The latest PastureStack release and the current main branch receive security fixes. Historical upstream tags are retained for provenance and are not supported by PastureStack.
- Catalog repositories are untrusted input and can contain links, templates, questions, images, and large file trees.
- Repository URLs, database credentials, API credentials, installation identifiers, and private catalogs are sensitive.
- No catalog source is fetched by the default configuration.
- Do not commit database credentials, private repository URLs, tokens, production catalog data, or installation identifiers.
- The archived Compose parser dependency is forbidden by a source gate; legacy metadata is handled by focused local decoding and compatibility tests.
- The disposable build image uses a digest-pinned base, an official Ubuntu snapshot, and exact direct APT package versions. Its raw vulnerability report remains evidence even when an exact OpenVEX review marks build-only kernel headers not affected.
- Candidate validation builds twice, compares byte-identical archives, records both Go binaries and their linkage, and scans source, product, and build-image scopes before release approval.
- Release artifacts are built only from the current public
maincommit by the manually dispatched GitHub release workflow.
Report suspected vulnerabilities through this repository's private security advisory channel. Do not include credentials, private catalog content, or installation identifiers in a public issue.