Skip to content

chore(main): release 0.44.3 - #1504

Merged
Wikid82 merged 3 commits into
mainfrom
release-please--branches--main
Oct 7, 2026
Merged

Wikid82 merged 3 commits into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Here's what's new in Charon

0.44.3 (2026-10-07)

Bug Fixes

  • return 404 when deleting a missing certificate by id (a6f27fa)
  • security: harden backend consistency checks (#1500) (ff99e17)
  • security: harden consistency checks in the certificate service (8f9af9b)
  • security: harden consistency checks in the host service (ec32088)
  • security: harden consistency checks in the host services (b41e86e)
  • security: harden consistency checks in the import handlers (5aff4e6)
  • security: harden consistency checks in the user service (63ec1aa)
  • security: harden outbound client configuration in hub sync (69eaac2)
  • security: harden outbound client configuration in notification senders (df74024)
  • security: harden outbound client configuration in notification senders (#1492) (8f5095a)
  • security: harden outbound client configuration in update checker (06b193b)
  • security: harden outbound client configuration in update checker and hub sync (#1495) (5a63907)
  • security: harden outbound destination validation (2dc3815)
  • security: harden outbound destination validation (#1493) (8b0d0c2)
  • security: harden outbound validation configuration in notification senders (6120010)
  • security: normalize host names consistently (7a94ee3)
  • security: pin coraza/v3 to 3.8.1 in caddy build (10f92d7)
  • security: tighten error handling in the setup flow (7579c8b)
  • security: validate host references inside the write transaction (5bb66e2)
  • use http.NoBody in sender client tests (ac81b90)
  • waf: resolve OWASP CRS ruleset by loose name and warn when WAF has no ruleset (73aeec3)

Merge this PR to cut the release.

@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Supply Chain Verification Results

✅ PASSED

📦 SBOM Summary

  • Components: 1870

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Alpine published zlib 1.3.2-r1 on 2026-10-06 and the runtime stage's apk upgrade
now pulls it, so the version-pinned grype suppression for 1.3.2-r0 stopped
matching and Supply Chain Verification failed on main / release PR #1504.
grype still reports no fix for the CVE; risk acceptance and 2026-10-18 expiry
are unchanged.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The toolchain key hashes .trivyignore byte for byte, so the comment-only
change from the previous commit moved the key and left the Dockerfile pin
stale. The functional zlib version bump in .grype.yaml is unchanged.
Tracked in #1505.
@Wikid82
Wikid82 merged commit 060434e into main Oct 7, 2026
35 checks passed
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants