Skip to content

fix(releases): harden compare and pin deploy helper toolchain#55

Open
jkaczman wants to merge 5 commits intomainfrom
harden-releases
Open

fix(releases): harden compare and pin deploy helper toolchain#55
jkaczman wants to merge 5 commits intomainfrom
harden-releases

Conversation

@jkaczman
Copy link
Copy Markdown
Collaborator

A couple of fixes:

  • Harden release verification by validating manifest bin_path values in compare.bash. Prevents path traversal and misleading (cross-run) binary comparisons.
  • Make deploy builds more supply-chain-safe by pinning and verifying external helper tooling (linuxdeploy, AppRun, NSIS helper DLL, cargo-xwin, and the global pnpm tarball)
  • Stop enabling the motion AI telemetry/debug feature in the default Raspberry camera hub release.

@jkaczman jkaczman requested a review from arrdalan April 11, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant