darwin-universal') const bindingPackageVersion = require('@registrystack/evidence-client-darwin-universal/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -198,8 +198,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-darwin-x64') const bindingPackageVersion = require('@registrystack/evidence-client-darwin-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -214,8 +214,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-darwin-arm64') const bindingPackageVersion = require('@registrystack/evidence-client-darwin-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -234,8 +234,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-freebsd-x64') const bindingPackageVersion = require('@registrystack/evidence-client-freebsd-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -250,8 +250,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-freebsd-arm64') const bindingPackageVersion = require('@registrystack/evidence-client-freebsd-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -271,8 +271,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-x64-musl') const bindingPackageVersion = require('@registrystack/evidence-client-linux-x64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -287,8 +287,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-x64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -305,8 +305,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-arm64-musl') const bindingPackageVersion = require('@registrystack/evidence-client-linux-arm64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -321,8 +321,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-arm64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-arm64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -339,8 +339,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-arm-musleabihf') const bindingPackageVersion = require('@registrystack/evidence-client-linux-arm-musleabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -355,8 +355,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-arm-gnueabihf') const bindingPackageVersion = require('@registrystack/evidence-client-linux-arm-gnueabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -373,8 +373,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-loong64-musl') const bindingPackageVersion = require('@registrystack/evidence-client-linux-loong64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -389,8 +389,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-loong64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-loong64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -407,8 +407,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-riscv64-musl') const bindingPackageVersion = require('@registrystack/evidence-client-linux-riscv64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -423,8 +423,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-riscv64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-riscv64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -440,8 +440,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-ppc64-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-ppc64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -456,8 +456,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-linux-s390x-gnu') const bindingPackageVersion = require('@registrystack/evidence-client-linux-s390x-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -476,8 +476,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-openharmony-arm64') const bindingPackageVersion = require('@registrystack/evidence-client-openharmony-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -492,8 +492,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-openharmony-x64') const bindingPackageVersion = require('@registrystack/evidence-client-openharmony-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -508,8 +508,8 @@ function requireNative() { try { const binding = require('@registrystack/evidence-client-openharmony-arm') const bindingPackageVersion = require('@registrystack/evidence-client-openharmony-arm/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -648,8 +648,8 @@ if (!nativeBinding || forceWasi) { if (!candidateFailed) { if (process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { const bindingPackageVersion = require('@registrystack/evidence-client-wasm32-wasi/package.json').version - if (bindingPackageVersion !== '0.35.0') { - throw new Error(`WASI binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0') { + throw new Error(`WASI binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } } wasiBinding = require('@registrystack/evidence-client-wasm32-wasi') diff --git a/crates/registry-evidence-client-node/npm/darwin-arm64/package.json b/crates/registry-evidence-client-node/npm/darwin-arm64/package.json index 8695bd7ba..c26cdb0a7 100644 --- a/crates/registry-evidence-client-node/npm/darwin-arm64/package.json +++ b/crates/registry-evidence-client-node/npm/darwin-arm64/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/evidence-client-darwin-arm64", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["arm64"], "main": "evidence-client.darwin-arm64.node", "files": ["evidence-client.darwin-arm64.node"], diff --git a/crates/registry-evidence-client-node/npm/linux-arm64-gnu/package.json b/crates/registry-evidence-client-node/npm/linux-arm64-gnu/package.json index 7c2d753bf..5c34a6ba5 100644 --- a/crates/registry-evidence-client-node/npm/linux-arm64-gnu/package.json +++ b/crates/registry-evidence-client-node/npm/linux-arm64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/evidence-client-linux-arm64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["arm64"], "main": "evidence-client.linux-arm64-gnu.node", "files": ["evidence-client.linux-arm64-gnu.node"], diff --git a/crates/registry-evidence-client-node/npm/linux-x64-gnu/package.json b/crates/registry-evidence-client-node/npm/linux-x64-gnu/package.json index 35804fdf0..bf8f75b7b 100644 --- a/crates/registry-evidence-client-node/npm/linux-x64-gnu/package.json +++ b/crates/registry-evidence-client-node/npm/linux-x64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/evidence-client-linux-x64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": ["x64"], "main": "evidence-client.linux-x64-gnu.node", "files": ["evidence-client.linux-x64-gnu.node"], diff --git a/crates/registry-evidence-client-node/package-lock.json b/crates/registry-evidence-client-node/package-lock.json index e9c51de8b..1e6e86ac1 100644 --- a/crates/registry-evidence-client-node/package-lock.json +++ b/crates/registry-evidence-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/evidence-client", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/evidence-client", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@napi-rs/cli": "3.10.5" diff --git a/crates/registry-evidence-client-node/package.json b/crates/registry-evidence-client-node/package.json index ef93ad6c2..23a99440e 100644 --- a/crates/registry-evidence-client-node/package.json +++ b/crates/registry-evidence-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/evidence-client", - "version": "0.35.0", + "version": "0.36.0", "description": "Node.js binding for the Evidence relying-party client, via napi-rs.", "license": "Apache-2.0", "publishConfig": { "access": "public", "provenance": true }, diff --git a/crates/registry-evidence-client-py/Cargo.toml b/crates/registry-evidence-client-py/Cargo.toml index 9296945ef..f87b70818 100644 --- a/crates/registry-evidence-client-py/Cargo.toml +++ b/crates/registry-evidence-client-py/Cargo.toml @@ -29,7 +29,7 @@ chrono.workspace = true # multiple candidates for rmeta dependency`, which no `use` path syntax can # resolve). One consistent alias, used everywhere this crate reaches the SDK, # avoids that rather than special-casing test code against production code. -evidence-client-sdk = { package = "registry-evidence-client", path = "../registry-evidence-client", version = "0.35.0" } +evidence-client-sdk = { package = "registry-evidence-client", path = "../registry-evidence-client", version = "0.36.0" } pyo3.workspace = true registry-platform-crypto.workspace = true registry-platform-httputil.workspace = true diff --git a/crates/registry-evidence-client-py/pyproject.toml b/crates/registry-evidence-client-py/pyproject.toml index f1fc51092..e90912a28 100644 --- a/crates/registry-evidence-client-py/pyproject.toml +++ b/crates/registry-evidence-client-py/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "registry-evidence-client" -version = "0.35.0" +version = "0.36.0" description = "Python binding for the Evidence relying-party client, via PyO3." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-relay-client-node/index.js b/crates/registry-relay-client-node/index.js index 7d9804df7..7d84b1939 100644 --- a/crates/registry-relay-client-node/index.js +++ b/crates/registry-relay-client-node/index.js @@ -77,8 +77,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-android-arm64') const bindingPackageVersion = require('@registrystack/relay-client-android-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -93,8 +93,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-android-arm-eabi') const bindingPackageVersion = require('@registrystack/relay-client-android-arm-eabi/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -114,8 +114,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-win32-x64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-win32-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -130,8 +130,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-win32-x64-msvc') const bindingPackageVersion = require('@registrystack/relay-client-win32-x64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -147,8 +147,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-win32-ia32-msvc') const bindingPackageVersion = require('@registrystack/relay-client-win32-ia32-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -163,8 +163,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-win32-arm64-msvc') const bindingPackageVersion = require('@registrystack/relay-client-win32-arm64-msvc/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -182,8 +182,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-darwin-universal') const bindingPackageVersion = require('@registrystack/relay-client-darwin-universal/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -198,8 +198,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-darwin-x64') const bindingPackageVersion = require('@registrystack/relay-client-darwin-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -214,8 +214,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-darwin-arm64') const bindingPackageVersion = require('@registrystack/relay-client-darwin-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -234,8 +234,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-freebsd-x64') const bindingPackageVersion = require('@registrystack/relay-client-freebsd-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -250,8 +250,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-freebsd-arm64') const bindingPackageVersion = require('@registrystack/relay-client-freebsd-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -271,8 +271,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-x64-musl') const bindingPackageVersion = require('@registrystack/relay-client-linux-x64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -287,8 +287,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-x64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-x64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -305,8 +305,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-arm64-musl') const bindingPackageVersion = require('@registrystack/relay-client-linux-arm64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -321,8 +321,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-arm64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-arm64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -339,8 +339,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-arm-musleabihf') const bindingPackageVersion = require('@registrystack/relay-client-linux-arm-musleabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -355,8 +355,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-arm-gnueabihf') const bindingPackageVersion = require('@registrystack/relay-client-linux-arm-gnueabihf/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -373,8 +373,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-loong64-musl') const bindingPackageVersion = require('@registrystack/relay-client-linux-loong64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -389,8 +389,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-loong64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-loong64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -407,8 +407,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-riscv64-musl') const bindingPackageVersion = require('@registrystack/relay-client-linux-riscv64-musl/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -423,8 +423,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-riscv64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-riscv64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -440,8 +440,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-ppc64-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-ppc64-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -456,8 +456,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-linux-s390x-gnu') const bindingPackageVersion = require('@registrystack/relay-client-linux-s390x-gnu/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -476,8 +476,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-openharmony-arm64') const bindingPackageVersion = require('@registrystack/relay-client-openharmony-arm64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -492,8 +492,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-openharmony-x64') const bindingPackageVersion = require('@registrystack/relay-client-openharmony-x64/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -508,8 +508,8 @@ function requireNative() { try { const binding = require('@registrystack/relay-client-openharmony-arm') const bindingPackageVersion = require('@registrystack/relay-client-openharmony-arm/package.json').version - if (bindingPackageVersion !== '0.35.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { - throw new Error(`Native binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0' && process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { + throw new Error(`Native binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } return binding } catch (e) { @@ -648,8 +648,8 @@ if (!nativeBinding || forceWasi) { if (!candidateFailed) { if (process.env.NAPI_RS_ENFORCE_VERSION_CHECK && process.env.NAPI_RS_ENFORCE_VERSION_CHECK !== '0') { const bindingPackageVersion = require('@registrystack/relay-client-wasm32-wasi/package.json').version - if (bindingPackageVersion !== '0.35.0') { - throw new Error(`WASI binding package version mismatch, expected 0.35.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) + if (bindingPackageVersion !== '0.36.0') { + throw new Error(`WASI binding package version mismatch, expected 0.36.0 but got ${bindingPackageVersion}. You can reinstall dependencies to fix this issue.`) } } wasiBinding = require('@registrystack/relay-client-wasm32-wasi') diff --git a/crates/registry-relay-client-node/npm/darwin-arm64/package.json b/crates/registry-relay-client-node/npm/darwin-arm64/package.json index 0eb1c56fd..cbc89f55e 100644 --- a/crates/registry-relay-client-node/npm/darwin-arm64/package.json +++ b/crates/registry-relay-client-node/npm/darwin-arm64/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/relay-client-darwin-arm64", - "version": "0.35.0", + "version": "0.36.0", "cpu": [ "arm64" ], diff --git a/crates/registry-relay-client-node/npm/linux-arm64-gnu/package.json b/crates/registry-relay-client-node/npm/linux-arm64-gnu/package.json index 3473e8f12..ff26e0fd2 100644 --- a/crates/registry-relay-client-node/npm/linux-arm64-gnu/package.json +++ b/crates/registry-relay-client-node/npm/linux-arm64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/relay-client-linux-arm64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": [ "arm64" ], diff --git a/crates/registry-relay-client-node/npm/linux-x64-gnu/package.json b/crates/registry-relay-client-node/npm/linux-x64-gnu/package.json index 9e38cbb41..b09ee7d47 100644 --- a/crates/registry-relay-client-node/npm/linux-x64-gnu/package.json +++ b/crates/registry-relay-client-node/npm/linux-x64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/relay-client-linux-x64-gnu", - "version": "0.35.0", + "version": "0.36.0", "cpu": [ "x64" ], diff --git a/crates/registry-relay-client-node/package-lock.json b/crates/registry-relay-client-node/package-lock.json index aa5009061..16e8d0f5b 100644 --- a/crates/registry-relay-client-node/package-lock.json +++ b/crates/registry-relay-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/relay-client", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/relay-client", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@napi-rs/cli": "3.10.5", diff --git a/crates/registry-relay-client-node/package.json b/crates/registry-relay-client-node/package.json index df0a7bbc7..2292a5c8e 100644 --- a/crates/registry-relay-client-node/package.json +++ b/crates/registry-relay-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/relay-client", - "version": "0.35.0", + "version": "0.36.0", "description": "Node.js binding for the Registry Relay V2 client, via napi-rs.", "license": "Apache-2.0", "publishConfig": { "access": "public", "provenance": true }, diff --git a/crates/registry-relay-client-py/Cargo.toml b/crates/registry-relay-client-py/Cargo.toml index 93e641831..f73c82772 100644 --- a/crates/registry-relay-client-py/Cargo.toml +++ b/crates/registry-relay-client-py/Cargo.toml @@ -22,7 +22,7 @@ extension-module = ["pyo3/extension-module"] pyo3.workspace = true registry-platform-crypto.workspace = true registry-platform-httputil.workspace = true -relay-client-sdk = { package = "registry-relay-client", path = "../registry-relay-client", version = "0.35.0" } +relay-client-sdk = { package = "registry-relay-client", path = "../registry-relay-client", version = "0.36.0" } serde.workspace = true serde_json.workspace = true tokio.workspace = true diff --git a/crates/registry-relay-client-py/pyproject.toml b/crates/registry-relay-client-py/pyproject.toml index b64089db2..cfe0ecf18 100644 --- a/crates/registry-relay-client-py/pyproject.toml +++ b/crates/registry-relay-client-py/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "registry-relay-client" -version = "0.35.0" +version = "0.36.0" description = "Python binding for the Registry Relay V2 client, via PyO3." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-stack-client-node/native.js b/crates/registry-stack-client-node/native.js index f64d313d5..27decc87a 100644 --- a/crates/registry-stack-client-node/native.js +++ b/crates/registry-stack-client-node/native.js @@ -1,6 +1,6 @@ 'use strict'; -const PACKAGE_VERSION = '0.35.0'; +const PACKAGE_VERSION = '0.36.0'; const PRODUCTS = new Set(['discovery', 'evidence', 'relay', 'breg', 'casework']); function target() { diff --git a/crates/registry-stack-client-node/npm/darwin-arm64/package.json b/crates/registry-stack-client-node/npm/darwin-arm64/package.json index 0e7e9f21d..43e70c453 100644 --- a/crates/registry-stack-client-node/npm/darwin-arm64/package.json +++ b/crates/registry-stack-client-node/npm/darwin-arm64/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/client-darwin-arm64", - "version": "0.35.0", + "version": "0.36.0", "description": "Registry Stack unified native clients for macOS arm64.", "license": "Apache-2.0", "publishConfig": { "access": "public" }, diff --git a/crates/registry-stack-client-node/npm/linux-arm64-gnu/package.json b/crates/registry-stack-client-node/npm/linux-arm64-gnu/package.json index 196e967d3..013eb9be0 100644 --- a/crates/registry-stack-client-node/npm/linux-arm64-gnu/package.json +++ b/crates/registry-stack-client-node/npm/linux-arm64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/client-linux-arm64-gnu", - "version": "0.35.0", + "version": "0.36.0", "description": "Registry Stack unified native clients for Linux arm64 glibc.", "license": "Apache-2.0", "publishConfig": { "access": "public" }, diff --git a/crates/registry-stack-client-node/npm/linux-x64-gnu/package.json b/crates/registry-stack-client-node/npm/linux-x64-gnu/package.json index 53f3fc394..bf2837040 100644 --- a/crates/registry-stack-client-node/npm/linux-x64-gnu/package.json +++ b/crates/registry-stack-client-node/npm/linux-x64-gnu/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/client-linux-x64-gnu", - "version": "0.35.0", + "version": "0.36.0", "description": "Registry Stack unified native clients for Linux x64 glibc.", "license": "Apache-2.0", "publishConfig": { "access": "public" }, diff --git a/crates/registry-stack-client-node/package-lock.json b/crates/registry-stack-client-node/package-lock.json index f19220937..a0366fe34 100644 --- a/crates/registry-stack-client-node/package-lock.json +++ b/crates/registry-stack-client-node/package-lock.json @@ -1,12 +1,12 @@ { "name": "@registrystack/client", - "version": "0.35.0", + "version": "0.36.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@registrystack/client", - "version": "0.35.0", + "version": "0.36.0", "license": "Apache-2.0", "devDependencies": { "@types/node": "22.20.4", diff --git a/crates/registry-stack-client-node/package.json b/crates/registry-stack-client-node/package.json index 089b7caee..9e98cbaaa 100644 --- a/crates/registry-stack-client-node/package.json +++ b/crates/registry-stack-client-node/package.json @@ -1,6 +1,6 @@ { "name": "@registrystack/client", - "version": "0.35.0", + "version": "0.36.0", "description": "Unified Node.js client for Registry Stack products.", "license": "Apache-2.0", "homepage": "https://docs.registrystack.org/reference/client-api/", diff --git a/crates/registry-stack-client-py/pyproject.toml b/crates/registry-stack-client-py/pyproject.toml index 16b08ea02..500014943 100644 --- a/crates/registry-stack-client-py/pyproject.toml +++ b/crates/registry-stack-client-py/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "registry-stack-client" -version = "0.35.0" +version = "0.36.0" description = "Unified Python client for Registry Stack products." readme = "README.md" license = { text = "Apache-2.0" } diff --git a/crates/registry-stack-client-py/python/registry_client/__init__.py b/crates/registry-stack-client-py/python/registry_client/__init__.py index 5b8af152a..a542eeedb 100644 --- a/crates/registry-stack-client-py/python/registry_client/__init__.py +++ b/crates/registry-stack-client-py/python/registry_client/__init__.py @@ -7,4 +7,4 @@ import registry_client.relay as relay __all__ = ["breg", "casework", "discovery", "evidence", "relay"] -__version__ = "0.35.0" +__version__ = "0.36.0" diff --git a/docs/site/src/content/docs/changelog.mdx b/docs/site/src/content/docs/changelog.mdx index f672f8dd0..f47bb5a7d 100644 --- a/docs/site/src/content/docs/changelog.mdx +++ b/docs/site/src/content/docs/changelog.mdx @@ -18,6 +18,26 @@ relevant product pages on this site rather than duplicating release notes. ## Unreleased +## v0.36.0 beta-48 + +- BREAKING: Base Registry Engine (BReg) records every activation in a database ledger and ships + unsigned, environment-neutral packages named by their package digest. Package signing is removed, + so upgrade to v0.35.0 first: this release does not read a predecessor package without a + `SHA256SUMS` envelope. `bregctl plan` and `bregctl status` report what an apply would change and + what the database activated, and `bregctl apply` without `--initial` adopts a database an earlier + release installed. `package.environment` and `package.instanceId` move to the runtime file's + `identity`, `package.sequence` is removed, and the runtime `package` block keeps only `root` and + `expectedDigest`. Every package's schema fingerprint changes, and a project that declared a + package identity compiles to a new `registryRevision`, so rebuild each package with the v0.36.0 + `bregctl package`. In split-role mode, plan, apply, and startup refuse a runtime role that can + write the ledger or the registry state. After upgrading BReg, re-import each BReg source into + Evidence once and repin each BReg source in Casework. See + [Upgrade in this order](../operate/advanced/upgrade-and-retire/#upgrade-in-this-order). + +{/* Evidence: crates/registry-breg/src/migration.rs, package_ledger_entry(), adopt_verified_package(), + and read_activation_status(); crates/registry-bregctl/src/apply_lifecycle.rs, plan() and status(); + crates/registry-breg/src/contract.rs, removed_project_field_diagnostics(). */} + - The shared audit writer recovers an active file whose final line a crash tore: the next start moves those bytes to the owner-only side file `.torn`, truncates to the last complete line, and logs it, instead of refusing to start. A configured `audit.path` ending in a companion @@ -39,9 +59,11 @@ relevant product pages on this site rather than duplicating release notes. fixture reports use `evaluatedCases`, `failingCase`, `expectedClass`, and `observedClass`. An unreadable file or a missing local dev session exits `3` instead of `1`. Commands that read one project take it as a positional - ``; the former `--project` flag stays accepted but hidden. The - `access` commands and `audit show` still act on the current directory, and - `doctor` keeps its `--project` option. `test` + ``; the former `--project` flag stays accepted but hidden on them. + `source import`, `source diff`, `source update`, and `target new` keep + their documented `--project`, the `access` commands and `audit show` still + act on the current directory, and `doctor` keeps its `--project` option. + `test` and `fixtures run` accept `--format junit`, and `dev start --name-prefix` sets the local issuer container name prefix. Update scripts that read `operation` or snake_case fixture keys. See diff --git a/docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx b/docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx index e96b2de28..0e068a329 100644 --- a/docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx +++ b/docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx @@ -1,6 +1,6 @@ --- title: Upgrade and retire a deployment -description: Upgrade Base Registry Engine, Registry Casework, Evidence, and their clients to a new release in a safe order, and retire a deployment without losing the records it must leave behind. +description: Upgrade Base Registry Engine, Registry Casework, Evidence, Registry Scheduling, and their clients to a new release in a safe order, and retire a deployment without losing the records it must leave behind. status: current owner: registry-docs source_repos: @@ -11,8 +11,8 @@ locale: en standards_referenced: [] --- -Use this runbook when you move a deployment of Base Registry Engine (BReg), Registry Casework, and -Evidence to a new release, or take it out of service. Each product's own guide carries its upgrade +Use this runbook when you move a deployment of Base Registry Engine (BReg), Registry Casework, +Evidence, and Registry Scheduling to a new release, or take it out of service. Each product's own guide carries its upgrade command; this page gives the order across products, the version rule that order enforces, and what each product must leave behind when it is retired. @@ -50,22 +50,29 @@ reverse path. See [Compatibility direction](../../../reference/api-stability/#co ## Upgrade in this order BReg goes first, because Casework and Evidence both read it. Casework follows because it refuses -a BReg of another release. Evidence and its wallet-facing front end come last. Rehearse the whole +a BReg of another release. Evidence and its wallet-facing front end come next. Scheduling reads +none of them and upgrades on its own, before the clients. Each release's notes list, per product, +the project and runtime-file changes its upgrade needs; make them in the step that upgrades that +product. Rehearse the whole sequence on a restored copy first, as [Run a disaster-recovery drill](../back-up-and-restore/#run-a-disaster-recovery-drill) describes. -1. **Back up both databases.** Take the BReg `pg_dump` and the Casework `pg_dump`, and copy both - products' packages and runtime files. These backups are the only way back; see +1. **Back up every database.** Take the BReg and Casework `pg_dump`s, and the Scheduling one + when it runs, and copy those products' packages and runtime files. These backups are the only way back; see [Roll back](#roll-back). 2. **Stop `evidence-oid4vci`**, when it runs. Its outstanding offers end here; see [Operational limits](../../../configure/evidence-oid4vci/#operational-limits). 3. **Pause and drain Evidence traffic** for every question that reads BReg, or pause the whole instance when you cannot drain one question at a time. Keep the previous Evidence candidate. -4. **Upgrade BReg.** Rebuild the deployed project unchanged with the new `bregctl package`, - point `package.root` at the rebuilt package, check it against the live database with - `bregctl plan --package` naming the same directory, `apply` it, run `bregctl verify`, and - restart every `breg` process on the new binary; `bregctl status` confirms what the database - activated. A model change follows as its own successor; see +4. **Upgrade BReg.** Make the project and runtime-file changes the release notes list, rebuild + the deployed project with no model change using the new `bregctl test` and `bregctl package + --test-receipt FILE --output BUILD` (a receipt from the earlier release is not accepted), point + `package.root` at `BUILD/package` (and `package.expectedDigest`, when set, at the package + digest it reports, `packageDigest` with `--format json`), check it against the live database with + `bregctl plan --runtime-config FILE --package BUILD/package` naming the same directory, apply + it with `bregctl apply --runtime-config FILE --package BUILD/package`, run `bregctl verify --runtime-config + FILE`, and restart every `breg` process on the new binary; `bregctl status --runtime-config + FILE` confirms what the database activated. A model change follows as its own successor; see [Activate the successor](../../breg-changes/#activate-the-successor). From a release before the activation ledger, this first `apply` adopts the database as it stands: `package.root` and `--package` must both name the rebuilt package, which must describe the schema the @@ -80,13 +87,31 @@ sequence on a restored copy first, as before it finishes, rerun it with the same `database.roles`: a retry under other roles is refused as `apply.resume.roles_differ`, naming the roles the activation started with. A new package applied under `database.roles` other than the ones the active activation serves with is refused as `apply.successor.roles_differ` before maintenance; apply the active package under the new roles first, then the new package. A role change, the active package applied under other `database.roles`, cannot be assessed by `bregctl migration reconcile`: when one stops before it finishes, fix the cause and rerun the same apply, which resumes it. Casework reports each BReg source as unavailable from here until step 5 finishes. -5. **Upgrade Casework.** Settle pending attempts first, since an upgrade can strand them. Run - `caseworkctl plan` and `caseworkctl apply` with the new binaries, then start `casework` and run - `caseworkctl doctor`; see [Plan, apply, and serve](../../casework/#plan-apply-and-serve). -6. **Upgrade Evidence.** Package a fresh candidate with the new `evidencectl package`, run - `evidence check --require-runtime-dependencies` with the new binary, start it, and verify a fresh synthetic - assertion. Then start the new `evidence-oid4vci`. -7. **Resume traffic, and upgrade clients.** Roll out every application that embeds a Registry +5. **Upgrade Casework.** Settle pending attempts first, since an upgrade can strand them. From a + release before the activation ledger, add `identity.databaseId` to the runtime file. When step + 4 changed the `registryRevision` a BReg source serves, check each such source with `caseworkctl + check PROJECT --against-breg-package DIR --source-id ID`, repin it with `caseworkctl source add + BREG_PROJECT --project PROJECT --source-id ID --apply`, package the Casework project again, and + point the runtime file's `package.root` at the new package (and `package.expectedDigest`, when + set, at its digest); see + [Check a BReg source's pinned revision](../../casework/#check-a-breg-sources-pinned-revision). + Stop every earlier `casework` process before the apply: one left running holds the audit + writer lock the new runtime needs, and can strand a source attempt when the apply changes a + source's binding generation. Run `caseworkctl plan --runtime-config FILE` and `caseworkctl apply --runtime-config FILE` with the + new binaries, then start `casework` and run `caseworkctl doctor --runtime-config FILE`; see [Plan, apply, and serve](../../casework/#plan-apply-and-serve). +6. **Upgrade Evidence.** Re-import each BReg source whose export the release notes say changed, + then package a fresh candidate with the new `evidencectl package`, run `evidence check + --runtime-config FILE --require-runtime-dependencies` with the new binary (add + `--without-audit-lock` while the earlier instance still runs), stop the earlier `evidence`, + start the new one, and verify a fresh synthetic assertion. Then start the new `evidence-oid4vci`. +7. **Upgrade Scheduling**, when it runs. Stop the earlier `scheduling` runtime, or keep its + destination bindings until its hook deliveries drain. Add `identity.databaseId` to the runtime + file when it has none, run `schedulingctl plan --runtime-config FILE` and `schedulingctl apply --runtime-config + FILE` with the new binary, then start `scheduling`; `schedulingctl status --runtime-config + FILE` confirms what the database activated. From a release before the activation ledger, the + first `apply` adopts the database and backfills the retained policy document, and the runtime + refuses to start until it has. +8. **Resume traffic, and upgrade clients.** Roll out every application that embeds a Registry Stack client at the same release before it calls the upgraded runtimes. {/* Evidence: docs/site/src/content/docs/operate/casework.mdx, "Upgrade Casework and BReg in @@ -101,6 +126,8 @@ sequence on a restored copy first, as crates/registry-bregctl/src/apply_lifecycle.rs, load_active_predecessor_package(); crates/registry-bregctl/src/lib.rs, PlanSuccessReport, StatusSuccessReport, and lifecycle_failure() for ApplyLifecycleError::CurrentPackage; + release/notes/v0.36.0.md, "Upgrade Scheduling, Relay, and Discovery from v0.35.0" + (identity.databaseId, apply before start, hook drain); release/scripts/rehearse-upgrade.py rehearses each product alone, not this composition. */} ## Roll back @@ -109,18 +136,36 @@ No product migrates backwards. A Casework binary refuses a database whose schema supports, and a BReg package applies forward only. Evidence refuses a runtime file carrying keys its release does not know. To return to the previous release: -- **BReg.** Undo a model change by rolling forward to a successor that reverts it. When the data - itself must go back, restore the pre-activation backup; see +- **BReg.** To return to the previous release, stop every `breg` and retire the upgraded + database, restore the step 1 `pg_dump` into a fresh database, and point the previous runtime file copied + in step 1 at it. The restored copy carries the claim of the database it was dumped from, so + adopt it with the previous release's `bregctl instance-claim adopt --runtime-config FILE + --acknowledge-original-retired` (see + [After a logical restore](../back-up-and-restore/#after-a-logical-restore) for why), then + start the previous `breg` with the previous package and that runtime file; the new release's + tools cannot read the earlier package or runtime file. To undo only a model + change, roll forward to a successor that reverts it, and when the data itself must go back, + restore the pre-activation backup; see [Roll back by rolling forward](../../breg-changes/#roll-back-by-rolling-forward). -- **Casework.** Restore the pre-migrate backup and run the previous binary and package; see +- **Casework.** Restore the pre-apply backup and run the previous binary, package, and runtime + file copied in step 1; see [Restore Registry Casework](../back-up-and-restore/#restore-registry-casework) for what that restore loses. - **Evidence.** Restart the previous binary with the previous bundle and runtime file. +- **Scheduling.** Restore the pre-apply database backup, then run the previous binary, package, + and runtime file copied in step 1. Always restore first: an earlier Scheduling runtime may not + detect a schema newer than its own. Because the release rule holds in both directions, rolling back one product means rolling back every product that must match it: Casework refuses a BReg that went back without it. {/* Evidence: crates/registry-casework/src/store.rs, refuse_newer_schema(); + crates/registry-bregctl/src/lib.rs, LegacyFormat refused as apply.package.refused; + crates/registry-bregctl/src/package_lifecycle.rs, PACKAGE_DIRECTORY (the package child of + --output); crates/registry-breg/src/instance_claim.rs, module docs (a logical copy keeps its + original's claim; v0.35.0 ships instance-claim adopt); + crates/registry-platform-audit/src/writer.rs, single-writer lock; + crates/registry-evidence/src/cli.rs, Check (--runtime-config, --without-audit-lock); crates/registry-breg/src/migration.rs, MigrationError::PackageBinding; crates/registry-evidence/src/config.rs, deny_unknown_fields on the runtime file. */} @@ -131,6 +176,19 @@ you have removed. Retiring a product leaves records behind: signatures others st decisions others may challenge, and audit entries your retention policy holds. None of the products has a decommission command, so the steps below are yours. +### Retire Scheduling + +Scheduling reads no other product and no other product reads it, so it can retire at any point +in this sequence. + +1. Stop routing booking requests to Scheduling, and tell the callers holding appointments how + those appointments will be honoured. +2. Stop `scheduling`. Reminder and observer-hook deliveries are outbox work its own workers send, + so every delivery still pending stops with it and is not sent. +3. Scheduling has no export command. Keep a final `pg_dump` for as long as your policy holds its + appointment records. +4. Ship the final audit file, its sealed files, and the `schedulingctl` sibling of `audit.path`. + ### Retire Evidence 1. Stop `evidence-oid4vci`, then stop routing requests to Evidence. @@ -181,6 +239,8 @@ has a decommission command, so the steps below are yours. docs/site/src/content/docs/reference/api-stability.mdx, JWKS served by the process; products/evidence/OPERATOR-CONTRACT.md, predecessor key retention and audit master retention; crates/registry-caseworkctl/src/lib.rs, no export command, RetentionCommand, AttemptCommand; + crates/registry-schedulingctl/src/lib.rs, no export command; crates/registry-scheduling/src/runtime.rs, + outbox workers spawned by the runtime; products/scheduling/README.md, the schedulingctl audit file; crates/registry-bregctl/src/lib.rs, DataCommand::Export, ImportAuthorityCommand, WebhookCommand; crates/registry-breg/src/field_encryption.rs, module docs. */} diff --git a/docs/site/src/data/archive-lock.yaml b/docs/site/src/data/archive-lock.yaml index 8928f4fe2..764874246 100644 --- a/docs/site/src/data/archive-lock.yaml +++ b/docs/site/src/data/archive-lock.yaml @@ -150,3 +150,7 @@ archives: bundle_sha256: 78bc8a6c1326463f4e251b3dd4fef598cafdaa10f8a936c0ac00965741f0f541 root_tree_sha256: e9e7af9c3635775f2c7631220a2c445c5484c77a62260043dbc62b6c535523ac version_tree_sha256: 7718a0c6da45c672586e178cc71c3486d8c9fc2d4633c35c8d1ce94174df9207 + v0.36.0: + bundle_sha256: 0524d9d504a047a9b170a9f1d231d121e9e54ce80e655225a8112157d0742b53 + root_tree_sha256: dda65abc14a0912c6048273aa290383d8478ed27ad0cf51c4ea439a8f0c26a02 + version_tree_sha256: 2a4bd54169ee1e810f97463d2cb44af01b425fc03042c9efc5e241484e7717a4 diff --git a/docs/site/src/data/docsets.yaml b/docs/site/src/data/docsets.yaml index 95560e24f..55f1f5bbe 100644 --- a/docs/site/src/data/docsets.yaml +++ b/docs/site/src/data/docsets.yaml @@ -32,6 +32,37 @@ docsets: registry-render: version: main source (unreleased) ref: HEAD + - id: v0.36.0 + label: v0.36.0 + path: /v/0.36.0/ + status: archived + availability: candidate + source: registry-stack-v0.36.0 + repo_docs_source: monorepo + published_at: 2026-09-29 + description: Registry Stack v0.36.0 beta-48 candidate documentation set. + products: + registry-stack: + version: v0.36.0 + ref: v0.36.0 + registry-relay: + version: v0.36.0 + ref: v0.36.0 + registry-manifest: + version: v0.36.0 + ref: v0.36.0 + registry-evidence: + version: v0.36.0 + ref: v0.36.0 + registry-casework: + version: v0.36.0 + ref: v0.36.0 + registry-scheduling: + version: v0.36.0 + ref: v0.36.0 + registry-render: + version: v0.36.0 + ref: v0.36.0 - id: v0.35.0 label: v0.35.0 path: /v/0.35.0/ diff --git a/docs/site/src/data/repo-docs.yaml b/docs/site/src/data/repo-docs.yaml index 534687b75..f09938ac8 100644 --- a/docs/site/src/data/repo-docs.yaml +++ b/docs/site/src/data/repo-docs.yaml @@ -76,6 +76,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ govstack-digital-registries, sdmx, openapi, json-schema, shacl, json-ld ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ govstack-digital-registries, sdmx, openapi, json-schema, shacl, json-ld ] + last_reviewed: unreviewed description: Approved Relay V2 product concept covering the registry contract, the compiler, the read-only source boundary, and the acceptance set. - src: products/relay-v2/STANDARDS-ALIGNMENT.md dest: products/registry-relay/standards-alignment @@ -110,6 +113,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ govstack-digital-registries, sdmx, openapi, json-schema, shacl, json-ld ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ govstack-digital-registries, sdmx, openapi, json-schema, shacl, json-ld ] + last_reviewed: unreviewed description: Maintained directional mapping from Relay V2 to the pinned GovStack drafts and the aligned SDMX read subset. Makes no conformance claim. registry-manifest: @@ -155,6 +161,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, odrl, sp-dci, w3c-did, prov-o, govstack-digital-registries ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, odrl, sp-dci, w3c-did, prov-o, govstack-digital-registries ] + last_reviewed: unreviewed description: Operator and integrator documentation for Registry Manifest. - src: products/manifest/docs/validate-and-render.md archive_src: docs/validate-and-render.md @@ -192,6 +201,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, odrl ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, odrl ] + last_reviewed: unreviewed - src: products/manifest/docs/profile-fixtures.md archive_src: docs/profile-fixtures.md dest: products/registry-manifest/profile-fixtures @@ -225,6 +237,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ sp-dci ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ sp-dci ] + last_reviewed: unreviewed - src: products/manifest/docs/reference.md archive_src: docs/reference.md dest: products/registry-manifest/reference @@ -261,6 +276,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, cccev, odrl, w3c-did ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ dcat, bregdcat-ap, cpsv-ap, ogc-api-records, shacl, skos, json-schema, json-ld, cccev, odrl, w3c-did ] + last_reviewed: unreviewed - src: products/manifest/docs/itb-semic-validation.md dest: products/registry-manifest/itb-semic-validation label: ITB and SEMIC validation @@ -294,6 +312,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ dcat, bregdcat-ap, shacl, skos, json-schema, json-ld ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ dcat, bregdcat-ap, shacl, skos, json-schema, json-ld ] + last_reviewed: unreviewed registry-evidence: label: Evidence Gateway remote: https://github.com/registrystack/registry-stack @@ -335,6 +356,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ openapi, json-schema, sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ openapi, json-schema, sd-jwt-vc ] + last_reviewed: unreviewed description: Operator and integrator documentation for Evidence Gateway, the minimum-disclosure assertion service. - src: products/evidence/CONCEPT.md dest: products/registry-evidence/concept @@ -369,6 +393,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ cccev, json-schema, openapi, sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ cccev, json-schema, openapi, sd-jwt-vc ] + last_reviewed: unreviewed description: Approved Version 1 product concept covering the boundary, data model, trust and privacy invariants, native API, and acceptance set. - src: products/evidence/reference/authoring-projects/CONFIG.md dest: products/registry-evidence/authoring-form @@ -403,6 +430,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ json-schema, openapi, sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ json-schema, openapi, sd-jwt-vc ] + last_reviewed: unreviewed description: Complete reference for the editable Evidence authoring project, its validation layers, local key material, and access policies. - src: products/evidence/reference/authoring-projects/SOURCE-EXPORT.md dest: products/registry-evidence/source-exports @@ -437,6 +467,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [] + last_reviewed: unreviewed description: Optional native source import, customized updates, provenance and interrupted transaction recovery. - src: products/evidence/reference/request-adapter/deployment-projects/SOURCE-CREDENTIAL-ROTATION.md dest: products/registry-evidence/source-credential-rotation @@ -471,6 +504,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [] + last_reviewed: unreviewed description: Rotate source credentials with explicit overlap, bounded OAuth caches and verified restart. - src: products/evidence/FIRST-CURL-TEST.md dest: products/registry-evidence/first-curl-test @@ -505,6 +541,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [] + last_reviewed: unreviewed description: Deterministic local curl checkpoint against the Evidence Gateway server with a mock source and an in-memory test JWKS. - src: products/evidence/SOURCE-TESTING.md dest: products/registry-evidence/source-testing @@ -539,6 +578,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ sd-jwt-vc ] + last_reviewed: unreviewed description: Source-testing contract with the deterministic mock matrix, opt-in public demo smoke tests, and credential handling rules. - src: products/evidence/SD-JWT-VC-DEMO.md dest: products/registry-evidence/sd-jwt-vc-demo @@ -573,6 +615,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ sd-jwt-vc ] + last_reviewed: unreviewed description: Deterministic local demo that issues one assertion in both later-verifiable formats and re-verifies the credential offline. - src: products/evidence/OPERATOR-CONTRACT.md dest: products/registry-evidence/operator-contract @@ -607,6 +652,9 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [ openapi, sd-jwt-vc ] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [ openapi, sd-jwt-vc ] + last_reviewed: unreviewed description: Supported deployment shape, requester authority and purpose duties, required configuration and secrets, and readiness, audit, and key obligations. - src: products/evidence/PERFORMANCE.md dest: products/registry-evidence/performance @@ -641,4 +689,7 @@ repos: - docsets: [ v0.35.0 ] standards_referenced: [] last_reviewed: unreviewed + - docsets: [ v0.36.0 ] + standards_referenced: [] + last_reviewed: unreviewed description: Measured baseline of the audit-durability throughput trade and the deferred work that would recover most of the cost. diff --git a/products/breg/CHANGELOG.md b/products/breg/CHANGELOG.md index 6631d0b44..0a5207a31 100644 --- a/products/breg/CHANGELOG.md +++ b/products/breg/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +## v0.36.0 - 2026-09-29 + - BREAKING: package signing is removed. Upgrade to v0.35.0 before this release: a deployment on v0.34.0 or earlier must pass through v0.35.0, because this release no longer reads a predecessor package that has no diff --git a/products/breg/wasm-handler-sdk/Cargo.lock b/products/breg/wasm-handler-sdk/Cargo.lock index 7efb0a2f5..41d2b0e3f 100644 --- a/products/breg/wasm-handler-sdk/Cargo.lock +++ b/products/breg/wasm-handler-sdk/Cargo.lock @@ -2725,7 +2725,7 @@ checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4" [[package]] name = "registry-breg" -version = "0.35.0" +version = "0.36.0" dependencies = [ "chrono", "jsonschema", @@ -2759,7 +2759,7 @@ dependencies = [ [[package]] name = "registry-evidence-client" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -2779,7 +2779,7 @@ dependencies = [ [[package]] name = "registry-evidence-verifier" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "chrono", @@ -2797,7 +2797,7 @@ dependencies = [ [[package]] name = "registry-manifest-core" -version = "0.35.0" +version = "0.36.0" dependencies = [ "oxiri", "registry-platform-canonical-json", @@ -2810,7 +2810,7 @@ dependencies = [ [[package]] name = "registry-platform-authcommon" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "registry-platform-crypto", @@ -2825,7 +2825,7 @@ dependencies = [ [[package]] name = "registry-platform-canonical-json" -version = "0.35.0" +version = "0.36.0" dependencies = [ "ryu-js", "serde", @@ -2835,7 +2835,7 @@ dependencies = [ [[package]] name = "registry-platform-config" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-platform-canonical-json", "rustix 1.1.5", @@ -2851,7 +2851,7 @@ dependencies = [ [[package]] name = "registry-platform-crypto" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "aws-lc-rs", @@ -2874,7 +2874,7 @@ dependencies = [ [[package]] name = "registry-platform-hooks" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-platform-canonical-json", "serde", @@ -2887,7 +2887,7 @@ dependencies = [ [[package]] name = "registry-platform-httpsec" -version = "0.35.0" +version = "0.36.0" dependencies = [ "http", "serde", @@ -2897,7 +2897,7 @@ dependencies = [ [[package]] name = "registry-platform-httputil" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "base64 0.23.1", @@ -2923,7 +2923,7 @@ dependencies = [ [[package]] name = "registry-platform-script" -version = "0.35.0" +version = "0.36.0" dependencies = [ "rhai", "serde", @@ -2933,7 +2933,7 @@ dependencies = [ [[package]] name = "registry-platform-sdjwt" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "getrandom 0.4.3", diff --git a/products/casework/CHANGELOG.md b/products/casework/CHANGELOG.md index 06375beef..d1d7beedf 100644 --- a/products/casework/CHANGELOG.md +++ b/products/casework/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +## v0.36.0 - 2026-09-29 + - BREAKING: a Casework package is activated in the database by `caseworkctl apply --runtime-config FILE`, and `casework serve` only reads that activation. `caseworkctl plan` reports, with the runtime credential and diff --git a/products/evidence/CHANGELOG.md b/products/evidence/CHANGELOG.md index 62dfe4e7d..dc19d543b 100644 --- a/products/evidence/CHANGELOG.md +++ b/products/evidence/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +## v0.36.0 - 2026-09-29 + - `evidencectl audit show --last-operation` reads a retained history that holds request-batch entries instead of refusing it, and refuses with `evidence.audit.request-batch` when the last operation is a batch. An diff --git a/products/evidence/generated/registry-evidence.openapi.json b/products/evidence/generated/registry-evidence.openapi.json index d00f0007b..ee8d288f0 100644 --- a/products/evidence/generated/registry-evidence.openapi.json +++ b/products/evidence/generated/registry-evidence.openapi.json @@ -1804,7 +1804,7 @@ "info": { "description": "Minimum-disclosure signed assertion service, Version 1.", "title": "Registry Evidence API", - "version": "0.35.0" + "version": "0.36.0" }, "openapi": "3.1.0", "paths": { diff --git a/products/manifest/CHANGELOG.md b/products/manifest/CHANGELOG.md index eff3734db..a6e2375db 100644 --- a/products/manifest/CHANGELOG.md +++ b/products/manifest/CHANGELOG.md @@ -7,6 +7,10 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm ## [Unreleased] +## [0.36.0] - 2026-09-29 + +- Registry Manifest has no user-visible changes in this release. + ## [0.35.0] - 2026-09-28 - Registry Manifest has no user-visible changes in this release. diff --git a/products/manifest/docs/release-notes.md b/products/manifest/docs/release-notes.md index 51562050d..1e22533a0 100644 --- a/products/manifest/docs/release-notes.md +++ b/products/manifest/docs/release-notes.md @@ -2,6 +2,10 @@ ## Unreleased +## 0.36.0 + +- Registry Manifest has no user-visible changes in this release. + ## 0.35.0 - Registry Manifest has no user-visible changes in this release. diff --git a/products/manifest/fuzz/Cargo.lock b/products/manifest/fuzz/Cargo.lock index 9be3a8715..282ed58c7 100644 --- a/products/manifest/fuzz/Cargo.lock +++ b/products/manifest/fuzz/Cargo.lock @@ -191,7 +191,7 @@ checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" [[package]] name = "registry-manifest-cli" -version = "0.35.0" +version = "0.36.0" dependencies = [ "registry-manifest-core", "serde", @@ -202,7 +202,7 @@ dependencies = [ [[package]] name = "registry-manifest-core" -version = "0.35.0" +version = "0.36.0" dependencies = [ "oxiri", "registry-platform-canonical-json", @@ -226,7 +226,7 @@ dependencies = [ [[package]] name = "registry-platform-canonical-json" -version = "0.35.0" +version = "0.36.0" dependencies = [ "ryu-js", "serde", diff --git a/products/platform/CHANGELOG.md b/products/platform/CHANGELOG.md index acd17ac28..4e5480b40 100644 --- a/products/platform/CHANGELOG.md +++ b/products/platform/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +## v0.36.0 - 2026-09-29 + - Recover a torn final line at open instead of refusing to start: the file writer copies the bytes after the last complete line to the owner-only side file `.torn`, syncs it, truncates the active file to its last complete diff --git a/products/platform/fuzz/Cargo.lock b/products/platform/fuzz/Cargo.lock index 6c1d7f608..4e72a279f 100644 --- a/products/platform/fuzz/Cargo.lock +++ b/products/platform/fuzz/Cargo.lock @@ -1628,7 +1628,7 @@ checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4" [[package]] name = "registry-platform-authcommon" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "registry-platform-crypto", @@ -1643,7 +1643,7 @@ dependencies = [ [[package]] name = "registry-platform-canonical-json" -version = "0.35.0" +version = "0.36.0" dependencies = [ "ryu-js", "serde", @@ -1653,7 +1653,7 @@ dependencies = [ [[package]] name = "registry-platform-crypto" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "aws-lc-rs", @@ -1695,7 +1695,7 @@ dependencies = [ [[package]] name = "registry-platform-httputil" -version = "0.35.0" +version = "0.36.0" dependencies = [ "async-trait", "base64 0.23.1", @@ -1721,7 +1721,7 @@ dependencies = [ [[package]] name = "registry-platform-oidc" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "jsonwebtoken", @@ -1736,7 +1736,7 @@ dependencies = [ [[package]] name = "registry-platform-sdjwt" -version = "0.35.0" +version = "0.36.0" dependencies = [ "base64 0.23.1", "getrandom 0.4.3", @@ -1752,7 +1752,7 @@ dependencies = [ [[package]] name = "registry-platform-sqlite" -version = "0.35.0" +version = "0.36.0" dependencies = [ "rusqlite", "rustix", diff --git a/products/relay-v2/security/advisory-baseline.json b/products/relay-v2/security/advisory-baseline.json index 35fda80f9..fb8ccd494 100644 --- a/products/relay-v2/security/advisory-baseline.json +++ b/products/relay-v2/security/advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:32a6c4602351fccb41faeff834e3c5886ba9018a7336ebb3c30c2d8c7d2022a9", + "sha256:579d38307df1ad88aa83af5e3073ad8f5023fd75c7a272dbae3e51dc556defdb", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -64,7 +64,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9" + "definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f" }, "policies": [ { @@ -87,8 +87,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -105,14 +105,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", - "component_layer_id": "sha256:32a6c4602351fccb41faeff834e3c5886ba9018a7336ebb3c30c2d8c7d2022a9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", + "component_layer_id": "sha256:579d38307df1ad88aa83af5e3073ad8f5023fd75c7a272dbae3e51dc556defdb", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:356899e509f3241064862d919eff941e6b406575ae45ecd493814ac94df17395", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5aebf959e4e64d7516048a43d6897951252a717673662cba0fe89ecb2195b248", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -132,10 +132,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:34fbee88b513832088919ee1998a31d68d44ec07ce34438bb2415fac1cf08610" + "sha256": "sha256:1266ab67b668f6e4a2df169879404c95cf3680de64bf87a531e3d5c1c241e3aa" } ], - "definition_digest": "sha256:4a4e866cb989b4dcf0e2d8ea9abc36cd5aedfa47de16936e3343028fae1aff3f" + "definition_digest": "sha256:ba69f54d6fb03be125ab92a84e91b54196001a177c1cd32875f783edfa71b7a2" } }, { @@ -145,8 +145,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -163,14 +163,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", - "component_layer_id": "sha256:32a6c4602351fccb41faeff834e3c5886ba9018a7336ebb3c30c2d8c7d2022a9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", + "component_layer_id": "sha256:579d38307df1ad88aa83af5e3073ad8f5023fd75c7a272dbae3e51dc556defdb", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:356899e509f3241064862d919eff941e6b406575ae45ecd493814ac94df17395", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5aebf959e4e64d7516048a43d6897951252a717673662cba0fe89ecb2195b248", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -190,10 +190,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:34fbee88b513832088919ee1998a31d68d44ec07ce34438bb2415fac1cf08610" + "sha256": "sha256:1266ab67b668f6e4a2df169879404c95cf3680de64bf87a531e3d5c1c241e3aa" } ], - "definition_digest": "sha256:4a4e866cb989b4dcf0e2d8ea9abc36cd5aedfa47de16936e3343028fae1aff3f" + "definition_digest": "sha256:ba69f54d6fb03be125ab92a84e91b54196001a177c1cd32875f783edfa71b7a2" } }, { @@ -203,8 +203,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", - "reviewed_at": "2026-09-27", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 Relay local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -221,14 +221,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:356899e509f3241064862d919eff941e6b406575ae45ecd493814ac94df17395", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5aebf959e4e64d7516048a43d6897951252a717673662cba0fe89ecb2195b248", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b55a5e893a6656c02342857eb85e104bd4f9713b448a44a9dcd57197e3d328c9", + "runtime_definition_digest": "sha256:9b8ef39976bce269e81283e08b4154c18fa06d64ddfd202253872185a491749f", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -248,10 +248,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:34fbee88b513832088919ee1998a31d68d44ec07ce34438bb2415fac1cf08610" + "sha256": "sha256:1266ab67b668f6e4a2df169879404c95cf3680de64bf87a531e3d5c1c241e3aa" } ], - "definition_digest": "sha256:4a4e866cb989b4dcf0e2d8ea9abc36cd5aedfa47de16936e3343028fae1aff3f" + "definition_digest": "sha256:ba69f54d6fb03be125ab92a84e91b54196001a177c1cd32875f783edfa71b7a2" } } ] diff --git a/products/scheduling/CHANGELOG.md b/products/scheduling/CHANGELOG.md index 3442bce05..9605316f3 100644 --- a/products/scheduling/CHANGELOG.md +++ b/products/scheduling/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +## v0.36.0 - 2026-09-29 + - Write operational logs to standard error instead of standard output, so a `stdout` audit destination carries audit entries alone. A collector that read `scheduling` logs from standard output reads standard error instead. @@ -31,9 +33,10 @@ schema version is pending or the runtime role or its role mode changed, so a rotated runtime role or a move to split mode re-applies it. The operator reference is kept only as a keyed hash scoped by the activation - id. Apply writes a `scheduling-activation-audit/v1` request entry to - `audit.schedulingctl.ndjson` before the transaction and a response entry - after it, and applies nothing when the request entry is refused. An + id. Apply writes a `scheduling-activation-audit/v1` request entry to the + `schedulingctl` sibling of `audit.path` (`audit.schedulingctl.ndjson` + beside `audit.ndjson`) before the transaction and a response entry after + it, and applies nothing when the request entry is refused. An activation whose commit was not acknowledged is read back, and one whose outcome cannot be read is answered `unfinished` with reason `schedulingctl.activation.unacknowledged`, naming `schedulingctl status`, diff --git a/products/scheduling/README.md b/products/scheduling/README.md index 97fb127f1..488efecc8 100644 --- a/products/scheduling/README.md +++ b/products/scheduling/README.md @@ -76,9 +76,9 @@ the activation ledger. With the migration credential and under one advisory lock, it applies the pending schema versions, binds the database to the policy's scheduling id, publishes the policy, grants the runtime role its access when the two credentials name different roles, and records one ledger -row, all in one transaction. It writes an activation request entry to -`audit.schedulingctl.ndjson` before that transaction and a response entry -after it, and applies nothing when the request entry cannot be written. +row, all in one transaction. It writes an activation request entry to the +`schedulingctl` sibling of `audit.path` (`audit.schedulingctl.ndjson` beside +`audit.ndjson`) before that transaction and a response entry after it, and applies nothing when the request entry cannot be written. `--operator-reference` (a change ticket, for instance) is kept only as a keyed hash, and each `--backup REF` is recorded as given. Applying the package that is already active refuses with `nothing needs applying` unless a schema diff --git a/release/manifests/registry-stack-beta-48.yaml b/release/manifests/registry-stack-beta-48.yaml new file mode 100644 index 000000000..fdc98490e --- /dev/null +++ b/release/manifests/registry-stack-beta-48.yaml @@ -0,0 +1,34 @@ +stack: + release: beta-48 + version: 0.36.0 + source_repo: registrystack/registry-stack + source_tag: v0.36.0 + +artifacts: + registry-manifest: 0.36.0 + relay: 0.36.0 + relayctl: 0.36.0 + evidence: 0.36.0 + evidencectl: 0.36.0 + evidence-oid4vci: 0.36.0 + evidencectl-installer: 0.36.0 + relay-installer: 0.36.0 + registry-docs: 0.36.0 + discovery: 0.36.0 + breg: 0.36.0 + bregctl: 0.36.0 + breg-installer: 0.36.0 + casework: 0.36.0 + caseworkctl: 0.36.0 + casework-installer: 0.36.0 + scheduling: 0.36.0 + schedulingctl: 0.36.0 + registry-client-node: 0.36.0 + registry-client-python: 0.36.0 + +identifier_catalog: + path: products/identifiers/generated/catalog.v1.json + sha256: 1a5068ee48aa6f4d63980195e3dbcbd6bb0e3ed2664e5f7f9ab0018d81c240b5 + entry_count: 162 + +external: {} diff --git a/release/notes/v0.36.0.md b/release/notes/v0.36.0.md new file mode 100644 index 000000000..252473b54 --- /dev/null +++ b/release/notes/v0.36.0.md @@ -0,0 +1,451 @@ +# Registry Stack v0.36.0 + +Registry Stack v0.36.0 is the beta-48 release. It records every BReg +activation in a database ledger and makes a BReg package unsigned and +environment neutral, named by its package digest. Registry Casework and +Registry Scheduling activate their packages through their own database ledgers +with `plan` and `apply` instead of migrating at startup. `evidencectl`, +`caseworkctl`, and `schedulingctl` share one JSON report envelope and one set +of exit codes. The BReg, Casework, and Scheduling images carry their operator +tool beside the runtime, and `schedulingctl` is published as a release binary. + +Upgrade to v0.36.0 from v0.35.0 only. This release removes package signing, +and with it the only way to read a predecessor package that has no +`SHA256SUMS` envelope. Deployments on v0.34.0 or earlier must upgrade to +v0.35.0 first. + +## Compatibility and migration + +Run the same release on every runtime, tool, and client, and upgrade in the +order [upgrade and retire](https://docs.registrystack.org/operate/advanced/upgrade-and-retire/#upgrade-in-this-order) +describes: BReg first, then Casework, then Evidence, then Scheduling, then +the clients. Take the database, package, and runtime-file backups it names +first; no product migrates backwards. + +### Upgrade Base Registry Engine from v0.35.0 + +- Upgrade in place by adopting the database into the activation ledger. Delete + `package.environment`, `package.instanceId`, and `package.sequence` from the + project and move the environment and instance id to the runtime file's + `identity`. Delete `package.trustAnchorPath`, `package.activeRevision`, + `package.activeSequence`, and `package.compilerSourceRevision` from the + runtime file. Rebuild the deployed project unchanged with the v0.36.0 + `bregctl test` and `bregctl package --test-receipt FILE --output BUILD`, point `package.root` at `BUILD/package` + (and `package.expectedDigest`, when set, at the package digest it reports, `packageDigest` + with `--format json`), run + `bregctl plan --runtime-config FILE --package BUILD/package` naming the same + directory (it reports the activation as `adopted`), then `bregctl apply + --runtime-config FILE --package BUILD/package` without `--initial`, `bregctl verify + --runtime-config FILE`, and restart every `breg` process on the new binary. + `bregctl status --runtime-config FILE` shows what the database + activated. Build each + model change afterwards as its own successor from the rebuilt package; see + [Activate the successor](https://docs.registrystack.org/operate/breg-changes/#activate-the-successor). +- A registry upgraded from a release that recorded no instance claim no longer + needs `bregctl instance-claim adopt --acknowledge-original-retired` after the + upgrade: an activation records the claim when the database has none. A + recorded claim is kept, so a restored copy still refuses to serve until it is + adopted. +- BREAKING: package signing is removed. A package is unsigned and named by its + package digest, the SHA-256 of its `SHA256SUMS`. `bregctl package` seals and + publishes it in one step into `/package` and refuses an output + directory that already holds a published package. `bregctl test` and + `package` refuse `--signature-threshold`, `--signature-key-id`, and + `--database-id`, `package` refuses `--signatures`, and both take the active + package directory as `--baseline-package` instead of + `--baseline-runtime-config`; each retired flag exits 2 and names its + replacement. The legacy-predecessor fallback v0.35.0 added is gone, and so + is `package.digest_pin_unverifiable`. `bregctl apply` and `bregctl plan` + refuse a package that does not follow the active one as + `apply.package.refused`, the active package itself under the + `database.roles` it already serves with as + `apply.package.already_active`, and a runtime file whose + `identity.databaseId` differs from the one the database recorded as + `apply.database.identity_mismatch`. An apply that resumes an unfinished + activation under other `database.roles` is refused as + `apply.resume.roles_differ`, and a successor applied under other roles as + `apply.successor.roles_differ`; apply the active package under the new roles + first, which records a `role_change` activation. An import authority's + `activationRevision` is `activationId` in its audit record and in the + `bregctl import-authority` report. +- BREAKING: the database records every activation, the initial one included, + as a row of `registry_internal.registry_migrations`, keyed by a UUID + activation id and ordered by `apply_order`. `registry_state` holds the + active package digest, the active activation id, and the instance claim; + the `registry_instance_claim` table is gone. Records, the revision journal, + outbox and delivery rows, audit entries, and import authorities name the + activation id where they named a package revision; webhook event data and + ingestion runs keep naming the active package digest as `packageRevision`. + `bregctl apply` reports `activationId` instead of `packageSequence`, a + destructive activation records its backup references, and a successful + activation supersedes every open import authority. Reconciliation audits + under `breg-migration-reconcile-audit/v3`, and `bregctl migration reconcile` + reports `maintenanceTargetPackageDigest`, `activePackageDigest`, and + `targetPackageDigest`. Webhook events take their `source` from + `identity.instanceId`, and startup refuses a changed `identity.instanceId` + while deliveries captured under the previous one are pending or leased. + `breg` refuses a database with no activated package, naming + `bregctl apply --package DIR --initial`, and a database that predates the + ledger, naming `bregctl apply --package DIR`. +- BREAKING: a database an earlier release installed is adopted into the + ledger once, by `bregctl apply --package DIR` without `--initial`, where DIR + and `package.root` both name the rebuilt deployed project. The live schema + fingerprint must equal the package's, and the adoption becomes ledger row 1 + with plan kind `adopted`. The earlier ledger history is dropped, the instance + claim is kept, ingestion runs opened against the running package are rebound + to the adopted package, and every open import authority is superseded; an + import authority a pre-ledger release had already closed names the + adoption's activation id. A fingerprint mismatch is refused as + `apply.adoption.fingerprint_mismatch`, a database left in maintenance as + `apply.adoption.not_ready`, and any other apply of a pre-ledger database as + `apply.database.pre_ledger`. +- BREAKING: the role mode is `single` when `database.roles.migration` and + `database.roles.runtime` name one role and `split` otherwise. In split mode + `bregctl apply` and `bregctl plan` refuse a runtime role that can write the + activation ledger or the registry state as `apply.runtime_role.can_write`, + naming the `REASSIGN OWNED BY`, `REVOKE`, or `DROP TRIGGER` to run, and + `breg` refuses it as `startup.runtime_role.can_write`. A trigger an operator + added to a registry table, such as a local audit trigger, triggers this + refusal; drop it, then rerun the refused command. `breg` refuses a runtime + role missing its grants as `startup.runtime_role.grants_missing`, and a + one-role runtime file over a database activated for a separate runtime role + as `startup.role_mode.changed`. `bregctl doctor` reports `roleMode`. +- BREAKING: an Evidence source export names the compiled model as + `provenance.registryRevision` instead of `provenance.packageRevision`, so + `evidencectl` reports changed provenance for every BReg source on its next + import. Re-import each BReg source once. +- BREAKING: the schema fingerprint no longer measures the runtime role's + grants, so one package fits a database served with one role or with two. + Every package's schema fingerprint changes; rebuild each package with the + v0.36.0 `bregctl package`. +- BREAKING: `registryRevision` is a function of the compiled model only. The + project's `package` block no longer appears in + `compiled/effective-model.json`, so a project that declared a package + identity compiles to a different `registryRevision`. +- BREAKING: a Registry Casework BReg source pins the `registryRevision` it was + imported from, and Casework startup refuses a pin the registry no longer + serves. After upgrading BReg, run `caseworkctl check PROJECT + --against-breg-package DIR --source-id ID`, repin with `caseworkctl source + add BREG_PROJECT --project PROJECT --source-id ID --apply`, then package, + plan, and apply the Casework project once. See + [Check a BReg source's pinned revision](https://docs.registrystack.org/operate/casework/#check-a-breg-sources-pinned-revision). +- BREAKING: a package is environment neutral, and one package is the unit an + operator promotes through every environment. `package.environment`, + `package.instanceId`, and `package.sequence` are refused as + `package.environment.removed`, `package.instance_id.removed`, and + `package.sequence.removed`; `package.sourceRevision` stays. The manifest is + `package/v2`, names its predecessor by `migrationPlan.fromPackageDigest`, + and a `package/v1` package is refused. The runtime `package` block holds + `root` and an optional `expectedDigest`; `trustAnchorPath`, + `activeRevision`, `activeSequence`, and `compilerSourceRevision` are refused + as `runtime_config.package_key_removed`. `identity.instanceId` must be a + lowercase letter followed by at most 63 lowercase letters, digits, `-`, or + `_` (`runtime_config.invalid_instance_id`), and `identity.environment` must + equal `identity.databaseInitializationEnvironment` + (`runtime_config.environment_identity_conflict`). The schema-test receipt is + `breg-schema-test-receipt/v2` and binds each reviewed migration file by path + and digest. A backup binding inside the package is refused when the package + is built; it is an apply input only (`bregctl apply --backup`). Reports name + packages by `packageDigest`. An initial apply accepts a package that names a + predecessor, an empty migration plan is refused, and `migration reconcile` + refuses the active package as its target. + +### Upgrade Registry Casework from v0.35.0 + +- Add `identity.databaseId` to `runtime.yaml`, then run `caseworkctl plan + --runtime-config FILE` and `caseworkctl apply --runtime-config FILE` once + with the new binaries before starting the runtime. The first apply on a database an earlier release migrated adopts + it: it applies the pending migrations and records the first activation. + Repin each BReg source after upgrading BReg, as the BReg section above + describes, package the project again, and point `package.root` (and + `package.expectedDigest`, when set) at the new package before plan and + apply. See + [Plan, apply, and serve](https://docs.registrystack.org/operate/casework/#plan-apply-and-serve). +- Stop every runtime serving the earlier package before `caseworkctl apply` + of a package that changes a source's binding generation. A runtime left + running can reserve a source attempt under the earlier binding that the new + runtime cannot execute or recover. No `status` or `doctor` report lists + such an attempt; the holder's next call receives the recovery problem + naming it, and the operator clears it with `caseworkctl attempt + mark-uncertain` then `caseworkctl attempt settle` once the source owner + confirms the outcome. +- BREAKING: a Casework package is activated in the database by + `caseworkctl apply --runtime-config FILE`, and `casework serve` only reads + that activation. `caseworkctl plan` reports with the runtime credential, + in a read-only transaction, what an apply would change. `caseworkctl apply` + uses the migration credential and, in one transaction, migrates the schema, + registers source generations, activates task templates, grants the runtime + role, and records one row in a new activation ledger (schema migration 19). + `--operator-reference` is recorded only as a keyed hash, and `--backup REF` + may be given up to 16 times. Each apply is audited as + `casework-activation-audit/v1`. Exit codes are 0 for success, 1 for a + refusal, 2 for a usage error, and 3 for an operational failure; an apply + that committed but whose audit response entry was refused reports + `casework.activation.applied-unaudited` and must not be repeated. + Re-applying the active package with nothing to change is refused. + `caseworkctl status` shows the activation history and the role mode. +- BREAKING: `runtime.yaml` requires `identity.databaseId`, an operator-chosen + logical name for the deployment's database. The first apply records it, + and every later apply and every startup refuses a database that recorded + another one. +- BREAKING: the runtime no longer migrates, registers source generations, or + activates task templates at startup. It refuses a database with no + activation, a schema other than its own, an active package other than the + one it loaded, an unregistered source generation, a database identity other + than its own, or a split-role activation whose runtime credential can now + write the activation ledger, naming `caseworkctl plan` then + `caseworkctl apply`. +- BREAKING: in split-role mode, `caseworkctl plan`, `caseworkctl apply`, and + startup refuse a runtime role that owns a Casework object, holds CREATE on + the schema, or holds TRIGGER on a Casework table, and a database where a + trigger no Casework migration creates is attached to a Casework table, + naming the `REASSIGN OWNED BY`, `REVOKE CREATE ON SCHEMA`, `REVOKE TRIGGER`, + or `DROP TRIGGER` statement to run. Apply also refuses, before any + migration, a default privilege that would grant the runtime role TRIGGER on + the tables it creates, naming `ALTER DEFAULT PRIVILEGES ... REVOKE TRIGGER + ON TABLES FROM `. +- BREAKING: startup refuses a BReg source whose imported description pins a + `sourceRevision` other than the registry revision the source serves, naming + the `caseworkctl check --against-breg-package` and `caseworkctl source add + --apply` repin. A source that cannot be read at startup is not refused + there; its reads refuse the same drift. +- BREAKING: `casework migrate` and `caseworkctl db migrate` are removed. Each + exits 2 and names `caseworkctl plan --runtime-config FILE` then + `caseworkctl apply --runtime-config FILE`. The `DatabaseMigrationReport` + kind is gone, and the `caseworkctl/v1alpha3` wire contract adds + `PlanReport`, `ApplyReport`, and `StatusReport` and the `DoctorReport` + `roleMode` and `singleRoleStatement` fields. +- BREAKING: every `caseworkctl --format json` report opens with `ok`, + `command`, and `status`, in that order, under `caseworkctl/v1alpha3`. `ok` + is true exactly when the exit code is 0, and `command` is present on every + report, failures included. +- `caseworkctl dev` applies in-process on every start, so a session retained + from an earlier release starts with its database in place. A session it + creates connects the runtime and apply with one database role; a retained + session keeps its split roles. + +### Upgrade Evidence from v0.35.0 + +- Re-import each BReg source once after upgrading BReg; the export's + provenance member is renamed, as the BReg section above describes. +- `evidence serve` writes its operational records to standard error instead + of standard output, so a `stdout` audit destination carries audit entries + alone. A log collector that read Evidence logs from standard output reads + standard error instead. +- `evidence` and `evidencectl` must be the same version: the core view + `evidencectl audit show` reads moves to + `registry.evidence.local-audit-operation/v2`. +- BREAKING: `evidencectl` follows the shared ctl report and exit contract. + Under `--format json` every command writes one object on standard output, + opening with `ok`, `command`, and `status`, and nothing on standard error; + `command` replaces the former `operation` member, and every member name is + camelCase. `fixtures run` and `test` reports rename `evaluated_cases`, + `failing_case`, `expected_class`, and `observed_class` to `evaluatedCases`, + `failingCase`, `expectedClass`, and `observedClass`, and a run that + evaluated no case carries `evidencectl.fixtures.no-case`. `source suggest` + notes move from standard error into the report's `notes` member. Exit + classes are 0 success, 1 domain refusal or failing fixture, 2 usage, and 3 + operational failure; a file that cannot be read or a missing local dev + session now exits 3 instead of 1. Every command that reads one project + takes it as a positional ``, and the former `--project` flag stays + accepted but hidden on those commands. `source import`, `source diff`, + `source update`, and `target new` keep their documented `--project`, whose + positional arguments are export or target directories; `doctor` keeps its + visible `--project`, and `access` and `audit show` still act on the current + directory. `test` and + `fixtures run` accept `--format junit`, and `dev start --name-prefix` sets + the local issuer container name prefix (`evidence-dev` by default). Update + scripts to read `command` and the camelCase fixture keys, parse JSON + reports from standard output alone, treat exit 3 as an unavailable + dependency, and pass the project positionally to the commands that take + one. See + [evidencectl](https://docs.registrystack.org/reference/evidencectl/#project-workflow). + +### Upgrade Scheduling, Relay, and Discovery from v0.35.0 + +- Add `identity.databaseId` to `runtime.yaml`, then run `schedulingctl apply + --runtime-config FILE` once after upgrading and before starting the + upgraded runtime. The first + apply on a database an earlier release migrated adopts it and backfills the + retained policy document. Stop the earlier runtime, or keep its destination + bindings until its hook deliveries drain, before `schedulingctl apply`. +- `scheduling` writes operational logs to standard error instead of standard + output, and logs at `info` when `RUST_LOG` is unset or invalid. +- BREAKING: Scheduling activates a package with `schedulingctl plan`, + `schedulingctl apply`, and `schedulingctl status`, recorded in a database + activation ledger, instead of `scheduling migrate` and a startup that adopts + the database and publishes the policy. `identity.databaseId` is required, + and an apply, `records apply`, or startup under another id is refused. + `plan` reads with the runtime credential and writes nothing. `apply` uses + the migration credential and, in one transaction, applies pending schema + versions, publishes the policy, grants the runtime role, and records one + ledger row; any valid package applies, an earlier one included, and the + active package refuses with `nothing needs applying` unless a schema + version is pending or the runtime role or its role mode changed. Each apply + is audited as `scheduling-activation-audit/v1` in a `schedulingctl` sibling + of `audit.path`. `plan` and `apply` refuse unbound hook destinations or + short HMAC keys as `schedulingctl.activation.hook-destinations`, and in + split role mode `plan`, `apply`, and `scheduling serve` refuse a runtime + role that can write the ledger as + `schedulingctl.activation.split-role-weakened`, naming the statement to + run. `scheduling serve` writes no activation state and refuses a database + with no active package, a package the ledger does not name, or a ledger + recorded for another `identity.databaseId`. `scheduling migrate` is removed + and exits 2 naming `schedulingctl plan` then `schedulingctl apply`, and + `schedulingctl records apply` refuses a database no `schedulingctl apply` + has activated. The operator commands exit 0 on success, 1 on a refusal, 2 + on a usage error, and 3 on an operational failure. +- BREAKING: every `schedulingctl --format json` report opens with `ok`, + `command`, and `status`, in that order. A refused report carries a + non-empty `diagnostics` array whose entries each name a `suggestedAction`, + and `records apply` reports `command: "records apply"` instead of + `records-apply`. +- Relay and Discovery have no user-visible changes in this release, and + neither has Registry Manifest. + +## Base Registry Engine + +- `bregctl plan --runtime-config FILE --package DIR` makes the checks + `bregctl apply` makes, under the same apply lock and in transactions it + rolls back, and reports whether an activation is pending and its kind + (`initial`, `successor`, `role_change`, `adopted`, or `none`). With + `--backup BINDING_PATH=BINDING_FILE` it checks each backup binding as apply + would. +- `bregctl status --runtime-config FILE` reads the activation ledger and + reports the active package digest and activation id, the + `registryRevision`, the role mode, the schema fingerprint, the maintenance + status, and every ledger row. +- `bregctl apply` of the active package under other configured database roles + is its own `role_change` activation: it grants the new runtime role and + revokes what the retired runtime role held. +- `bregctl apply --operator-reference TEXT` binds an operator's change + reference to the activation. The ledger records only its keyed hash, so the + audit profile must be keyed. +- Every activation, adoption included, is audited as + `breg-activation-audit/v1`. An audit destination that refuses the request + entry refuses the apply as `apply.audit.unavailable`, and nothing changes. +- `bregctl instance-claim adopt` also runs on a database the instance claim + already names, as after a point-in-time recovery, a snapshot, or a base + backup: it claims the database again with a raised epoch, supersedes every + open import authority, and is audited with the event `reclaimed`. Run it + once after any restore, before the database serves. The + `instance_claim.already_current` refusal is gone. +- A runtime file may name one role as both `database.roles.migration` and + `database.roles.runtime`, with one reference as both + `database.runtimeUrlRef` and `database.migrationUrlRef`. +- `bregctl dev` and the quickstart serve the local registry with one database + role. A session retained from an earlier release keeps its split runtime + file; remove the project's `.breg/dev` directory to start one that serves + with one role. +- A runtime file refused as `runtime_config.document` names the wrong field + and why, without repeating the refused value. +- A `bregctl` usage error, in human and JSON output, names the refused + argument and its error kind but never repeats a rejected token, so a + mistyped `--operator-reference` value no longer reaches the terminal or a + captured log in clear. The diagnostic code stays `usage.invalid` and the + exit status 2. +- The BReg image carries `bregctl` at `/usr/local/bin/bregctl`. The + entrypoint stays `breg`; run `plan`, `apply`, and `status` from the image by + overriding the entrypoint. See + [Activate from the image](https://docs.registrystack.org/operate/breg/#activate-from-the-image). + +## Registry Casework + +- `caseworkctl check PROJECT --against-breg-package DIR [--source-id ID] + [--bregctl-bin PATH]` verifies a closed BReg package through the `bregctl` + of the same release and compares its registry revision with the source's + pinned `sourceRevision`. A mismatch is refused as + `casework.source-revision.stale`; `casework.source.ambiguous`, + `casework.source.none`, `casework.source.unknown`, and + `casework.source-description.missing` name the other refusals. +- `caseworkctl plan` refuses a runtime role that cannot read an existing + activation ledger as `casework.activation.ledger-unreadable`, naming + `caseworkctl apply` with the migration credential. +- `caseworkctl plan` names `casework.activation.hosted-work-would-be-dropped` + and `casework.activation.unpublished-audit-would-be-dropped` when schema + migration 15 or 17 is pending and the table it drops still holds rows; + apply refuses the same. +- `caseworkctl package --help` says that its package is the unit + `caseworkctl plan` and `apply` activate, and that `bregctl package` builds a + BReg registry package. +- A command line `caseworkctl` refuses is described by the kind of error and + the argument name, and names `caseworkctl --help`. The refused value is + never repeated. +- The Casework image carries `caseworkctl` at `/usr/local/bin/caseworkctl`. + The entrypoint stays `casework`; run `plan`, `apply`, and `status` from the + image by overriding the entrypoint. See + [Run plan, apply, and status from the image](https://docs.registrystack.org/operate/casework/#run-plan-apply-and-status-from-the-image). + +## Evidence + +- `evidencectl audit show --last-operation` reads a retained history that + holds request-batch entries, and refuses with `evidence.audit.request-batch` + when the last operation is a batch. An operation that ended in a denial or + a transient failure prints `DISCLOSURE DENIED` or `TRANSIENT FAILURE` with + its reason, and earlier operations left without an outcome are counted on + an `EARLIER OPERATIONS WITHOUT AN OUTCOME` line. +- A request batch with more items than `burstPerPrincipal`, or a holder-bound + release presenting more holder keys than the burst, is refused as + `evidence.invalid_request` (400) without `Retry-After` instead of + `evidence.rate_limited`, and charges nothing. `evidence check` and + `evidencectl doctor` warn when `rateLimits.burstPerPrincipal` is below the + largest request cost the bundle admits. The shipped reference deployments, + BReg Evidence starters, and the `evidencectl` local bundle set + `burstPerPrincipal: 16`. +- An HTTP source response whose shape drifted from the declared projection + increments `evidence_source_shape_drift_total{source}` and writes a + rate-limited `WARN` naming the source and the declared JSON pointers. A 404 + that is not the source's declared `unresolvedProblem` still answers + `source.unavailable` and now writes a rate-limited `WARN`. Neither record + carries a response value, an undeclared member name, a selector, or a + subject. +- `evidencectl access policy add` and `access client add` no longer refuse + the directory they just created when the shell runs under a strict umask + such as `077`. + +## Registry Scheduling + +- `schedulingctl status --runtime-config FILE` reads the full activation + history, the schema version, and the role mode. +- `schedulingctl plan` names `schedulingctl.activation.unpublished-audit` + when schema migration 8 is pending and the audit outbox still holds + unpublished records, and refuses a runtime role that cannot read an + existing ledger as `schedulingctl.activation.ledger-unreadable`. +- A command line `schedulingctl` refuses is described by the kind of error + and the argument name, and names `schedulingctl --help`. The refused value + is never repeated. +- `schedulingctl` is published as a release binary for `linux-amd64`, + `linux-arm64`, and `macos-arm64`, and the Scheduling image carries it at + `/usr/local/bin/schedulingctl`. The entrypoint stays `scheduling`, and the + Scheduling runtime remains an image-only artifact. + +## Shared platform and clients + +- The shared audit writer recovers an active file whose final line a crash + tore: it moves those bytes to the owner-only side file `.torn`, + truncates to the last complete line, and logs the side file's path and byte + count instead of refusing to start. A `FileDestination` whose file name ends + in a companion suffix another stream owns is refused with + `AuditDestinationError::PathNamesReservedCompanion`. `AuditSegments` and + `SealedSegment` give inspection tooling a read-only view of a stream's + companion names and sealed segments. See + [Audit retention](https://docs.registrystack.org/operate/retention-and-persistent-state/#audit-retention). +- The Rust client crates are unchanged. The Node.js bindings are rebuilt with + `@napi-rs/cli` 3.10.5, which adds a `__napiBindingTarget` export to the + standalone binding packages; the `@registrystack/client` facade does not + expose it. + +## Release process + +- The BReg, Casework, and Scheduling images each carry their operator tool + beside the runtime, built from the same source, and the release reports + each image tool's exposure. +- The upgrade rehearsal adopts a pre-ledger BReg database through plan and + apply and then activates a successor, rehearses the Casework upgrade + through plan and apply, and replaces a sealed Evidence package. +- The Pages gate fails when a published release was never promoted, and the + published docsets are promoted so the development docs name the latest + release. + +[Changes since v0.35.0](https://github.com/registrystack/registry-stack/compare/v0.35.0...v0.36.0). +This remains a pre-1.0 Beta release for self-hosted institutional pilots. diff --git a/release/scripts/test_check_advisory_baselines.py b/release/scripts/test_check_advisory_baselines.py index 129ac2f91..5e07e350d 100644 --- a/release/scripts/test_check_advisory_baselines.py +++ b/release/scripts/test_check_advisory_baselines.py @@ -27,19 +27,19 @@ ROOT / "release/security/scheduling-advisory-baseline.json", ) LIVE_REFERENCE_IMAGE_DIGESTS = { - "relay": "sha256:356899e509f3241064862d919eff941e6b406575ae45ecd493814ac94df17395", - "breg": "sha256:dcb71543bb75903ff9b21ecc64cc3ac7a760026ee288f21d0f42d94811edb107", - "casework": "sha256:f14bb0d0a8f60a068594962ae4dc5e4bb81f00f043f1f5872b0330455afeb84f", - "discovery": "sha256:0071c5043c0e6ab67377901ac81bde5c70c4553427c53a13179f151edbce5f08", - "evidence": "sha256:86f5717af0e365c2db69a169c53af96df4a62cb820222e84fe99ac6256147887", - "scheduling": "sha256:d81fdad41c859a23e57935a95063b4201f5f5493d5b96cb5797eb3cfea43c712", + "relay": "sha256:5aebf959e4e64d7516048a43d6897951252a717673662cba0fe89ecb2195b248", + "breg": "sha256:66f29a1c74b4d8dca7760134afbff116f53a1103563d86e8af1e9f410d436fb7", + "casework": "sha256:e201e91d4ef9c339b120eed7d924546398ad73db8b247d1a91d9b05169c4679c", + "discovery": "sha256:ab8f064d9904e01e0ba1255c053d6922b8ab347c32d54e560a8a0551d905c04f", + "evidence": "sha256:49820862728b93bb7a37b9701cf9bcdc988ce1c03b7486e3368ecdfae0840603", + "scheduling": "sha256:5ad4cc6f14c6d0bccdfd677899d433f525e0a659f817d58a724a5833b9223802", } -LIVE_REFERENCE_SOURCE_REVISION = "545a9afc4840b1305c1641e36342c257640308fc" +LIVE_REFERENCE_SOURCE_REVISION = "022b88e987db5e4779164ad7bf33df0201c48bea" # The date the live exceptions below were reviewed against, stated here rather # than derived from the baselines: deriving it from their own reviewed_at values # would make the checker's future-dated guard unreachable for the newest # exception. Move it forward by hand when the baselines are renewed. -LIVE_REVIEW_EVALUATION_DATE = "2026-09-27" +LIVE_REVIEW_EVALUATION_DATE = "2026-09-28" LIVE_REFERENCE_PROVENANCE = { "relay": "local_reproduction", "breg": "local_reproduction", diff --git a/release/security/breg-advisory-baseline.json b/release/security/breg-advisory-baseline.json index 4cfc42fbd..4ea0243e8 100644 --- a/release/security/breg-advisory-baseline.json +++ b/release/security/breg-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:e2cf667642050e791c727f2c9f8652620243e861f67e09a37d60457a62ff42ec", + "sha256:c31b74d54ead5d08a1dee2c877c3a3f729840c3ff20fbd7748c545891f3a12d3", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -51,7 +51,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508" + "definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e" }, "policies": [ { @@ -74,8 +74,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. The image also carries the operator tool /usr/local/bin/bregctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it imports none of those interfaces either, and its one review-required address-taken dlsym use is the same Wasmtime Intel JIT profiler availability probe, which only selects NotifyEvent and Initialize. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -92,14 +92,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", - "component_layer_id": "sha256:e2cf667642050e791c727f2c9f8652620243e861f67e09a37d60457a62ff42ec", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", + "component_layer_id": "sha256:c31b74d54ead5d08a1dee2c877c3a3f729840c3ff20fbd7748c545891f3a12d3", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:dcb71543bb75903ff9b21ecc64cc3ac7a760026ee288f21d0f42d94811edb107", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:66f29a1c74b4d8dca7760134afbff116f53a1103563d86e8af1e9f410d436fb7", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -119,10 +119,10 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:577127529d4388e0d0e4378b2916fb55c3fed791939e30b0b8c8457b8a2f54b5" + "sha256": "sha256:ab69b613e2ef39d436df4c9ac7799a9ba8e1fd922767df68f4a9fd802ad93061" } ], - "definition_digest": "sha256:56d2d22ff7128bae0339af49cc2f1c3fec82b2e70ccfd1ba32e4c19312904c7b" + "definition_digest": "sha256:f8726a260aebefc95d67d769acdcc9011a835a2cd233816bacb2c3694a56ad78" } }, { @@ -132,8 +132,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. The image also carries the operator tool /usr/local/bin/bregctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither imports nor contains strfmon or strfmon_l either, and its one review-required address-taken dlsym use is the same Wasmtime Intel JIT profiler availability probe, which only selects NotifyEvent and Initialize. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -150,14 +150,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", - "component_layer_id": "sha256:e2cf667642050e791c727f2c9f8652620243e861f67e09a37d60457a62ff42ec", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", + "component_layer_id": "sha256:c31b74d54ead5d08a1dee2c877c3a3f729840c3ff20fbd7748c545891f3a12d3", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:dcb71543bb75903ff9b21ecc64cc3ac7a760026ee288f21d0f42d94811edb107", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:66f29a1c74b4d8dca7760134afbff116f53a1103563d86e8af1e9f410d436fb7", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -177,10 +177,10 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:577127529d4388e0d0e4378b2916fb55c3fed791939e30b0b8c8457b8a2f54b5" + "sha256": "sha256:ab69b613e2ef39d436df4c9ac7799a9ba8e1fd922767df68f4a9fd802ad93061" } ], - "definition_digest": "sha256:56d2d22ff7128bae0339af49cc2f1c3fec82b2e70ccfd1ba32e4c19312904c7b" + "definition_digest": "sha256:f8726a260aebefc95d67d769acdcc9011a835a2cd233816bacb2c3694a56ad78" } }, { @@ -190,8 +190,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", - "reviewed_at": "2026-09-27", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 BReg local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required address-taken dlsym use is Wasmtime's Intel JIT profiler availability probe and only selects NotifyEvent and Initialize. The image also carries the operator tool /usr/local/bin/bregctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf either, and its one review-required address-taken dlsym use is the same Wasmtime Intel JIT profiler availability probe, which only selects NotifyEvent and Initialize. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -208,14 +208,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:dcb71543bb75903ff9b21ecc64cc3ac7a760026ee288f21d0f42d94811edb107", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:66f29a1c74b4d8dca7760134afbff116f53a1103563d86e8af1e9f410d436fb7", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:b9ab59d1ee4e8ecefb7c0d8469b7b07f19f348f2c24d9124756fb79481c42508", + "runtime_definition_digest": "sha256:7558165a48ea99d40311697ef83afd72209e0ebc1c0dc0cae3d86834deb2288e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -235,10 +235,10 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:577127529d4388e0d0e4378b2916fb55c3fed791939e30b0b8c8457b8a2f54b5" + "sha256": "sha256:ab69b613e2ef39d436df4c9ac7799a9ba8e1fd922767df68f4a9fd802ad93061" } ], - "definition_digest": "sha256:56d2d22ff7128bae0339af49cc2f1c3fec82b2e70ccfd1ba32e4c19312904c7b" + "definition_digest": "sha256:f8726a260aebefc95d67d769acdcc9011a835a2cd233816bacb2c3694a56ad78" } } ] diff --git a/release/security/casework-advisory-baseline.json b/release/security/casework-advisory-baseline.json index 16182c241..bc45ef834 100644 --- a/release/security/casework-advisory-baseline.json +++ b/release/security/casework-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:db86528964016f079eab2b7bad4ef0abae4384d785a1ec5de0770b838a811f6d", + "sha256:bfe0e48830a26f652534c163384cdf49a55502de34582b7841c17d5836bcf056", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a" + "definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4" }, "policies": [ { @@ -75,8 +75,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/caseworkctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it imports none of those interfaces either, with no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -93,14 +93,14 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", - "component_layer_id": "sha256:db86528964016f079eab2b7bad4ef0abae4384d785a1ec5de0770b838a811f6d", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", + "component_layer_id": "sha256:bfe0e48830a26f652534c163384cdf49a55502de34582b7841c17d5836bcf056", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:f14bb0d0a8f60a068594962ae4dc5e4bb81f00f043f1f5872b0330455afeb84f", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:e201e91d4ef9c339b120eed7d924546398ad73db8b247d1a91d9b05169c4679c", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/casework", - "sha256": "sha256:79507e0e70e31d1ca75c372bcb2fa2b1ea569db38ba8684f4ad2754cbfe14f8d" + "sha256": "sha256:343c74b9e7b57c46fbb6bf0e4f895c8c793b9a4a013f54c2a3f35b56f9cabf21" } ], - "definition_digest": "sha256:62fcb4d5a076312f6fa28cfe53abad2a9650f4b454200e1ee4c45426b88a84e4" + "definition_digest": "sha256:1bbff11cf797d1f73cfd25c46309fecb5ca922f59988dbbe2405ea284c0d0241" } }, { @@ -133,8 +133,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/caseworkctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither imports nor contains strfmon or strfmon_l either, with no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -151,14 +151,14 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", - "component_layer_id": "sha256:db86528964016f079eab2b7bad4ef0abae4384d785a1ec5de0770b838a811f6d", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", + "component_layer_id": "sha256:bfe0e48830a26f652534c163384cdf49a55502de34582b7841c17d5836bcf056", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:f14bb0d0a8f60a068594962ae4dc5e4bb81f00f043f1f5872b0330455afeb84f", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:e201e91d4ef9c339b120eed7d924546398ad73db8b247d1a91d9b05169c4679c", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/casework", - "sha256": "sha256:79507e0e70e31d1ca75c372bcb2fa2b1ea569db38ba8684f4ad2754cbfe14f8d" + "sha256": "sha256:343c74b9e7b57c46fbb6bf0e4f895c8c793b9a4a013f54c2a3f35b56f9cabf21" } ], - "definition_digest": "sha256:62fcb4d5a076312f6fa28cfe53abad2a9650f4b454200e1ee4c45426b88a84e4" + "definition_digest": "sha256:1bbff11cf797d1f73cfd25c46309fecb5ca922f59988dbbe2405ea284c0d0241" } }, { @@ -191,8 +191,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", - "reviewed_at": "2026-09-27", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 Casework local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/caseworkctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf either, with no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -209,14 +209,14 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:f14bb0d0a8f60a068594962ae4dc5e4bb81f00f043f1f5872b0330455afeb84f", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:e201e91d4ef9c339b120eed7d924546398ad73db8b247d1a91d9b05169c4679c", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:8f156e5000b6f2feeaef9b65d99bc02faf470638ea7334d0b3cd4b59c360936a", + "runtime_definition_digest": "sha256:4e967da0b3b3123dea084093caf8e123182ab0d1d782e31e328c74ad398137e4", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,10 @@ }, { "path": "/usr/local/bin/casework", - "sha256": "sha256:79507e0e70e31d1ca75c372bcb2fa2b1ea569db38ba8684f4ad2754cbfe14f8d" + "sha256": "sha256:343c74b9e7b57c46fbb6bf0e4f895c8c793b9a4a013f54c2a3f35b56f9cabf21" } ], - "definition_digest": "sha256:62fcb4d5a076312f6fa28cfe53abad2a9650f4b454200e1ee4c45426b88a84e4" + "definition_digest": "sha256:1bbff11cf797d1f73cfd25c46309fecb5ca922f59988dbbe2405ea284c0d0241" } } ] diff --git a/release/security/discovery-advisory-baseline.json b/release/security/discovery-advisory-baseline.json index 9b1323f7a..9b9183ec9 100644 --- a/release/security/discovery-advisory-baseline.json +++ b/release/security/discovery-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:84d05115cda35c19fd92209ee841ad5b1bfd3b69da5639bdac0e498b58b8d35a" + "sha256:042f8f69118c661950b5901101736d4a07fd496f4d9e06db451fbcf832d99577" ], "config": { "user": "65532", @@ -50,7 +50,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4" + "definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1" }, "policies": [ { @@ -73,8 +73,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -91,14 +91,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", - "component_layer_id": "sha256:84d05115cda35c19fd92209ee841ad5b1bfd3b69da5639bdac0e498b58b8d35a", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", + "component_layer_id": "sha256:042f8f69118c661950b5901101736d4a07fd496f4d9e06db451fbcf832d99577", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0071c5043c0e6ab67377901ac81bde5c70c4553427c53a13179f151edbce5f08", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:ab8f064d9904e01e0ba1255c053d6922b8ab347c32d54e560a8a0551d905c04f", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -118,10 +118,10 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:dbb1089a8a8ef64f28986d8868bad88b8f161dc96cf5b07c53216a65ee8a4431" + "sha256": "sha256:3fa9f5588060a9bf73880d2c748182656141737b6446302de3935cf7672164fc" } ], - "definition_digest": "sha256:01b31f62e1832cbd0a8e3695429bdb043bfe2d7eaadff3b7b508f019fb9c2043" + "definition_digest": "sha256:9b0dd112f98dff9d517a9f1ba4c2e238d84dcb9e67d342aba1a0f6e91a2b318c" } }, { @@ -131,8 +131,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -149,14 +149,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", - "component_layer_id": "sha256:84d05115cda35c19fd92209ee841ad5b1bfd3b69da5639bdac0e498b58b8d35a", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", + "component_layer_id": "sha256:042f8f69118c661950b5901101736d4a07fd496f4d9e06db451fbcf832d99577", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0071c5043c0e6ab67377901ac81bde5c70c4553427c53a13179f151edbce5f08", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:ab8f064d9904e01e0ba1255c053d6922b8ab347c32d54e560a8a0551d905c04f", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -176,10 +176,10 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:dbb1089a8a8ef64f28986d8868bad88b8f161dc96cf5b07c53216a65ee8a4431" + "sha256": "sha256:3fa9f5588060a9bf73880d2c748182656141737b6446302de3935cf7672164fc" } ], - "definition_digest": "sha256:01b31f62e1832cbd0a8e3695429bdb043bfe2d7eaadff3b7b508f019fb9c2043" + "definition_digest": "sha256:9b0dd112f98dff9d517a9f1ba4c2e238d84dcb9e67d342aba1a0f6e91a2b318c" } }, { @@ -189,8 +189,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", - "reviewed_at": "2026-09-27", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 Discovery local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -207,14 +207,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0071c5043c0e6ab67377901ac81bde5c70c4553427c53a13179f151edbce5f08", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:ab8f064d9904e01e0ba1255c053d6922b8ab347c32d54e560a8a0551d905c04f", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:f4eda18f671b09a25aab5e95fe3adfd96129413ca26feb23517260f652a2cdf4", + "runtime_definition_digest": "sha256:479947848345b349a5bba716d4856ddaa49db1a0cbae3544a36082b795380ae1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -234,10 +234,10 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:dbb1089a8a8ef64f28986d8868bad88b8f161dc96cf5b07c53216a65ee8a4431" + "sha256": "sha256:3fa9f5588060a9bf73880d2c748182656141737b6446302de3935cf7672164fc" } ], - "definition_digest": "sha256:01b31f62e1832cbd0a8e3695429bdb043bfe2d7eaadff3b7b508f019fb9c2043" + "definition_digest": "sha256:9b0dd112f98dff9d517a9f1ba4c2e238d84dcb9e67d342aba1a0f6e91a2b318c" } } ] diff --git a/release/security/evidence-advisory-baseline.json b/release/security/evidence-advisory-baseline.json index f868b76a2..02d5a83d5 100644 --- a/release/security/evidence-advisory-baseline.json +++ b/release/security/evidence-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:a4e4f24283977f2331f0160ef77fbb926e77b961c660a42bd9b72abb9964071c", + "sha256:93c91aaa69bafe87080294b20fe26f039e3d88293cb3401c1f68ff95f4b98d6e", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea" + "definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e" }, "policies": [ { @@ -75,8 +75,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -93,14 +93,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", - "component_layer_id": "sha256:a4e4f24283977f2331f0160ef77fbb926e77b961c660a42bd9b72abb9964071c", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", + "component_layer_id": "sha256:93c91aaa69bafe87080294b20fe26f039e3d88293cb3401c1f68ff95f4b98d6e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:86f5717af0e365c2db69a169c53af96df4a62cb820222e84fe99ac6256147887", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:49820862728b93bb7a37b9701cf9bcdc988ce1c03b7486e3368ecdfae0840603", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:303ff304ea4c83f7a5b578fda8a7e39933e82f9ae23b64cdd3a7abdd440574ad" + "sha256": "sha256:ab27ad3a5fbd3c38c69def31bdaeb03679fbc88abd37306bf33617966a2d0f5e" } ], - "definition_digest": "sha256:4c8927c5200d1928b4c2cb14127b5a6a8afc62147aeab60d702adbfa24ef126f" + "definition_digest": "sha256:2b0875e62b2433ed5b515af446b8093485eb4b032e1c8018cc013514b846e543" } }, { @@ -133,8 +133,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", - "reviewed_at": "2026-09-27", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -151,14 +151,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", - "component_layer_id": "sha256:a4e4f24283977f2331f0160ef77fbb926e77b961c660a42bd9b72abb9964071c", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", + "component_layer_id": "sha256:93c91aaa69bafe87080294b20fe26f039e3d88293cb3401c1f68ff95f4b98d6e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:86f5717af0e365c2db69a169c53af96df4a62cb820222e84fe99ac6256147887", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:49820862728b93bb7a37b9701cf9bcdc988ce1c03b7486e3368ecdfae0840603", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:303ff304ea4c83f7a5b578fda8a7e39933e82f9ae23b64cdd3a7abdd440574ad" + "sha256": "sha256:ab27ad3a5fbd3c38c69def31bdaeb03679fbc88abd37306bf33617966a2d0f5e" } ], - "definition_digest": "sha256:4c8927c5200d1928b4c2cb14127b5a6a8afc62147aeab60d702adbfa24ef126f" + "definition_digest": "sha256:2b0875e62b2433ed5b515af446b8093485eb4b032e1c8018cc013514b846e543" } }, { @@ -191,8 +191,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", - "reviewed_at": "2026-09-27", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 Evidence local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -209,14 +209,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:86f5717af0e365c2db69a169c53af96df4a62cb820222e84fe99ac6256147887", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:49820862728b93bb7a37b9701cf9bcdc988ce1c03b7486e3368ecdfae0840603", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:0330aa20fdccc9953cd9e92efa02808e9b4408074cf6c30724fc7839a4cd7cea", + "runtime_definition_digest": "sha256:a10acc0833fc23fee9ea7a794dba8586535a9aac53796757d423ef2bce7fad9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:303ff304ea4c83f7a5b578fda8a7e39933e82f9ae23b64cdd3a7abdd440574ad" + "sha256": "sha256:ab27ad3a5fbd3c38c69def31bdaeb03679fbc88abd37306bf33617966a2d0f5e" } ], - "definition_digest": "sha256:4c8927c5200d1928b4c2cb14127b5a6a8afc62147aeab60d702adbfa24ef126f" + "definition_digest": "sha256:2b0875e62b2433ed5b515af446b8093485eb4b032e1c8018cc013514b846e543" } } ] diff --git a/release/security/scheduling-advisory-baseline.json b/release/security/scheduling-advisory-baseline.json index 6804ceaf7..686a28c4a 100644 --- a/release/security/scheduling-advisory-baseline.json +++ b/release/security/scheduling-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:ce7fd62fba44ba6329c3c5a2441c286402c6f100a5ea009e07722f9e61008434", + "sha256:dbf145589e1ce92d848bd8450ea2cb4b47a9993dcc6fd5cb57ae934beaa00ec3", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0" + "definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539" }, "policies": [ { @@ -75,7 +75,7 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "reviewed_at": "2026-09-27", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -92,15 +92,15 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", - "component_layer_id": "sha256:ce7fd62fba44ba6329c3c5a2441c286402c6f100a5ea009e07722f9e61008434", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.35.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", + "component_layer_id": "sha256:dbf145589e1ce92d848bd8450ea2cb4b47a9993dcc6fd5cb57ae934beaa00ec3", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.36.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/schedulingctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it imports none of those interfaces either, with no review-required dynamic lookup. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still records this Trixie version as vulnerable and fixes only forky and sid.", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:d81fdad41c859a23e57935a95063b4201f5f5493d5b96cb5797eb3cfea43c712", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5ad4cc6f14c6d0bccdfd677899d433f525e0a659f817d58a724a5833b9223802", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/scheduling", - "sha256": "sha256:356b7fd646c030743e064b735c9a1da31e77b39cc5c616a1a66b34480354001f" + "sha256": "sha256:dc0f8e6673befe9cbd59c6344af37756d08b06947f2a71ef8121223ff6db4ea5" } ], - "definition_digest": "sha256:5963d577a25cee92892a4921c43040777da6db35b2e8374126043463d66be7b8" + "definition_digest": "sha256:72c3e92b71f0b2335689a05325cccbc5db547e7aa3bce245d443cf8bd67ca817" } }, { @@ -133,7 +133,7 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "reviewed_at": "2026-09-27", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -150,15 +150,15 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", - "component_layer_id": "sha256:ce7fd62fba44ba6329c3c5a2441c286402c6f100a5ea009e07722f9e61008434", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.35.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian fixes the issue only in forky and sid.", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", + "component_layer_id": "sha256:dbf145589e1ce92d848bd8450ea2cb4b47a9993dcc6fd5cb57ae934beaa00ec3", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.36.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. That base now ships libc6 2.41-12+deb13u4 itself, and the image's application layer installs the same pinned libc6 2.41-12+deb13u4 over it, so the reviewed loader, libc, libm and libpthread bytes are unchanged from the v0.33.0 review. Its executable neither imports nor contains strfmon or strfmon_l. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/schedulingctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither imports nor contains strfmon or strfmon_l either, with no review-required dynamic lookup. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian fixes the issue only in forky and sid.", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:d81fdad41c859a23e57935a95063b4201f5f5493d5b96cb5797eb3cfea43c712", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5ad4cc6f14c6d0bccdfd677899d433f525e0a659f817d58a724a5833b9223802", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/scheduling", - "sha256": "sha256:356b7fd646c030743e064b735c9a1da31e77b39cc5c616a1a66b34480354001f" + "sha256": "sha256:dc0f8e6673befe9cbd59c6344af37756d08b06947f2a71ef8121223ff6db4ea5" } ], - "definition_digest": "sha256:5963d577a25cee92892a4921c43040777da6db35b2e8374126043463d66be7b8" + "definition_digest": "sha256:72c3e92b71f0b2335689a05325cccbc5db547e7aa3bce245d443cf8bd67ca817" } }, { @@ -191,7 +191,7 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "reviewed_at": "2026-09-27", + "reviewed_at": "2026-09-28", "expires_at": "2026-10-06", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -208,15 +208,15 @@ "runtime_base_changed", "runtime_config_changed" ], - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", - "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.35.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36342916528 at source 545a9afc4840b1305c1641e36342c257640308fc, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-27; Debian still lists no fixed zlib package for Trixie.", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.36.0 Linux AMD64 Scheduling local reproduction is exact rehearsal run 36494611865 at source 022b88e987db5e4779164ad7bf33df0201c48bea, built on the pinned distroless cc-debian13 nonroot base sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97. zlib1g 1:1.3.dfsg+really1.3.1-1+b1 remains in the same unchanged base layer. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The exposure report has no review-required dynamic lookup. The image also carries the operator tool /usr/local/bin/schedulingctl in the application layer the fingerprint binds; its exposure report and a scan of its exported bytes show it neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf either, with no review-required dynamic lookup. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-28; Debian still lists no fixed zlib package for Trixie.", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:d81fdad41c859a23e57935a95063b4201f5f5493d5b96cb5797eb3cfea43c712", - "reference_source_revision": "545a9afc4840b1305c1641e36342c257640308fc", + "reference_image_digest": "sha256:5ad4cc6f14c6d0bccdfd677899d433f525e0a659f817d58a724a5833b9223802", + "reference_source_revision": "022b88e987db5e4779164ad7bf33df0201c48bea", "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:bc1e9d918c4cbc2491b0e989944cb93a512cf5f98f88c15d1a593c5b7e2127a0", + "runtime_definition_digest": "sha256:6081e23b7b37912f244fe5a68b177952dd052d2ad358572acf79b2cbf7742539", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,10 @@ }, { "path": "/usr/local/bin/scheduling", - "sha256": "sha256:356b7fd646c030743e064b735c9a1da31e77b39cc5c616a1a66b34480354001f" + "sha256": "sha256:dc0f8e6673befe9cbd59c6344af37756d08b06947f2a71ef8121223ff6db4ea5" } ], - "definition_digest": "sha256:5963d577a25cee92892a4921c43040777da6db35b2e8374126043463d66be7b8" + "definition_digest": "sha256:72c3e92b71f0b2335689a05325cccbc5db547e7aa3bce245d443cf8bd67ca817" } } ]