Skip to content

Preserve named timezones in the BCI CLI image - #164

Open
ai-collaboration-app[bot] wants to merge 2 commits into
mainfrom
fix-cli-container-timezones
Open

ai-collaboration-app[bot] wants to merge 2 commits into
mainfrom
fix-cli-container-timezones

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Sep 16, 2026

Copy link
Copy Markdown

Preserve named TZ behavior after #162 by embedding time/tzdata in the SUSE Observability CLI. Agent timestamps and license/service-token expiry dates retain local dates in BCI micro without system zoneinfo. The embedded database follows the Go toolchain; system timezone data takes precedence.

Focused native amd64/arm64 container checks cover UTC, New York winter/summer, Kathmandu and unchanged JSON timestamps, with separate secret scans and UNKNOWN-inclusive vulnerability scans. Candidate evidence retains source/binary/image identities and inventories.

Recovery from run 35117696829: Grype JSON has no top-level artifacts; inventory validation now uses its CycloneDX output. Both reports also contained six matches: CVE-2026-54369/54370/54371 against libacl1 and libattr1. Refreshing the BCI micro 15.7 multi-architecture digest supplies the reported fixed RPM versions. No findings are suppressed and the zero-match gate remains enforced.

Validation at signed head b387844594ceeac3011cdda635a7daea8a288af5: native build/runtime/scans passed on both architectures: Go 1.25.13, 20 passing fixture checks each, 21 RPMs, zero Trivy/Grype vulnerability findings and zero secrets. Raw reports and source/binary/image identities: amd64 artifact, arm64 artifact. Existing CI: tests, lint, license and GoReleaser checks all passed. Gate controls reject missing/empty inventories and the retained vulnerable reports. Changed workflow passes offline Zizmor; full-repo findings remain in unchanged ci.yml.

Tracks https://github.com/StackVista/cve-reporter/issues/65. Changed-head independent review and human merge/release remain outstanding; this candidate does not close the delivery tracker.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant