Skip to content

ci: align Filestash with fleet contracts - #2

Closed
jmagar wants to merge 6 commits into
mainfrom
codex/fleet-alignment-reviewable-20260730
Closed

ci: align Filestash with fleet contracts#2
jmagar wants to merge 6 commits into
mainfrom
codex/fleet-alignment-reviewable-20260730

Conversation

@jmagar

@jmagar jmagar commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • clear high-severity frontend audit findings
  • update reachable vulnerable gRPC dependency for GO-2026-6061
  • remove the remaining Jenkins ARM64 target and enforce x86_64-only publication
  • route fast Linux work through typed runner-farm pools
  • make heavy publication release.published-only on GitHub-hosted x86_64

Validation

  • actionlint and fleet contract
  • make verify; 30 frontend tests; Go vet/tests and coverage gates
  • govulncheck: zero affected reachable vulnerabilities
  • npm audit: zero vulnerabilities
  • zero ARM/aarch64/QEMU active build scan

@jmagar

jmagar commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #4 (codex/fleet-alignment-20260730), which is content-identical to this branch's fleet-alignment work plus a reusable-workflow implementation-ref repin (the only diff between the two branches is the pinned commit SHA in ci.yml/release.yml). Closing this one; #4 is the canonical PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant