[Release] Publish accumulated usability and security hardening — September 2026 #51

Closed
opened 2026-09-08 01:20:40 +02:00 by zemion · 6 comments
Owner

User-authorized release preparation: finish known verification gaps, review accumulated dirty/untracked work, create new independently versioned package tags, publish branches/packages and a reviewed signed catalog/runtime where gates permit. Initial inventory:30 dirty repositories; Cases additionally has a root npm version mismatch in already-published0.1.23 and needs a new patch (no historical tag changes). Core/meta target0.1.45; module patches retain independent versions. Scope includes Core#295,#296, Meta#50 and owning security issues. Gates:focused cross-module checks, manifest/version/migration alignment, browser/build/dependency regressions, immutable source/artifact checks. Track actual publication separately from local verification; no production deployment or live mail operations authorized or planned.

User-authorized release preparation: finish known verification gaps, review accumulated dirty/untracked work, create new independently versioned package tags, publish branches/packages and a reviewed signed catalog/runtime where gates permit. Initial inventory:30 dirty repositories; Cases additionally has a root npm version mismatch in already-published0.1.23 and needs a new patch (no historical tag changes). Core/meta target0.1.45; module patches retain independent versions. Scope includes Core#295,#296, Meta#50 and owning security issues. Gates:focused cross-module checks, manifest/version/migration alignment, browser/build/dependency regressions, immutable source/artifact checks. Track actual publication separately from local verification; no production deployment or live mail operations authorized or planned.
Author
Owner

Preparation update: refreshed all79 origins; previously reported ahead counts were stale, and branches already matched Gitea. Preserved historical Docs tag discrepancies (v0.1.6/v0.1.21) without force-updating either source. Created fresh operator-private remote clones. Selected new Core/meta0.1.45 and28 modulepatches (including Cases0.1.24 metadata repair); source version gate now passes, migration baseline recorded and strictgraphgate passes. Fixed Meta#50 mixed-clockfixture; Campaign611tests+37subtests and standalone11pathchecks pass. Fixed stale Committee/Risk documentationcount assertions; their full suites plus Voting/Scheduling pass149tests. Release helper now supports literal MODULE_VERSION with regressioncoverage. Repaired missing documented Owners-only v* protection on seven package repos; no application permissions/secrets changed. Finalbuild compiles but startupgzip exceeds unchangedbudget by9bytes; a genuine code-size reduction is pending, so no Coretag/pushyet. Broaderfocused and browserchecks continue. No liveapplication data or mailoperationperformed.

Preparation update: refreshed all79 origins; previously reported ahead counts were stale, and branches already matched Gitea. Preserved historical Docs tag discrepancies (v0.1.6/v0.1.21) without force-updating either source. Created fresh operator-private remote clones. Selected new Core/meta0.1.45 and28 modulepatches (including Cases0.1.24 metadata repair); source version gate now passes, migration baseline recorded and strictgraphgate passes. Fixed Meta#50 mixed-clockfixture; Campaign611tests+37subtests and standalone11pathchecks pass. Fixed stale Committee/Risk documentationcount assertions; their full suites plus Voting/Scheduling pass149tests. Release helper now supports literal MODULE_VERSION with regressioncoverage. Repaired missing documented Owners-only v* protection on seven package repos; no application permissions/secrets changed. Finalbuild compiles but startupgzip exceeds unchangedbudget by9bytes; a genuine code-size reduction is pending, so no Coretag/pushyet. Broaderfocused and browserchecks continue. No liveapplication data or mailoperationperformed.
Author
Owner

Source preparation committed:28 independently versioned modules plus Coreshared-UI/cache changes and Website dependency patch (notpushedyet). FinalCoreUI productionbuild passes unchangedcap at163908gzipbytes (220headroom), after moving unchangedsettings-only defaults to lazycode. Full209browserconformance pass;13post-extractionappearance/theme cases pass. Release-relatedfixturechecks now derive exactversions fromcomposition; immutableartifact tests intentionally waitfornewlocaltags. Two orchestration findings surfaced: localmodule candidate tagging wrongly required futureCorelock; fixing onlylocal sequencing whilepreserving mandatorypublicationalignment. Flatpak projects /home and /usr as nfsnobody; hostread-onlyverification showsreal trustedownership, so publicationruntime is beingprepared with privatehostPython3.12, withoutchangingtrustgates. Remote-registryTrivy0.74 scan foundknownHIGH/CRITICAL findings inruntimebaseimage candidates; compatiblepatchupdates underreview, andruntimepublication remainsheld. Source/package/catalogpublication isseparate; no productiondeployment.

Source preparation committed:28 independently versioned modules plus Coreshared-UI/cache changes and Website dependency patch (notpushedyet). FinalCoreUI productionbuild passes unchangedcap at163908gzipbytes (220headroom), after moving unchangedsettings-only defaults to lazycode. Full209browserconformance pass;13post-extractionappearance/theme cases pass. Release-relatedfixturechecks now derive exactversions fromcomposition; immutableartifact tests intentionally waitfornewlocaltags. Two orchestration findings surfaced: localmodule candidate tagging wrongly required futureCorelock; fixing onlylocal sequencing whilepreserving mandatorypublicationalignment. Flatpak projects /home and /usr as nfsnobody; hostread-onlyverification showsreal trustedownership, so publicationruntime is beingprepared with privatehostPython3.12, withoutchangingtrustgates. Remote-registryTrivy0.74 scan foundknownHIGH/CRITICAL findings inruntimebaseimage candidates; compatiblepatchupdates underreview, andruntimepublication remainsheld. Source/package/catalogpublication isseparate; no productiondeployment.
Author
Owner

Release installability checks found 25 module repositories whose Git root does not expose the owning WebUI package (18 missing manifests, 7 generic roots). The local-tag batch was stopped during preflight: readback confirms zero new tags, and nothing has been pushed. Repairing these facades requires 12 additional independently versioned patch releases; existing 28 module targets remain unchanged. Also restoring Tasks to default module discovery with a regression: all 46 descriptors remain lazy, production build passes unchanged budgets (516,987 raw / 163,976 gzip).

The full-registry catalog path also predates newer strict candidate provenance requirements. A tested compatibility bridge is being prepared to retain registry artifact hashes, exact annotated tag/commit identities and signed keyring binding without weakening publication checks. Runtime image remediation is separately tracked in #52; source/package/catalog publication will not replace the latest signed runtime release.

Release installability checks found 25 module repositories whose Git root does not expose the owning WebUI package (18 missing manifests, 7 generic roots). The local-tag batch was stopped during preflight: readback confirms zero new tags, and nothing has been pushed. Repairing these facades requires 12 additional independently versioned patch releases; existing 28 module targets remain unchanged. Also restoring Tasks to default module discovery with a regression: all 46 descriptors remain lazy, production build passes unchanged budgets (516,987 raw / 163,976 gzip). The full-registry catalog path also predates newer strict candidate provenance requirements. A tested compatibility bridge is being prepared to retain registry artifact hashes, exact annotated tag/commit identities and signed keyring binding without weakening publication checks. Runtime image remediation is separately tracked in #52; source/package/catalog publication will not replace the latest signed runtime release.
Author
Owner

Release staging checkpoint: immutable module tags and clean Git install

  • All 40 new module tags have been created locally and imported into shared checkouts with exact annotated-object/commit readback. Historical tag objects were preserved. Core/Meta are still untagged; no source pushes, registry publication, signed catalog publication or deployment have occurred.
  • Full functional checks completed in sections: 63 module combinations and 209 browser cases. The required single complete focused run remains pending the final Core tag/lock.
  • Final release-tool regression suite: 221 tests and 59 subtests passed after repairing a stale test reference to the relocated operations runbook.
  • The generated Core release lock references all 46 WebUI module Git packages by their exact tag commits. Clean npm ci with install scripts disabled and the production build pass against real, non-symlink Git packages. The unchanged startup gzip budget correctly caught an 873-byte overage caused by newer allowed dependency resolution. A small Core-only optional password-generator loading boundary reduces startup by approximately 2 KiB; browser verification and final committed-release rebuild are in progress. No budget increase or dependency downgrade is being used.
  • Private release clones use the existing commit identity locally only; registered origins, SSH authentication/host-key verification and trust gates are retained. Per-invocation IPv4 routing avoids a diagnosed IPv6 timeout without global network changes.
  • Native package publication and a fresh full signed module catalog will follow final verification. Runtime distribution and ordinary Meta Gitea runtime Release remain held under #52; no assetless Release will replace runtime discovery. Existing license metadata gaps remain separately recorded in #53.
### Release staging checkpoint: immutable module tags and clean Git install - All 40 new module tags have been created locally and imported into shared checkouts with exact annotated-object/commit readback. Historical tag objects were preserved. Core/Meta are still untagged; no source pushes, registry publication, signed catalog publication or deployment have occurred. - Full functional checks completed in sections: 63 module combinations and 209 browser cases. The required single complete focused run remains pending the final Core tag/lock. - Final release-tool regression suite: 221 tests and 59 subtests passed after repairing a stale test reference to the relocated operations runbook. - The generated Core release lock references all 46 WebUI module Git packages by their exact tag commits. Clean npm ci with install scripts disabled and the production build pass against real, non-symlink Git packages. The unchanged startup gzip budget correctly caught an 873-byte overage caused by newer allowed dependency resolution. A small Core-only optional password-generator loading boundary reduces startup by approximately 2 KiB; browser verification and final committed-release rebuild are in progress. No budget increase or dependency downgrade is being used. - Private release clones use the existing commit identity locally only; registered origins, SSH authentication/host-key verification and trust gates are retained. Per-invocation IPv4 routing avoids a diagnosed IPv6 timeout without global network changes. - Native package publication and a fresh full signed module catalog will follow final verification. Runtime distribution and ordinary Meta Gitea runtime Release remain held under #52; no assetless Release will replace runtime discovery. Existing license metadata gaps remain separately recorded in #53.
Author
Owner

Source publication is complete: all 40 selected module patches, Core 0.1.45 (a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45), and Meta 0.1.45 (88b685ff5e) were published, Meta last. Every main branch and immutable annotated tag object was read back and matched its frozen receipt. No historical tags were moved.

The first two attempts stopped before any mutation on separate intermittent SSH tag-read timeouts. Both failed logs were retained. A separately reviewed private operator adapter permits at most THREE total attempts only for exact timed-out, frozen-ref read commands; authentication errors, conflicts and all writes are not retried. Nine isolated tests passed independently, and all canonical source/preflight/receipt checks stayed unchanged. The successful publication needed zero retries. This is an operator-only aid, not a change to any published source tree.

The complete, unmodified focused gate passed (63 production module combinations, 213 browser cases, all backend and remaining checks), as did 221 release-tool tests plus 59 subtests. Two existing PostgreSQL concurrency tests remained explicitly skipped without a configured test database. All 79 shared worktrees are clean; remote-tracking synchronization for the 42 published repositories is in progress.

Native package CI was triggered automatically and is still publishing. The exact registry artifact download, native-archive production build, signed full module catalog and website publication are PENDING. This coordination issue stays open until those results are recorded. Runtime images and the ordinary Meta runtime Release remain held under #52; no deployment has been performed.

<!-- govoplan-release-20260908-source-complete --> Source publication is complete: all 40 selected module patches, Core 0.1.45 (a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45), and Meta 0.1.45 (88b685ff5e689acf096bdfc7084bd108e801e86e) were published, Meta last. Every main branch and immutable annotated tag object was read back and matched its frozen receipt. No historical tags were moved. The first two attempts stopped before any mutation on separate intermittent SSH tag-read timeouts. Both failed logs were retained. A separately reviewed private operator adapter permits at most THREE total attempts only for exact timed-out, frozen-ref read commands; authentication errors, conflicts and all writes are not retried. Nine isolated tests passed independently, and all canonical source/preflight/receipt checks stayed unchanged. The successful publication needed zero retries. This is an operator-only aid, not a change to any published source tree. The complete, unmodified focused gate passed (63 production module combinations, 213 browser cases, all backend and remaining checks), as did 221 release-tool tests plus 59 subtests. Two existing PostgreSQL concurrency tests remained explicitly skipped without a configured test database. All 79 shared worktrees are clean; remote-tracking synchronization for the 42 published repositories is in progress. Native package CI was triggered automatically and is still publishing. The exact registry artifact download, native-archive production build, signed full module catalog and website publication are PENDING. This coordination issue stays open until those results are recorded. Runtime images and the ordinary Meta runtime Release remain held under #52; no deployment has been performed.
Author
Owner

The scoped source/package/signed-catalog Git release is complete. This does NOT claim a production deployment or a new runtime distribution.

Published and verified

  • All 40 selected module patches plus Core and Meta 0.1.45: exact remote main commits and annotated tag objects verified. Core: a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45; Meta: 88b685ff5e689acf096bdfc7084bd108e801e86e. No historical tags were rewritten.
  • All 41 new native package pairs and developer govoplan==0.1.45 published through protected-tag CI. The full 73-wheel/47-WebUI set was downloaded from the canonical registry and independently verified. The separate developer Meta wheel matches all 73 declared dependency entries (16 base + 57 full-extra); SHA-256 e1c6b836e58280f54c3124391db6c28ce95321ebe217b6ef1144c8f6483ec973.
  • Website dependency fix d2d955a and signed catalog commit 03ac237949a1963189d1b7a4b3cc3397e60b10a1 pushed. Annotated tag catalog-v0.1.45, tag object 3d4735ea3028edfa47341e4f0b53650a4ae868d6, was remotely verified. The website build passed.
  • Stable catalog sequence 202609080236; canonical catalog hash 29b0b6ae10c0115f656a7035fd0c3298c31201f8a09a17834dbb73cf2d30a36e. Published file SHA-256 00dd1fa8390b7823dc082eddaca0bd826f9fcee0c479f56cd82ea55f93bf3cc8. The existing trusted keyring is unchanged; no key rotation occurred.
  • Canonical full package-set hash 2937bde1ad27926071a2d4cb26bb69bd87fb20f076552c171e671a9e5f95d939; artifact-lock hash 9472700ae76bc7920a91fc7619cf3c3c9f0438a2eb2edc0daefe4ddf6398facc.
  • All 79 registered shared repositories independently verified clean and synchronized with origin/main, with zero ahead/behind commits. Historical tags, unrelated branches and Git configuration were preserved.

Verification

The complete unmodified focused gate passed: 63 production module combinations, 213 browser cases, all remaining backend/structural checks; release tooling passed 221 tests plus 59 subtests. Two existing Datasources PostgreSQL concurrency tests remained explicitly skipped because no test PostgreSQL URL was configured; that evidence is not claimed.

Both fresh immutable Git-source and native-registry production builds passed unchanged budgets. The latter installed all 46 actual native module archives with strict peers, no force/legacy-peer workaround, and preserved all 208 external locked identities. Startup bundle: 513,825 raw / 163,019 gzip bytes, with 1,109 gzip bytes of budget headroom; 46 lazy / zero eager module descriptors. An initial private-harness check rejected npm's absolute-to-relative tarball spelling; all archive bytes/SRI matched. A narrowly tested two-spelling correction passed six tests and the full build, without altering source, dependency versions, integrity checks or budgets. Failed evidence was retained.

Push-triggered whole-system security audit run 1432 and developer Meta package run 1433 succeeded. Subsequent scheduled audit 1434 is a separate run and was not cancelled or bypassed.

Explicitly separate, still open

  • Website #9: public static-catalog deployment. Fresh public readback still serves 0.1.18 / sequence 202608061915. Git publication is not deployment: host/stack details and explicit authority are missing, and the website's two base-image scans require remediation/applicability review. No image was executed, rebuilt, adopted or deployed.
  • Meta #52: application runtime-image remediation, architecture/final-image evidence and runtime-release gates. No ordinary source-only Meta Gitea runtime Release was created, preserving existing runtime discovery.
  • Core #297, Access #22, Xrechnung #2, Workflow Engine #3, and Meta #53–#55 retain their separate isolation/recovery/history/licensing/release-tool work.

No live database migration, application deployment or real campaign mail was performed. Release notes and upgrade/manual smoke guidance are in docs/releases/0.1.45.md; bounded review evidence is in docs/security/SECURITY_PERFORMANCE_REVIEW_2026-09-08.md and the runtime audit report.

<!-- govoplan-release-20260908-final-publication --> The scoped source/package/signed-catalog Git release is complete. This does NOT claim a production deployment or a new runtime distribution. ## Published and verified - All 40 selected module patches plus Core and Meta 0.1.45: exact remote main commits and annotated tag objects verified. Core: `a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45`; Meta: `88b685ff5e689acf096bdfc7084bd108e801e86e`. No historical tags were rewritten. - All 41 new native package pairs and developer `govoplan==0.1.45` published through protected-tag CI. The full 73-wheel/47-WebUI set was downloaded from the canonical registry and independently verified. The separate developer Meta wheel matches all 73 declared dependency entries (16 base + 57 full-extra); SHA-256 `e1c6b836e58280f54c3124391db6c28ce95321ebe217b6ef1144c8f6483ec973`. - Website dependency fix `d2d955a` and signed catalog commit `03ac237949a1963189d1b7a4b3cc3397e60b10a1` pushed. Annotated tag `catalog-v0.1.45`, tag object `3d4735ea3028edfa47341e4f0b53650a4ae868d6`, was remotely verified. The website build passed. - Stable catalog sequence `202609080236`; canonical catalog hash `29b0b6ae10c0115f656a7035fd0c3298c31201f8a09a17834dbb73cf2d30a36e`. Published file SHA-256 `00dd1fa8390b7823dc082eddaca0bd826f9fcee0c479f56cd82ea55f93bf3cc8`. The existing trusted keyring is unchanged; no key rotation occurred. - Canonical full package-set hash `2937bde1ad27926071a2d4cb26bb69bd87fb20f076552c171e671a9e5f95d939`; artifact-lock hash `9472700ae76bc7920a91fc7619cf3c3c9f0438a2eb2edc0daefe4ddf6398facc`. - All 79 registered shared repositories independently verified clean and synchronized with origin/main, with zero ahead/behind commits. Historical tags, unrelated branches and Git configuration were preserved. ## Verification The complete unmodified focused gate passed: 63 production module combinations, 213 browser cases, all remaining backend/structural checks; release tooling passed 221 tests plus 59 subtests. Two existing Datasources PostgreSQL concurrency tests remained explicitly skipped because no test PostgreSQL URL was configured; that evidence is not claimed. Both fresh immutable Git-source and native-registry production builds passed unchanged budgets. The latter installed all 46 actual native module archives with strict peers, no force/legacy-peer workaround, and preserved all 208 external locked identities. Startup bundle: 513,825 raw / 163,019 gzip bytes, with 1,109 gzip bytes of budget headroom; 46 lazy / zero eager module descriptors. An initial private-harness check rejected npm's absolute-to-relative tarball spelling; all archive bytes/SRI matched. A narrowly tested two-spelling correction passed six tests and the full build, without altering source, dependency versions, integrity checks or budgets. Failed evidence was retained. Push-triggered whole-system security audit run 1432 and developer Meta package run 1433 succeeded. Subsequent scheduled audit 1434 is a separate run and was not cancelled or bypassed. ## Explicitly separate, still open - [Website #9](https://git.add-ideas.de/add-ideas/addideas-govoplan-website/issues/9): public static-catalog deployment. Fresh public readback still serves 0.1.18 / sequence 202608061915. Git publication is not deployment: host/stack details and explicit authority are missing, and the website's two base-image scans require remediation/applicability review. No image was executed, rebuilt, adopted or deployed. - [Meta #52](https://git.add-ideas.de/GovOPlaN/govoplan/issues/52): application runtime-image remediation, architecture/final-image evidence and runtime-release gates. No ordinary source-only Meta Gitea runtime Release was created, preserving existing runtime discovery. - Core #297, Access #22, Xrechnung #2, Workflow Engine #3, and Meta #53–#55 retain their separate isolation/recovery/history/licensing/release-tool work. No live database migration, application deployment or real campaign mail was performed. Release notes and upgrade/manual smoke guidance are in `docs/releases/0.1.45.md`; bounded review evidence is in `docs/security/SECURITY_PERFORMANCE_REVIEW_2026-09-08.md` and the runtime audit report.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan#51