registrystack / registrystack/registry-stack

Onboard the Registry Casework release image before the first 0.30.0 candidate

Aperta
#989 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
area:release
Lingua principale
Rust
Stelle
2
Fork
0
Merge medio
2h 55m
PR unite (30g)
130

Descrizione

### What is missing

Registry Casework joins the release set at 0.30.0 with `casework`, `caseworkctl`, and `mint` in `casework-install.sh` and the `ghcr.io/registrystack/casework` image. The docs on the `docs/casework-rewrite` branch already cite `ghcr.io/registrystack/casework:v0.30.0`. The out-of-band onboarding steps in `release/OPERATIONS.md` ("Onboard a new release image", steps 3 to 6) are not done, and nothing fails early on them: the first real candidate fails closed instead, the same shape as the BReg onboarding at v0.26.0.

Verified on 2026-09-11:

- `gh api /orgs/registrystack/packages/container/casework` returns 404, and so does `casework-candidate`. Neither GHCR package identity exists.
- `casework-candidate` is absent from `CANDIDATE_PACKAGES` in `release/scripts/cleanup-release-candidates.py`. It must stay absent until the private package exists, because listing an absent package fails the whole daily cleanup run closed.
- `release/security/casework-advisory-baseline.json` does not exist, and `release/scripts/test_check_advisory_baselines.py` pins only the relay, breg, discovery, evidence, and mint baselines.

### Ask

In the order the operations guide gives, outside the release clock:

1. Run the classic-PAT oras bootstrap for `casework` (public) and `casework-candidate` (private), and grant both `registrystack/registry-stack` Actions access with Write.
2. Add `casework-candidate` to `CANDIDATE_PACKAGES` with its matching test, as soon as the private package exists. Keep `casework` in `PUBLIC_PACKAGES`.
3. Run one named baseline-bootstrap candidate, which is expected to stop at the advisory-baseline check.
4. Author and review `release/security/casework-advisory-baseline.json` from that exact private image, and extend the baseline test pins with it. Do not copy another product's baseline.

### Why a ticket

These steps need a real candidate image and a human sign-off on the baseline, so they cannot ride in the documentation and installer PR that introduces the release assets.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia con i passaggi 3–6 in release/OPERATIONS.md, quindi esamina release/scripts/cleanup-release-candidates.py e release/scripts/test_check_advisory_baselines.py. Esegui il bootstrap dei pacchetti casework pubblici e privati, esegui un candidato baseline-bootstrap denominato e usa esattamente quell’immagine privata per la baseline dell’advisory. Il lavoro è completato quando l’accesso ai pacchetti funziona, i test di pulizia dei candidati e della baseline hanno esito positivo e release/security/casework-advisory-baseline.json è stato esaminato e fissato.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
docker, github-actions
Ambito
devops, release, security
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.