Preserve named timezones in the BCI CLI image - #164
Open
ai-collaboration-app[bot] wants to merge 2 commits into
Open
ai-collaboration-app[bot] wants to merge 2 commits into
ai-collaboration-app[bot] wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Preserve named
TZbehavior after #162 by embeddingtime/tzdatain the SUSE Observability CLI. Agent timestamps and license/service-token expiry dates retain local dates in BCI micro without system zoneinfo. The embedded database follows the Go toolchain; system timezone data takes precedence.Focused native amd64/arm64 container checks cover UTC, New York winter/summer, Kathmandu and unchanged JSON timestamps, with separate secret scans and UNKNOWN-inclusive vulnerability scans. Candidate evidence retains source/binary/image identities and inventories.
Recovery from run 35117696829: Grype JSON has no top-level
artifacts; inventory validation now uses its CycloneDX output. Both reports also contained six matches: CVE-2026-54369/54370/54371 against libacl1 and libattr1. Refreshing the BCI micro 15.7 multi-architecture digest supplies the reported fixed RPM versions. No findings are suppressed and the zero-match gate remains enforced.Validation at signed head
b387844594ceeac3011cdda635a7daea8a288af5: native build/runtime/scans passed on both architectures: Go 1.25.13, 20 passing fixture checks each, 21 RPMs, zero Trivy/Grype vulnerability findings and zero secrets. Raw reports and source/binary/image identities: amd64 artifact, arm64 artifact. Existing CI: tests, lint, license and GoReleaser checks all passed. Gate controls reject missing/empty inventories and the retained vulnerable reports. Changed workflow passes offline Zizmor; full-repo findings remain in unchangedci.yml.Tracks https://github.com/StackVista/cve-reporter/issues/65. Changed-head independent review and human merge/release remain outstanding; this candidate does not close the delivery tracker.