Skip to content

chore(main): release 3.105.0 - #1520

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--components--shifter
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--components--shifter

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

3.105.0 (2026-09-16)

Features

  • add administrator audit log and activity history surface (3a30e4c)
  • add administrator audit log and activity history surface (a22bfab)
  • add AWS environment teardown workflow (ed3a891)
  • add AWS environment teardown workflow (#1287) (346f868)
  • add in-tenant artifact preparation (d14930f)
  • add in-tenant artifact preparation (03f24dd)
  • add nazgul GCP tenant scaffolding + bake lane (f092e2e)
  • add runtime Mission Control lease policies (f830b44)
  • administer range-to-workspace scoping and reassignment (PLAT-237) (b9b8268)
  • administer range-to-workspace scoping and reassignment (PLAT-237) (21c27c4)
  • api: expose retry-safe range operations and truthful cleanup outcomes (07ab2ac)
  • api: expose retry-safe range operations and truthful cleanup outcomes (a1d823c)
  • cms: ship a launchable smoke-linux in-box pack (e596e71)
  • complete SPA and RAES authority cutover (9cddc3c)
  • complete SPA and RAES cutover (aaa78a6)
  • ctf: add public event registration (d40f27e)
  • ctf: bind signed receipts to range identity (ab5bcbd)
  • ctf: bind signed receipts to range identity (ad97760)
  • ctf: durable delivery worker and in-app channel for scoped communications (56ed720)
  • ctf: durable delivery worker and in-app channel for scoped communications (ee69e35)
  • ctf: in-place content refresh for managed CTF events (66ccfea)
  • ctf: in-place content refresh for managed CTF events (8416c53)
  • ctf: model scoped communication campaigns, audiences, content, and deliveries (0d7a75d)
  • ctf: model scoped communication campaigns, audiences, content, and deliveries (28c4904)
  • ctf: platform-admin global CTF event administration (2324f4b)
  • ctf: platform-admin global CTF event administration (c7a02c6)
  • ctf: support multiple full co-organizers per CTF event (7863ca0)
  • ctf: support multiple full co-organizers per CTF event (d16915a)
  • ctf: unified communication admission and scheduler due-time integration (6a9da4f)
  • ctf: unified communication admission and scheduler due-time integration (ac30b92)
  • deployment-configurable Mission Control range lease policy (ac9a0e5)
  • deployment-configurable Mission Control range lease policy (79f160e)
  • enforce browser accessibility with an axe gate and ADR-055 baseline ratchet (d0e9533)
  • enforce browser accessibility with an axe gate and ADR-055 baseline ratchet (10d18f7)
  • enforce GCP zero-egress firewall for pinned none ranges (PLAT-238) (5e625db)
  • engine: seed RAES image registry from base range image env (c4b44fb)
  • gcp: add the #2087 range-escape containment-signal seam (dea807f)
  • gcp: add the #2087 range-escape containment-signal seam (4a4613c)
  • gcp: bootstrap single-project deployments from external inventory (5fbf929)
  • gcp: bootstrap single-project deployments from inventory (0b08091)
  • gcp: fail-fast on GCE range preconditions before gdc-bootstrap deploys (0105598)
  • gcp: fail-fast on GCE range preconditions before gdc-bootstrap deploys (d1b44b0)
  • gcp: multi-region range-cell placement via RANGE_NETWORK_ZONES (b89c773)
  • gcp: multi-region range-cell placement via RANGE_NETWORK_ZONES (3d56aa4)
  • gcp: package isolated model broker deployment (345ef30)
  • gcp: package isolated model broker deployment (05c51e8)
  • installation: complete AWS EKS bundle runtime-env projection and doctor preflight (3aa0741)
  • installation: complete AWS EKS bundle runtime-env projection, doctor preflight, and settings/inventory modules (b2d3c14)
  • mission-control: enforce per-file agent upload limit before transfer (9b45170)
  • mission-control: enforce per-file agent upload limit before transfer (e624add)
  • model-access: define policy catalog and shared access contracts (fadb418)
  • model-access: enforce project sharing authority (39c1337)
  • model-access: enforce required scenario/event model admission before launch (PLAT-202) (7511688)
  • model-access: enforce required scenario/event model admission before launch (PLAT-202) (4cb00fa)
  • model-access: persist sharing bindings and resolve overlapping policies (201f097)
  • model-access: persist sharing bindings and resolve overlapping policies (551d671)
  • model-access: project sharing authority changes (9d004d8)
  • parameterize gdc-bootstrap by environment for multi-tenant standup (985f91e)
  • parity-safe GCP range pause/resume for GDC VM Runtime and GCE (557c699)
  • parity-safe GCP range pause/resume for GDC VM Runtime and GCE (144838e)
  • range-owned GCP Cloud NAT so none ranges have no NAT path (PLAT-238) (fd7842e)
  • range: configurable warm pool for faster initial launch (045d7e9)
  • range: configurable warm pool for faster initial launch (#28) (5672618)
  • range: ship launchable smoke-linux pack + RAES-aware post-deploy smoke (4e218af)
  • realize pinned range egress on the AWS provisioner path (PLAT-238) (b741e72)
  • user lifecycle administration (suspend/reset/ownership transfer) (5764ad4)
  • user lifecycle administration (suspend/reset/ownership transfer) (d96706a)
  • workspace egress policy control in the SPA admin surface (PLAT-238) (b5f3ede)
  • workspace network egress policy backend spine (PLAT-238) (a97dcd8)
  • workspace-level network egress policy (zero-egress) on AWS and GCP (518fdbd)
  • workspaces: add member invitations and onboarding (810564a)
  • workspaces: add member invitations and onboarding (e0a4a57)
  • workspaces: add per-workspace resource quotas and usage (36a06b7)
  • workspaces: add per-workspace resource quotas and usage (ce594fd)

Bug Fixes

  • address pre-merge review — undeployable NAT, deny-all firewall, agent URL, token-auth contract (PLAT-238) (f40bf02)
  • address review cycle 2 — move-chain, fail-closed egress, model layering, session-only auth (PLAT-238) (53e9d19)
  • adr-guard: address Sonar documentation findings (613f365)
  • adr-guard: address Sonar documentation findings (245ec34)
  • adr-guard: clarify ingress schema field (e504650)
  • adr-guard: resolve new-code Sonar findings (e85bafa)
  • adr-guard: resolve new-code Sonar findings (237e378)
  • api: address CI Postgres-lane + SonarCloud findings on retry-safe operations (aef8c4b)
  • api: align public contract with runtime boundaries (ee6639c)
  • api: align published contract with runtime authority (33d15c7)
  • api: align scoreboard runtime with published contract (bfa34eb)
  • api: resolve SonarCloud findings in retry-safe launch mixin and cleanup projection (1e98a9a)
  • api: split range history projection (7fe8066)
  • bootstrap: stop deploy facade from clobbering distinct module main entrypoints (9dcc016)
  • CI quality gate — mypy auth typing, ruff format, provisioner operation-dict assertion (PLAT-238) (4808b41)
  • clarify gcp resource metadata handling (ec14d31)
  • clear artifact preparation quality findings (4cb947d)
  • clear remaining SonarCloud new-code smells (docstrings, type hint, S5778) (e5a170a)
  • close cyberscript GCE egress gap + RAES router leak; test-quality forwarding (PLAT-238) (fdcd8d4)
  • cms: align retry-safe launch with post-PLAT-202 create_range_dispatch (64bb600)
  • complete artifact preparation quality gates (ab9e00b)
  • ctf: address validator quality findings (eff78a4)
  • ctf: address validator quality findings (cd3e16a)
  • ctf: clear remaining SonarCloud new-code findings (type hints, re-export imports) (4583bd4)
  • ctf: close participant readiness safety gaps (29fa2f3)
  • ctf: close participant readiness safety gaps (69abe12)
  • ctf: close participant readiness safety gaps (7eecf96)
  • ctf: keep staff-assign role request field backward-compatible (ADR-040) (82e830d)
  • ctf: lock receipt range without nullable join (1117dd4)
  • ctf: narrow parsed URL type (ffde5d3)
  • ctf: narrow parsed URL type (5840905)
  • ctf: precompute challenge filter URLs in the view (Web:MaxLineLengthCheck) (800f1be)
  • ctf: refresh submission API contract (e28fdbf)
  • ctf: renumber shared audit entity_type migration to 0015 after dev merge (984fc05)
  • ctf: resolve SonarCloud new-code findings (type hints, file split, audit atomicity) (4ddbfe0)
  • ctf: service-boundary authz asserts, stale-role revocation, and file splits (b573353)
  • ctf: trim _crud.py docstrings under the 500-line new-code limit (6db33c4)
  • enforce participant readiness evidence (84d7f9f)
  • enforce participant readiness evidence (4209e94)
  • finish nazgul GCP standup — Helm metadata netpol, evidence read, polaris verify-stack (d28af86)
  • frontend: redirect legacy settings route (711245d)
  • gate GCS usage-log delivery for Domain Restricted Sharing orgs (435c9ef)
  • gcp: add platform-network Private Google Access DNS for googleapis (3114d68)
  • gcp: add platform-network Private Google Access DNS for googleapis (8c853fa)
  • gcp: add the missing Workload Identity annotation for provisioner-launcher (3bc7234)
  • gcp: address bootstrap CI and Sonar findings (09118d7)
  • gcp: allow egress to the GKE metadata server for Workload Identity (5ec586e)
  • gcp: allow provisioner-launcher egress to the GKE control-plane CIDR (8e21f89)
  • gcp: allow shifter-jobs egress to Cloud SQL for range provisioning (ef015d2)
  • gcp: allow the Google APIs backend range on platform/jobs egress (f45b1ab)
  • gcp: close range-cell egress release-blockers under ADR-056 (27cd255)
  • gcp: close range-cell egress release-blockers under ADR-056 (84217da)
  • gcp: deploy worker-operation-result-applier (was orphaned manifest) (a5a536c)
  • gcp: disable NodeLocal DNSCache (incompatible with Dataplane V2) (08865ff)
  • gcp: disable NodeLocal DNSCache (incompatible with Dataplane V2) (bf33891)
  • gcp: docstring the containment-signal delivery helper (Sonar) (2e6a5b9)
  • gcp: drop the inert 34.126.0.0/18 backend range (red herring) (a92846d)
  • gcp: enable Cloud NAT dynamic port allocation for the platform VPC (b44cfa7)
  • gcp: enable Cloud NAT dynamic port allocation for the platform VPC (7754782)
  • gcp: enable workload identity for gcp-dev platform pods (c26362a)
  • gcp: enforce control-plane NetworkPolicy via GKE Dataplane V2 (4d4b726)
  • gcp: enforce control-plane NetworkPolicy via GKE Dataplane V2 (07ff61f)
  • gcp: fix fresh GCE-backend deploy gaps (GDC baremetal-gcr gate + virtctl) (218faf1)
  • gcp: gate GDC baremetal-gcr image-reader off the default GCE apply (3c2d810)
  • gcp: grant the CI deploy SA the platform-core roles it needs (a35a5fb)
  • gcp: grant the CI deploy SA the platform-core roles it needs (enumerated) (24d2497)
  • gcp: harden the cluster default node pool config (Shielded secure boot) (f6328bb)
  • gcp: keep range model under the S104 line ceiling (47e06c1)
  • gcp: make CI OIDC/WIF a foundational root so gcp-dev destroy+rebuild cycles (728403d)
  • gcp: make CI OIDC/WIF a foundational root so gcp-dev destroy+rebuild cycles (b84ff7c)
  • gcp: make range guests reachable for setup + probe (19cefe0)
  • gcp: pin the GKE cluster default node pool to the dedicated node SA (6fd9463)
  • gcp: pin the GKE cluster default node pool to the dedicated node SA (8a5b504)
  • gcp: pin virtctl digest and gate it off the default GCE provisioner image (afea747)
  • gcp: resolve gcp-dev-destroy state addresses by suffix (e55a65e)
  • gcp: resolve gcp-dev-destroy state addresses by suffix (fix skipped guards) (2da283e)
  • gcp: scope the deploy SA's serviceAccountUser to the GKE node SA (b1d944d)
  • gcp: separate CI identities (f6f0b7b)
  • gcp: separate CI identities (d1a1146)
  • gcp: support immutable GitHub deployment identities (abfd5e9)
  • gcp: type hints + keep range model within line budget (Sonar #2037) (1dc3f89)
  • grant packer SA bucket-metadata reader on gdc-vm-images (GDC export + polaris stack fetch) (77f0e9b)
  • ignore create-only default-pool node_config drift on GKE cluster (f39a905)
  • make network firewall teardown ordering-safe (rule-group dereference + inspection route toggle) (f722188)
  • model-access: regenerate /api/v1 contract for CTFEvent.model_demand (1c20b63)
  • model-access: regenerate SPA openapi types for CTFEvent.model_demand (f8ecdf6)
  • model-access: resolve remaining quality findings (23521bf)
  • model-access: resolve SonarCloud quality-gate findings (ac84696)
  • model-access: satisfy PostgreSQL and quality gates (f34e4d7)
  • model-access: satisfy Sonar line-length rule (e9ec4ec)
  • ngfw: drop dead popup.closed===undefined check (javascript:S3403) (9323209)
  • order-safe Network Firewall teardown for range rule groups and portal route toggle (bbd41fe)
  • packer: kali GCE guest boots + sshd binds — static networkd config (bee2443)
  • packer: kali guest boots on GCE — remove NetworkManager dual-stack (0496561)
  • parametrize dict generics for SonarCloud new-code gate (#1287) (11fd1de)
  • polaris splice helper hands off to a14-kali's real entrypoint path (e028a88)
  • polaris: preserve splice credential on recreation (3c497cc)
  • polaris: preserve splice credential on recreation (9b0f5a9)
  • postgres FOR UPDATE join + SonarCloud new-code findings (19c0f15)
  • provisioner: drop invalid provider= kwarg to build_guest_execution_context (483e7c0)
  • provisioner: keep compensation diagnostics bounded and file under size gate (42284ca)
  • provisioner: log credential-channel failure type without leaking secrets (c6cd210)
  • provisioner: route failed-provision compensation through canonical teardown (e3ce40d)
  • provisioner: route failed-provision compensation through canonical teardown (cfbe0cd)
  • provisioner: surface the real cause of credential-channel failures (a741e85)
  • quality: extract inline template JS to static files, split long JS/templates, bundle tags-builder params; document verified SonarCloud false-positives (c3b01ee)
  • quality: resolve ~400 SonarCloud maintainability findings (type hints, docstrings, static methods, comment placement, complexity) (811713f)
  • quality: resolve all open SonarCloud findings across the repo (a3cd24a)
  • quality: resolve all open SonarCloud findings across the repo (9a069f9)
  • quality: resolve SonarCloud vulnerabilities, bugs, and critical findings (code smells tracked in #2185) (25f22ed)
  • raes: scope image-registry projection by authored source name (0bb8530)
  • re-parent 0055 egress-mode migration onto 0054 placement-zone leaf (PLAT-238) (879a570)
  • resolve API contract drift and SonarCloud new-code smells (PLAT-237) (845defa)
  • resolve bootstrap SAST B404 on type-only subprocess import (#1287) (e758373)
  • resolve remaining preparation quality findings (1c95d7a)
  • return authored range-scope error messages (CodeQL py/stack-trace-exposure) (b36d668)
  • runner: standardize isolated runner network placement (43e6b79)
  • runner: standardize isolated runner network placement (bab316e)
  • sanitize request id in range-scope logs (CodeQL py/log-injection) (6dcd083)
  • satisfy cutover API and quality gates (3482e15)
  • security: validate same-origin redirect targets in extracted JS and stop exception-detail exposure in auth session view (CodeQL) (540e793)
  • smoke-linux: re-bind pack digest after concepts.md em-dash fix (ffed60e)
  • smoke: make post-deploy smoke work with RAES-native ranges (dd717eb)
  • supply bake-time DC01_IP so polaris dns service starts during polaris-vm bake (853ea93)
  • test: satisfy gce range preconditions via the process boundary, not a first-party patch (03d3330)
  • warm-pool: clear remaining Sonar new-code findings (cast replace(), re-export all, test globals) (14da16d)
  • warm-pool: resolve Sonar quality-gate findings and claim-consistency constraint (7cf9b9c)
  • workspaces: clear remaining invitation quality findings (6d6879c)
  • workspaces: resolve invitation quality findings (6a60f3c)

This PR was generated with Release Please. See documentation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants