Skip to content

Upstream release/security tracking #11

Description

@github-actions

Upstream Release/Security Tracking

Last automated check: 2026-09-21T16:28:29.198Z
Workflow run: https://github.com/esaueng/FactoryAssistantOS/actions/runs/35625795961

1 pinned upstream ref(s) need review.
1 upstream repo(s) have published security advisories listed below.

Component Upstream Pinned here Latest upstream Latest published advisory Status
OS home-assistant/operating-system 17.3 18.3 (release) no published repository advisories (none) review available upstream change
CORE home-assistant/core not pinned here 2026.9.3 (release) GHSA-4ghv-53cq-7wp3 (medium) (published) tracked
SUPERVISOR home-assistant/supervisor not pinned here 2026.09.3 (release) no published repository advisories (none) tracked
FRONTEND home-assistant/frontend not pinned here 20260826.7 (release) no published repository advisories (none) tracked
ADDONS home-assistant/addons not pinned here no release/tag found (none) no published repository advisories (none) tracked
OS_AGENT home-assistant/os-agent not pinned here 1.14.0 (release) no published repository advisories (none) tracked
BUILDER home-assistant/builder not pinned here 2026.09.0 (release) no published repository advisories (none) tracked
VERSION home-assistant/version not pinned here no release/tag found (none) no published repository advisories (none) tracked
LANDINGPAGE home-assistant/landingpage not pinned here 2026.08.0 (release) no published repository advisories (none) tracked

Security Review Queue

  • Review upstream release notes for each row marked review available upstream change.
  • Review linked published repository advisories before bumping pins.
  • Check GitHub Security Advisories manually for rows where the repository advisory check was unavailable.
  • Re-run the docs/OS_BUILD.md rebrand checklist against any bumped OS tag.
  • Confirm no Home Assistant/OHF marks re-enter shipped user-facing artifacts.
  • Confirm the monitoring-only safety boundary still holds.

This workflow only tracks upstream state using release/tag lookups and GitHub's public repository security advisory API. It does not modify pins, merge upstream code, or replace the manual security review required before a release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions