-
v0.1.1 — fix a CVE in v0.1.0's own grpc fix
CI / chart (push) Successful in 1sCI / security (push) Successful in 54sCI / test (push) Successful in 3m50sRelease / test (push) Successful in 1m44sRelease / chart (push) Successful in 2sRelease / image (push) Successful in 5m47sRelease / scan-image (push) Successful in 5sreleased this
2026-10-01 13:22:43 +00:00 Supersedes v0.1.0, released minutes earlier: that release's own trivy scan
(scan-image) found that google.golang.org/grpc v1.83.1 -- the version
v0.1.0 had just bumped to, to clear a different, earlier grpc CVE -- has
its own high-severity denial-of-service CVE (CVE-2026-84445), fixed one
patch later at v1.83.2. Pure timing between the two fixes, not a new
finding elsewhere: nothing else in this release changes. v0.1.0's image
and chart stay published under their own tag, per this project's own
release process, but are not deployed anywhere and the Ryuvia/charts
wrapper being created alongside this release points at v0.1.1, never at
v0.1.0.Same scope as v0.1.0 otherwise: watches TerdutServer, TerdutTeam,
TerdutEscalationRule, TerdutDeadmanSwitch and TerdutAlertSource CRDs and
drives terdut-server's own REST API to match. Full design in DESIGN.md,
staged build history in ROADMAP.md.Requires terdut-server v0.33.0 for its core operation (service-account
API, the v0.33.0 dead man's switch PUT this operator's reconciler needs
for update-in-place). TerdutTeam's crash-recovery path additionally needs
GET /api/teams?name= (TEAM-LOOKUP.md), committed to terdut-server main but
not yet in a tagged release as of this writing -- not a blocker for this
release, which installs only the operator and its CRDs, no CR of any
kind.Nothing here is irreversible on its own, for the same reason: no
TerdutServer, credential or webhook key is created by installing this
chart, only the operator Deployment, its RBAC, and the five CRDs.Downloads