Skip to content

Release v2.5.0: published and verified #248

Description

@bifrost0x

Released v2.5.0 - 2026-10-05

WebSSH v2.5.0 is published at 07f472691e61eab6554dd6f75cf56fb8333964ba.
Changes since v2.4.0: 17 merged PRs. #252 includes the superseded #253 update.

Release decision and acceptance

The maintainer authorized publication on 2026-10-05 after the outstanding operational acceptance was explicitly reported. Real Warpgate acceptance, deployment canaries, upgrade/backup/restore/rollback rehearsal and applicable LDAP/Tailscale/Windows SMB/Firefox/Safari checks were not repeated on the final revision. They are tracked in #254, assigned to @bifrost0x, and are not marked passed. Required CI/security gates were not waived. Warpgate remains disabled by default.

  • Confirmed version, scope and exact release SHA.
  • Exact-candidate main CI and native images: run 37275096457.
  • Exact-tag CI, native AMD64/ARM64 scans/runtime checks and immutable image publication: run 37276528581.
  • Python 3.11 compatibility, full Python suite, Redis 7/8, SSH/SMB integration, both browser shards, dependency/vendor checks, container recovery/hardening and release-promotion checks passed. CodeQL Python, JavaScript/TypeScript and Actions passed on the release SHA.
  • GitHub Release published as stable/latest; remote tag resolves to the exact approved SHA.
  • Independently verified 2.5.0, 2.5 and latest share the index below, both runtime platforms carry the correct source SHA, and their attestation manifests retain SPDX-SBOM and SLSA-Provenance-v1 descriptors.
  • Deferred operational acceptance remains explicit in Deployment acceptance follow-up for v2.5.0 #254; no unrun check is represented as passing.

Versioned image identity

ghcr.io/bifrost0x/webssh@sha256:5cd320c7e48ab805dcb5a78950ed1ac41015e7f9ac0c97dd880e84308021312a

main still points to its separately built, previously verified index sha256:e6bc1700e1a455325bb2339c3dcc43323d142a3153cec7e14235ad8e156af575 for the same source revision. It is not required to be byte-identical to the tag-built image.

An additional local Windows/Python 3.14.3 backup/recovery/release-contract selection passed 236 tests. That is program-level evidence, not an operational rollback rehearsal.

Historical pre-release plan and earlier evidence (superseded by the release record above)

Goal

Prepare the next versioned release from reviewed main, covering the changes after v2.4.0. v2.5.0 is a proposed version and scope, not a published release or a date commitment.

Why

The post-v2.4.0 work contains workspace continuity and tmux directory-sync fixes (#231, #233, #234, #235, #236), optional Warpgate support (#238), paste/transcript fixes (#239, #241), connection/file usability improvements (#242), repository/tool maintenance (#232, #243), and security dependency updates (#246, #247). They are merged but not present in the v2.4.0 tag.

Baseline reviewed for planning: dc3d9bf26f57cbeb440227afe13f9635c4d9f258 (2026-10-03).
Changes since v2.4.0.
Successful baseline CI and native image publication.

Release acceptance

  • Pending at that assessment: Confirm the final scope, version and release-candidate SHA; list any deferred work with a reason. The tested revision below is not yet a release authorization.
  • Recorded at that assessment: Record the current tested candidate SHA and successful CI evidence for that exact revision: c0f83a85c3e8ddd3114c528bb57f14c2a6eb764f (2026-10-04). Final candidate selection remains in the preceding item; any later revision needs its own evidence.
  • Pending at that assessment: Repeat real Warpgate protocol acceptance on the final candidate: interactive authentication/cancellation, terminal, SFTP and tmux reconnect. Earlier protocol evidence in Support Warpgate SSH selectors and interactive authentication #238 is revision-specific.
  • Pending at that assessment: Run focused canary checks for tmux directory synchronization, multiline paste/control input, saved transcripts and mobile session/file navigation.
  • Pending at that assessment: Record upgrade and backup/restore/rollback results for the supported deployment, or document specific rollout limitations. Keep the target-specific LDAP, Tailscale, Windows SMB and Firefox/Safari checks identified in Fix repository security scan findings #202 explicit; they are not automatically covered by green CI.
  • Recorded at that assessment: Confirm native AMD64/ARM64 candidate scans and execution of the pinned workflow actions pass for the recorded revision. Both native scan/runtime jobs succeeded; the workflows use full commit-SHA action pins. ci: update GitHub Actions pins and urllib3 security floor #246 and fix: update vulnerable brace-expansion dev dependency #247 are already merged; the failures reported on 2026-10-02 are not open code tasks.
  • Pending at that assessment: Publish reviewed release notes and the version tag at the recorded candidate SHA, without re-merging code already in main.
  • Pending at that assessment: Verify the versioned multi-architecture image, source identity, SBOM/provenance and tag-pipeline results; link the release and evidence before closing the release milestone.

Evidence record

For each acceptance item, add the exact SHA, date, environment and result/link. Do not check an item merely because an older PR had similar tests. Deployment-specific exceptions need an explicit owner decision; never silently waive required CI/security gates.

This issue tracks release preparation. It does not promise additional features or a release date.

Evidence assessment - 2026-10-04

Assessed revision: c0f83a85c3e8ddd3114c528bb57f14c2a6eb764f, current main at assessment. The original planning baseline above is retained for traceability. Milestones and planning documentation are now applied through #249 and #250; these are documentation changes, not additional product features.

Verified for this revision

Build and Publish Docker Image run 37183855436 completed successfully on this exact SHA. The job and step results confirm:

  • Python test jobs, Python 3.11 compatibility selection, dependency locks and Redis 7/8 integration passed.
  • Disposable OpenSSH and encrypted SMB integration jobs passed.
  • Both Chromium browser shards passed. The first shard also ran JavaScript unit tests, lint and vendored-asset checks successfully.
  • Container threading/readiness, recovery/hardening smoke checks and the immutable release-promotion contract passed.
  • Native AMD64 candidate and native ARM64 candidate each passed source/image identity validation, the exact-image scan, and runtime compatibility/hardening checks.
  • Image promotion assembled and validated the index and promoted it without rebuilding. This is the main-branch publication, not evidence of a v2.5.0 tag release.
  • The commit's CodeQL Python, JavaScript/TypeScript and Actions checks also succeeded.

The separate security-scan job was skipped in this run. The native image-scan evidence above comes from the successful scan steps inside both build-candidate jobs, not from that skipped job. These are hosted job/step results; no new local or deployment-specific test is claimed.

Remaining acceptance and next actions

Area Existing evidence Required before closure
Final scope/version Proposed v2.5.0 scope and current tested SHA recorded Maintainer selects the final version/SHA and records any deferred scope. If SHA changes, refresh applicable evidence.
Real Warpgate protocol #238 records earlier tests on 47eb6f3 and f4328b4; those results are revision-specific Run the disposable Warpgate 0.29.0/OpenSSH fixture against the selected candidate, then record browser authentication/cancellation, terminal, byte-identical SFTP and tmux reconnect results.
Workflow canary Current Chromium regression gate is green Exercise tmux directory sync, multiline paste/control input, saved transcripts and mobile session/file navigation in the intended deployment; record environment and observations.
Upgrade/recovery Current container recovery/hardening smoke checks passed Record a supported-deployment upgrade, backup/restore and rollback rehearsal, including relevant schema compatibility. A generic smoke check does not prove an operational rollback.
Environment-specific compatibility Current disposable SSH/SMB tests passed; #202 identifies broader rollout limits Record applicable real LDAP, Tailscale-peer, Windows SMB/concurrent two-principal race, and Firefox/Safari checks, or explicit maintainer-owned limitations. None are waived here.
Versioned publication Main-branch image pipeline passed; latest published release remains v2.4.0 at assessment Publish reviewed notes and the selected version tag, then verify that tag's multi-architecture image, source identity, SBOM/provenance and pipeline before closing #248 and the milestone.

The Warpgate fixture instructions require a disposable local gateway and synthetic accounts. The hosted workflow runs explicit SSH and SMB integration jobs, but no Warpgate integration job; its standard Python suite excludes tests/integration. Green CI therefore does not satisfy the real Warpgate acceptance item. The fixture tests must not target an existing gateway because they modify test account policy and target settings.

Release owner: @bifrost0x. Next execution order: select candidate/scope, complete the missing protocol/canary/upgrade evidence, publish, then verify the versioned output. No release, tag, deployment or acceptance waiver was performed by this evidence update.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions