diff --git a/backend/entrypoint.sh b/backend/entrypoint.sh index 178335b..db2115e 100755 --- a/backend/entrypoint.sh +++ b/backend/entrypoint.sh @@ -82,8 +82,10 @@ done # (Docker crée les bind-mounts manquants en root:root, appuser ne peut pas écrire) # REPO_BASE peut valoir /repos (mode rpm seul) ou /repos/rpm (mode both) RPM_REPO_BASE="${REPO_BASE:-/repos}" -for DISTRO in almalinux8 almalinux9 rocky8 rocky9 centos-stream9 oraclelinux8 \ - oraclelinux9 fedora opensuse-leap-15.5 opensuse-leap-15.6 \ +for DISTRO in almalinux8 almalinux9 almalinux10 rocky8 rocky9 rocky10 \ + centos-stream9 centos-stream10 oraclelinux8 oraclelinux9 \ + oraclelinux10 fedora fedora43 fedora44 \ + opensuse-leap-15.5 opensuse-leap-15.6 opensuse-leap-16.0 \ opensuse-leap opensuse-tumbleweed; do for ARCH in x86_64 aarch64 noarch; do mkdir -p "${RPM_REPO_BASE}/${DISTRO}/${ARCH}/repodata" 2>/dev/null || true diff --git a/backend/routers/distributions_router.py b/backend/routers/distributions_router.py index cf49dac..8211f7d 100755 --- a/backend/routers/distributions_router.py +++ b/backend/routers/distributions_router.py @@ -160,12 +160,17 @@ def migrate( "jammy": {"label": "Ubuntu 22.04 LTS"}, "noble": {"label": "Ubuntu 24.04 LTS"}, "focal": {"label": "Ubuntu 20.04 LTS"}, + "resolute": {"label": "Ubuntu 26.04 LTS"}, "bookworm": {"label": "Debian 12"}, + "trixie": {"label": "Debian 13"}, # Alpine Linux (APK — inventaire et CVE uniquement, pas de dépôt reprepro) "alpine3.18": {"label": "Alpine Linux 3.18", "pkg_type": "apk"}, "alpine3.19": {"label": "Alpine Linux 3.19", "pkg_type": "apk"}, "alpine3.20": {"label": "Alpine Linux 3.20", "pkg_type": "apk"}, "alpine3.21": {"label": "Alpine Linux 3.21", "pkg_type": "apk"}, + "alpine3.22": {"label": "Alpine Linux 3.22", "pkg_type": "apk"}, + "alpine3.23": {"label": "Alpine Linux 3.23", "pkg_type": "apk"}, + "alpine3.24": {"label": "Alpine Linux 3.24", "pkg_type": "apk"}, } diff --git a/backend/routers/scan_router.py b/backend/routers/scan_router.py index dc19d80..b04870f 100644 --- a/backend/routers/scan_router.py +++ b/backend/routers/scan_router.py @@ -73,16 +73,32 @@ def rescan_package( "jammy": "ubuntu:22.04", "noble": "ubuntu:24.04", "focal": "ubuntu:20.04", + "resolute": "ubuntu:26.04", "bookworm": "debian:12", + "trixie": "debian:13", # RPM - "almalinux8": "almalinux:8", - "almalinux9": "almalinux:9", - "rocky8": "rockylinux:8", - "rocky9": "rockylinux:9", - "centos-stream9": "centos:9", - "oraclelinux8": "oraclelinux:8", - "oraclelinux9": "oraclelinux:9", - "fedora42": "fedora:42", + "almalinux8": "almalinux:8", + "almalinux9": "almalinux:9", + "almalinux10": "almalinux:10", + "rocky8": "rockylinux:8", + "rocky9": "rockylinux:9", + "rocky10": "rockylinux:10", + "centos-stream9": "centos:9", + "centos-stream10": "centos:10", + "oraclelinux8": "oraclelinux:8", + "oraclelinux9": "oraclelinux:9", + "oraclelinux10": "oraclelinux:10", + "fedora": "fedora:42", + "fedora42": "fedora:42", + "fedora43": "fedora:43", + "fedora44": "fedora:44", + "opensuse-leap-15.6": "opensuse/leap:15.6", + "opensuse-leap-16.0": "opensuse/leap:16.0", + # APK + "alpine3.21": "alpine:3.21", + "alpine3.22": "alpine:3.22", + "alpine3.23": "alpine:3.23", + "alpine3.24": "alpine:3.24", } grype_distro = _DISTRO_MAP.get(distribution, distribution) diff --git a/backend/security-keys/upstream-archive-keyring.gpg b/backend/security-keys/upstream-archive-keyring.gpg index b45a54d..af0d429 100644 Binary files a/backend/security-keys/upstream-archive-keyring.gpg and b/backend/security-keys/upstream-archive-keyring.gpg differ diff --git a/backend/services/distributions_apk.py b/backend/services/distributions_apk.py index a0f2941..11ffefa 100644 --- a/backend/services/distributions_apk.py +++ b/backend/services/distributions_apk.py @@ -37,6 +37,9 @@ {"codename": "alpine3.19", "name": "Alpine Linux 3.19", "arch": ["x86_64", "aarch64"]}, {"codename": "alpine3.20", "name": "Alpine Linux 3.20", "arch": ["x86_64", "aarch64"]}, {"codename": "alpine3.21", "name": "Alpine Linux 3.21", "arch": ["x86_64", "aarch64"]}, + {"codename": "alpine3.22", "name": "Alpine Linux 3.22", "arch": ["x86_64", "aarch64"]}, + {"codename": "alpine3.23", "name": "Alpine Linux 3.23", "arch": ["x86_64", "aarch64"]}, + {"codename": "alpine3.24", "name": "Alpine Linux 3.24", "arch": ["x86_64", "aarch64"]}, ] VALID_APK_CODENAMES: set[str] = {d["codename"] for d in APK_DISTRIBUTIONS} diff --git a/backend/services/distributions_apt.py b/backend/services/distributions_apt.py index 9825c20..a288d52 100755 --- a/backend/services/distributions_apt.py +++ b/backend/services/distributions_apt.py @@ -1,6 +1,6 @@ """ Gestion des distributions reprepro (enterprise). -Distributions fixes : jammy, noble, focal, bookworm. +Distributions fixes : focal, jammy, noble, resolute, bookworm, trixie. reprepro est exécuté directement dans le container backend (installé dans l'image). Les volumes repos/conf, repos/dists, repos/db et repos/pool sont partagés. """ @@ -36,11 +36,27 @@ "badge": "ESM", "color": "gray", }, + { + "codename": "resolute", + "name": "Ubuntu 26.04 LTS", + "full_name": "Ubuntu 26.04 LTS — Resolute Raccoon", + "os": "ubuntu", + "badge": "LTS", + "color": "purple", + }, { "codename": "bookworm", "name": "Debian 12", "full_name": "Debian 12 — Bookworm", "os": "debian", + "badge": "Oldstable", + "color": "red", + }, + { + "codename": "trixie", + "name": "Debian 13", + "full_name": "Debian 13 — Trixie", + "os": "debian", "badge": "Stable", "color": "red", }, @@ -52,6 +68,9 @@ {"codename": "alpine3.19", "name": "Alpine Linux 3.19", "os": "alpine", "pkg_type": "apk"}, {"codename": "alpine3.20", "name": "Alpine Linux 3.20", "os": "alpine", "pkg_type": "apk"}, {"codename": "alpine3.21", "name": "Alpine Linux 3.21", "os": "alpine", "pkg_type": "apk"}, + {"codename": "alpine3.22", "name": "Alpine Linux 3.22", "os": "alpine", "pkg_type": "apk"}, + {"codename": "alpine3.23", "name": "Alpine Linux 3.23", "os": "alpine", "pkg_type": "apk"}, + {"codename": "alpine3.24", "name": "Alpine Linux 3.24", "os": "alpine", "pkg_type": "apk"}, ] VALID_CODENAMES = ( @@ -64,11 +83,17 @@ "ubuntu-jammy-updates": "jammy", "ubuntu-noble": "noble", "ubuntu-focal": "focal", + "ubuntu-resolute": "resolute", + "ubuntu-resolute-updates": "resolute", "debian-bookworm": "bookworm", + "debian-trixie": "trixie", + "debian-trixie-updates": "trixie", "ubuntu-jammy-security": "jammy", "ubuntu-noble-security": "noble", "ubuntu-focal-security": "focal", + "ubuntu-resolute-security": "resolute", "debian-bookworm-security": "bookworm", + "debian-trixie-security": "trixie", } diff --git a/backend/services/distributions_rpm.py b/backend/services/distributions_rpm.py index f8c7f31..3fd4632 100644 --- a/backend/services/distributions_rpm.py +++ b/backend/services/distributions_rpm.py @@ -1,7 +1,8 @@ """ Gestion des distributions RPM (createrepo_c). -Distributions : AlmaLinux 8, Rocky Linux 8, CentOS Stream 9, Oracle Linux 8, - Fedora, openSUSE Leap 15.5/15.6/Leap/Tumbleweed. +Distributions : AlmaLinux 8/9/10, Rocky Linux 8/9/10, CentOS Stream 9/10, + Oracle Linux 8/9/10, Fedora 42/43/44, + openSUSE Leap 15.6/16.0/Tumbleweed. createrepo_c est exécuté directement dans le container backend. """ import os @@ -37,6 +38,17 @@ "package_manager": "dnf", "grype_distro": "almalinux:9", }, + { + "codename": "almalinux10", + "name": "AlmaLinux 10", + "full_name": "AlmaLinux 10 — Purple Lion", + "os": "almalinux", + "version": "10", + "badge": "RHEL-compat", + "color": "blue", + "package_manager": "dnf", + "grype_distro": "almalinux:10", + }, { "codename": "rocky8", "name": "Rocky Linux 8", @@ -59,6 +71,17 @@ "package_manager": "dnf", "grype_distro": "rockylinux:9", }, + { + "codename": "rocky10", + "name": "Rocky Linux 10", + "full_name": "Rocky Linux 10 — Red Quartz", + "os": "rocky", + "version": "10", + "badge": "RHEL-compat", + "color": "green", + "package_manager": "dnf", + "grype_distro": "rockylinux:10", + }, { "codename": "centos-stream9", "name": "CentOS Stream 9", @@ -70,6 +93,17 @@ "package_manager": "dnf", "grype_distro": "centos:9", }, + { + "codename": "centos-stream10", + "name": "CentOS Stream 10", + "full_name": "CentOS Stream 10", + "os": "centos", + "version": "10", + "badge": "Upstream RHEL", + "color": "purple", + "package_manager": "dnf", + "grype_distro": "centos:10", + }, { "codename": "oraclelinux8", "name": "Oracle Linux 8", @@ -81,17 +115,65 @@ "package_manager": "dnf", "grype_distro": "oraclelinux:8", }, + { + "codename": "oraclelinux9", + "name": "Oracle Linux 9", + "full_name": "Oracle Linux 9 — Red Tiger", + "os": "oraclelinux", + "version": "9", + "badge": "RHEL-compat", + "color": "red", + "package_manager": "dnf", + "grype_distro": "oraclelinux:9", + }, + { + "codename": "oraclelinux10", + "name": "Oracle Linux 10", + "full_name": "Oracle Linux 10", + "os": "oraclelinux", + "version": "10", + "badge": "RHEL-compat", + "color": "red", + "package_manager": "dnf", + "grype_distro": "oraclelinux:10", + }, # ── Fedora ──────────────────────────────────────────────────────────────── + # "fedora" (sans suffixe) désigne historiquement Fedora 42, désormais EOL. + # Les releases suivantes ont chacune leur codename versionné : partager un + # seul codename mélangerait leurs paquets et fausserait le --distro passé + # à Grype. { "codename": "fedora", - "name": "Fedora", - "full_name": "Fedora 42", + "name": "Fedora 42", + "full_name": "Fedora 42 (EOL)", "os": "fedora", "version": "42", + "badge": "EOL", + "color": "gray", + "package_manager": "dnf", + "grype_distro": "fedora:42", + }, + { + "codename": "fedora43", + "name": "Fedora 43", + "full_name": "Fedora 43", + "os": "fedora", + "version": "43", "badge": "Upstream", "color": "blue", "package_manager": "dnf", - "grype_distro": "fedora:42", + "grype_distro": "fedora:43", + }, + { + "codename": "fedora44", + "name": "Fedora 44", + "full_name": "Fedora 44", + "os": "fedora", + "version": "44", + "badge": "Upstream", + "color": "blue", + "package_manager": "dnf", + "grype_distro": "fedora:44", }, # ── openSUSE ────────────────────────────────────────────────────────────── { @@ -105,6 +187,17 @@ "package_manager": "zypper", "grype_distro": "opensuse/leap:15.6", }, + { + "codename": "opensuse-leap-16.0", + "name": "openSUSE Leap 16.0", + "full_name": "openSUSE Leap 16.0", + "os": "opensuse", + "version": "16.0", + "badge": "SUSE-stable", + "color": "teal", + "package_manager": "zypper", + "grype_distro": "opensuse/leap:16.0", + }, { "codename": "opensuse-tumbleweed", "name": "openSUSE Tumbleweed", @@ -130,26 +223,41 @@ "almalinux8-extras": "almalinux8", "almalinux9-baseos": "almalinux9", "almalinux9-appstream": "almalinux9", + "almalinux10-baseos": "almalinux10", + "almalinux10-appstream": "almalinux10", # Rocky Linux "rocky8-baseos": "rocky8", "rocky8-appstream": "rocky8", "rocky9-baseos": "rocky9", "rocky9-appstream": "rocky9", + "rocky10-baseos": "rocky10", + "rocky10-appstream": "rocky10", # CentOS Stream "centos-stream9-baseos": "centos-stream9", "centos-stream9-appstream": "centos-stream9", + "centos-stream10-baseos": "centos-stream10", + "centos-stream10-appstream": "centos-stream10", # Oracle Linux "oraclelinux8-baseos": "oraclelinux8", "oraclelinux8-appstream": "oraclelinux8", - "oraclelinux9-baseos": "oraclelinux8", # pas de distro oraclelinux9 encore + "oraclelinux9-baseos": "oraclelinux9", + "oraclelinux9-appstream": "oraclelinux9", + "oraclelinux10-baseos": "oraclelinux10", + "oraclelinux10-appstream": "oraclelinux10", # Fedora + EPEL "fedora42": "fedora", "fedora42-updates": "fedora", + "fedora43": "fedora43", + "fedora43-updates": "fedora43", + "fedora44": "fedora44", + "fedora44-updates": "fedora44", "epel8": "almalinux8", "epel9": "rocky9", + "epel10": "almalinux10", # openSUSE "opensuse-leap-15.6-oss": "opensuse-leap-15.6", "opensuse-leap-15.6-updates": "opensuse-leap-15.6", + "opensuse-leap-16.0-oss": "opensuse-leap-16.0", "opensuse-tumbleweed-oss": "opensuse-tumbleweed", } diff --git a/backend/services/package_index_apk.py b/backend/services/package_index_apk.py index 58a050f..e35b6ab 100644 --- a/backend/services/package_index_apk.py +++ b/backend/services/package_index_apk.py @@ -62,7 +62,70 @@ _ALPINE_CDN = "https://dl-cdn.alpinelinux.org/alpine" DEFAULT_SOURCES = [ - # ── Alpine 3.21 (LTS actuelle) ──────────────────────────────────────────── + # ── Alpine 3.24 (branche stable actuelle) ───────────────────────────────── + { + "id": "alpine3.24-main", + "label": "Alpine 3.24 — main", + "apkindex_url": f"{_ALPINE_CDN}/v3.24/main/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.24", + "arch": "x86_64", + "component": "main", + "format": "apk", + "security": False, + }, + { + "id": "alpine3.24-community", + "label": "Alpine 3.24 — community", + "apkindex_url": f"{_ALPINE_CDN}/v3.24/community/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.24", + "arch": "x86_64", + "component": "community", + "format": "apk", + "security": False, + }, + # ── Alpine 3.23 ─────────────────────────────────────────────────────────── + { + "id": "alpine3.23-main", + "label": "Alpine 3.23 — main", + "apkindex_url": f"{_ALPINE_CDN}/v3.23/main/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.23", + "arch": "x86_64", + "component": "main", + "format": "apk", + "security": False, + }, + { + "id": "alpine3.23-community", + "label": "Alpine 3.23 — community", + "apkindex_url": f"{_ALPINE_CDN}/v3.23/community/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.23", + "arch": "x86_64", + "component": "community", + "format": "apk", + "security": False, + }, + # ── Alpine 3.22 ─────────────────────────────────────────────────────────── + { + "id": "alpine3.22-main", + "label": "Alpine 3.22 — main", + "apkindex_url": f"{_ALPINE_CDN}/v3.22/main/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.22", + "arch": "x86_64", + "component": "main", + "format": "apk", + "security": False, + }, + { + "id": "alpine3.22-community", + "label": "Alpine 3.22 — community", + "apkindex_url": f"{_ALPINE_CDN}/v3.22/community/x86_64/APKINDEX.tar.gz", + "distro": "alpine3.22", + "arch": "x86_64", + "component": "community", + "format": "apk", + "security": False, + }, + # ── Alpine 3.21 ─────────────────────────────────────────────────────────── { "id": "alpine3.21-main", "label": "Alpine 3.21 — main", @@ -151,6 +214,42 @@ # signe aarch64 avec une clé RSA DIFFÉRENTE de x86_64 (confirmé en direct # sur les 8 sources : alpine-devel@...-616ae350.rsa.pub, pas -6165ee59) — # voir scripts/gen-apk-keys.sh, cette seconde clé y est déjà déclarée. + { + "id": "alpine3.24-main-aarch64", + "label": "Alpine 3.24 — main [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.24/main/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.24", "arch": "aarch64", "component": "main", "format": "apk", "security": False, + }, + { + "id": "alpine3.24-community-aarch64", + "label": "Alpine 3.24 — community [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.24/community/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.24", "arch": "aarch64", "component": "community", "format": "apk", "security": False, + }, + { + "id": "alpine3.23-main-aarch64", + "label": "Alpine 3.23 — main [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.23/main/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.23", "arch": "aarch64", "component": "main", "format": "apk", "security": False, + }, + { + "id": "alpine3.23-community-aarch64", + "label": "Alpine 3.23 — community [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.23/community/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.23", "arch": "aarch64", "component": "community", "format": "apk", "security": False, + }, + { + "id": "alpine3.22-main-aarch64", + "label": "Alpine 3.22 — main [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.22/main/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.22", "arch": "aarch64", "component": "main", "format": "apk", "security": False, + }, + { + "id": "alpine3.22-community-aarch64", + "label": "Alpine 3.22 — community [aarch64]", + "apkindex_url": f"{_ALPINE_CDN}/v3.22/community/aarch64/APKINDEX.tar.gz", + "distro": "alpine3.22", "arch": "aarch64", "component": "community", "format": "apk", "security": False, + }, { "id": "alpine3.21-main-aarch64", "label": "Alpine 3.21 — main [aarch64]", diff --git a/backend/services/package_index_apt.py b/backend/services/package_index_apt.py index 8d038bb..816da4c 100755 --- a/backend/services/package_index_apt.py +++ b/backend/services/package_index_apt.py @@ -126,6 +126,44 @@ "arch": "amd64", "security": True, }, + # ── Ubuntu 26.04 Resolute ──────────────────────────────────────────────── + # Publiée le 2026-04-23 (Release: "Suite: resolute / Version: 26.04", sans + # Valid-Until — contrairement à "stonking" 26.10 encore en développement, + # volontairement absente d'ici comme le sont les autres releases interim). + { + "id": "ubuntu-resolute", + "label": "Ubuntu 26.04 (Resolute) main", + "url": "https://archive.ubuntu.com/ubuntu/dists/resolute/main/binary-amd64/Packages.gz", + "distro": "resolute", + "component": "main", + "arch": "amd64", + }, + { + "id": "ubuntu-resolute-universe", + "label": "Ubuntu 26.04 (Resolute) universe", + "url": "https://archive.ubuntu.com/ubuntu/dists/resolute/universe/binary-amd64/Packages.gz", + "distro": "resolute", + "component": "universe", + "arch": "amd64", + }, + { + "id": "ubuntu-resolute-updates", + "label": "Ubuntu 26.04 Updates (main)", + "url": "https://archive.ubuntu.com/ubuntu/dists/resolute-updates/main/binary-amd64/Packages.gz", + "distro": "resolute-updates", + "component": "main", + "arch": "amd64", + "security": True, + }, + { + "id": "ubuntu-resolute-updates-universe", + "label": "Ubuntu 26.04 Updates (universe)", + "url": "https://archive.ubuntu.com/ubuntu/dists/resolute-updates/universe/binary-amd64/Packages.gz", + "distro": "resolute-updates", + "component": "universe", + "arch": "amd64", + "security": True, + }, # ── Debian 12 Bookworm ─────────────────────────────────────────────────── { "id": "debian-bookworm", @@ -151,6 +189,52 @@ "component": "non-free", "arch": "amd64", }, + { + # Composant introduit par Debian 12 (firmware non libre sorti de + # non-free pour être installable par défaut) — il manquait ici. + "id": "debian-bookworm-non-free-firmware", + "label": "Debian 12 (Bookworm) non-free-firmware", + "url": "https://deb.debian.org/debian/dists/bookworm/non-free-firmware/binary-amd64/Packages.gz", + "distro": "bookworm", + "component": "non-free-firmware", + "arch": "amd64", + }, + # ── Debian 13 Trixie ───────────────────────────────────────────────────── + # Stable depuis le 2025-08-09 (Release courante : "Debian 13.6", Suite: + # stable). Composants annoncés par le Release : main contrib + # non-free-firmware non-free. + { + "id": "debian-trixie", + "label": "Debian 13 (Trixie) main", + "url": "https://deb.debian.org/debian/dists/trixie/main/binary-amd64/Packages.gz", + "distro": "trixie", + "component": "main", + "arch": "amd64", + }, + { + "id": "debian-trixie-contrib", + "label": "Debian 13 (Trixie) contrib", + "url": "https://deb.debian.org/debian/dists/trixie/contrib/binary-amd64/Packages.gz", + "distro": "trixie", + "component": "contrib", + "arch": "amd64", + }, + { + "id": "debian-trixie-non-free", + "label": "Debian 13 (Trixie) non-free", + "url": "https://deb.debian.org/debian/dists/trixie/non-free/binary-amd64/Packages.gz", + "distro": "trixie", + "component": "non-free", + "arch": "amd64", + }, + { + "id": "debian-trixie-non-free-firmware", + "label": "Debian 13 (Trixie) non-free-firmware", + "url": "https://deb.debian.org/debian/dists/trixie/non-free-firmware/binary-amd64/Packages.gz", + "distro": "trixie", + "component": "non-free-firmware", + "arch": "amd64", + }, # ── Sources de sécurité ────────────────────────────────────────────────── { "id": "ubuntu-jammy-security", @@ -206,6 +290,24 @@ "arch": "amd64", "security": True, }, + { + "id": "ubuntu-resolute-security", + "label": "Ubuntu 26.04 Security", + "url": "https://security.ubuntu.com/ubuntu/dists/resolute-security/main/binary-amd64/Packages.gz", + "distro": "resolute", + "component": "main", + "arch": "amd64", + "security": True, + }, + { + "id": "ubuntu-resolute-security-universe", + "label": "Ubuntu 26.04 Security (universe)", + "url": "https://security.ubuntu.com/ubuntu/dists/resolute-security/universe/binary-amd64/Packages.gz", + "distro": "resolute", + "component": "universe", + "arch": "amd64", + "security": True, + }, { "id": "debian-bookworm-security", "label": "Debian 12 Security", @@ -224,6 +326,24 @@ "arch": "amd64", "security": True, }, + { + "id": "debian-trixie-security", + "label": "Debian 13 Security", + "url": "https://security.debian.org/debian-security/dists/trixie-security/main/binary-amd64/Packages.xz", + "distro": "trixie", + "component": "main", + "arch": "amd64", + "security": True, + }, + { + "id": "debian-trixie-updates", + "label": "Debian 13 Updates", + "url": "https://deb.debian.org/debian/dists/trixie-updates/main/binary-amd64/Packages.xz", + "distro": "trixie-updates", + "component": "main", + "arch": "amd64", + "security": True, + }, # ── arm64 ──────────────────────────────────────────────────────────────── # Ubuntu arm64 n'est PAS servi par archive.ubuntu.com/security.ubuntu.com # (confirmé en direct : 404 sur les trois) — c'est un mirroir séparé, @@ -334,6 +454,40 @@ "arch": "arm64", "security": True, }, + { + "id": "ubuntu-resolute-arm64", + "label": "Ubuntu 26.04 (Resolute) main [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute/main/binary-arm64/Packages.gz", + "distro": "resolute", + "component": "main", + "arch": "arm64", + }, + { + "id": "ubuntu-resolute-universe-arm64", + "label": "Ubuntu 26.04 (Resolute) universe [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute/universe/binary-arm64/Packages.gz", + "distro": "resolute", + "component": "universe", + "arch": "arm64", + }, + { + "id": "ubuntu-resolute-updates-arm64", + "label": "Ubuntu 26.04 Updates (main) [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute-updates/main/binary-arm64/Packages.gz", + "distro": "resolute-updates", + "component": "main", + "arch": "arm64", + "security": True, + }, + { + "id": "ubuntu-resolute-updates-universe-arm64", + "label": "Ubuntu 26.04 Updates (universe) [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute-updates/universe/binary-arm64/Packages.gz", + "distro": "resolute-updates", + "component": "universe", + "arch": "arm64", + "security": True, + }, { "id": "debian-bookworm-arm64", "label": "Debian 12 (Bookworm) main [arm64]", @@ -358,6 +512,46 @@ "component": "non-free", "arch": "arm64", }, + { + "id": "debian-bookworm-non-free-firmware-arm64", + "label": "Debian 12 (Bookworm) non-free-firmware [arm64]", + "url": "https://deb.debian.org/debian/dists/bookworm/non-free-firmware/binary-arm64/Packages.gz", + "distro": "bookworm", + "component": "non-free-firmware", + "arch": "arm64", + }, + { + "id": "debian-trixie-arm64", + "label": "Debian 13 (Trixie) main [arm64]", + "url": "https://deb.debian.org/debian/dists/trixie/main/binary-arm64/Packages.gz", + "distro": "trixie", + "component": "main", + "arch": "arm64", + }, + { + "id": "debian-trixie-contrib-arm64", + "label": "Debian 13 (Trixie) contrib [arm64]", + "url": "https://deb.debian.org/debian/dists/trixie/contrib/binary-arm64/Packages.gz", + "distro": "trixie", + "component": "contrib", + "arch": "arm64", + }, + { + "id": "debian-trixie-non-free-arm64", + "label": "Debian 13 (Trixie) non-free [arm64]", + "url": "https://deb.debian.org/debian/dists/trixie/non-free/binary-arm64/Packages.gz", + "distro": "trixie", + "component": "non-free", + "arch": "arm64", + }, + { + "id": "debian-trixie-non-free-firmware-arm64", + "label": "Debian 13 (Trixie) non-free-firmware [arm64]", + "url": "https://deb.debian.org/debian/dists/trixie/non-free-firmware/binary-arm64/Packages.gz", + "distro": "trixie", + "component": "non-free-firmware", + "arch": "arm64", + }, { "id": "ubuntu-jammy-security-arm64", "label": "Ubuntu 22.04 Security [arm64]", @@ -412,6 +606,24 @@ "arch": "arm64", "security": True, }, + { + "id": "ubuntu-resolute-security-arm64", + "label": "Ubuntu 26.04 Security [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute-security/main/binary-arm64/Packages.gz", + "distro": "resolute", + "component": "main", + "arch": "arm64", + "security": True, + }, + { + "id": "ubuntu-resolute-security-universe-arm64", + "label": "Ubuntu 26.04 Security (universe) [arm64]", + "url": "https://ports.ubuntu.com/ubuntu-ports/dists/resolute-security/universe/binary-arm64/Packages.gz", + "distro": "resolute", + "component": "universe", + "arch": "arm64", + "security": True, + }, { "id": "debian-bookworm-security-arm64", "label": "Debian 12 Security [arm64]", @@ -430,6 +642,24 @@ "arch": "arm64", "security": True, }, + { + "id": "debian-trixie-security-arm64", + "label": "Debian 13 Security [arm64]", + "url": "https://security.debian.org/debian-security/dists/trixie-security/main/binary-arm64/Packages.xz", + "distro": "trixie", + "component": "main", + "arch": "arm64", + "security": True, + }, + { + "id": "debian-trixie-updates-arm64", + "label": "Debian 13 Updates [arm64]", + "url": "https://deb.debian.org/debian/dists/trixie-updates/main/binary-arm64/Packages.xz", + "distro": "trixie-updates", + "component": "main", + "arch": "arm64", + "security": True, + }, ] diff --git a/backend/services/package_index_rpm.py b/backend/services/package_index_rpm.py index 9323c3a..d987613 100644 --- a/backend/services/package_index_rpm.py +++ b/backend/services/package_index_rpm.py @@ -242,6 +242,28 @@ "security": False, "format": "rpm", }, + # ── CentOS Stream 10 ─────────────────────────────────────────────────────── + # Même remarque que Stream 9 : rolling release, pas d'updateinfo.xml.gz. + { + "id": "centos-stream10-baseos", + "label": "CentOS Stream 10 — BaseOS", + "repomd_url": "https://mirror.stream.centos.org/10-stream/BaseOS/x86_64/os/repodata/repomd.xml", + "distro": "centos-stream10", + "arch": "x86_64", + "component": "baseos", + "security": False, + "format": "rpm", + }, + { + "id": "centos-stream10-appstream", + "label": "CentOS Stream 10 — AppStream", + "repomd_url": "https://mirror.stream.centos.org/10-stream/AppStream/x86_64/os/repodata/repomd.xml", + "distro": "centos-stream10", + "arch": "x86_64", + "component": "appstream", + "security": False, + "format": "rpm", + }, # ── Oracle Linux 8 ───────────────────────────────────────────────────────── { "id": "oraclelinux8-baseos", @@ -284,6 +306,28 @@ "security": True, "format": "rpm", }, + # ── Oracle Linux 10 ──────────────────────────────────────────────────────── + # Même quirk que OL8/OL9 : /latest/ présent sur baseos, absent sur appstream. + { + "id": "oraclelinux10-baseos", + "label": "Oracle Linux 10 — BaseOS", + "repomd_url": "https://yum.oracle.com/repo/OracleLinux/OL10/baseos/latest/x86_64/repodata/repomd.xml", + "distro": "oraclelinux10", + "arch": "x86_64", + "component": "baseos", + "security": True, + "format": "rpm", + }, + { + "id": "oraclelinux10-appstream", + "label": "Oracle Linux 10 — AppStream", + "repomd_url": "https://yum.oracle.com/repo/OracleLinux/OL10/appstream/x86_64/repodata/repomd.xml", + "distro": "oraclelinux10", + "arch": "x86_64", + "component": "appstream", + "security": True, + "format": "rpm", + }, # ── Fedora 42 ────────────────────────────────────────────────────────────── # Fedora 42 est EOL (cycle de support Fedora ~13 mois ; superseded par 43/44). # dl.fedoraproject.org ne sert plus que les versions activement maintenues — @@ -314,6 +358,54 @@ "security": True, "format": "rpm", }, + # ── Fedora 43 / 44 ───────────────────────────────────────────────────────── + # Les deux releases actuellement maintenues (Fedora supporte N et N-1). + # Contrairement à Fedora 42 ci-dessus, elles sont encore servies par + # dl.fedoraproject.org — elles devront migrer vers + # archives.fedoraproject.org à leur EOL, comme 42 l'a fait. + # Chaque release a son propre codename "distro" : partager "fedora" + # mélangerait les paquets de 42/43/44 dans un même inventaire et + # fausserait le rapprochement CVE (grype --distro fedora:NN). + { + "id": "fedora43", + "label": "Fedora 43 — Everything", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/releases/43/Everything/x86_64/os/repodata/repomd.xml", + "distro": "fedora43", + "arch": "x86_64", + "component": "everything", + "security": False, + "format": "rpm", + }, + { + "id": "fedora43-updates", + "label": "Fedora 43 — Updates", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/updates/43/Everything/x86_64/repodata/repomd.xml", + "distro": "fedora43", + "arch": "x86_64", + "component": "updates", + "security": True, + "format": "rpm", + }, + { + "id": "fedora44", + "label": "Fedora 44 — Everything", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/releases/44/Everything/x86_64/os/repodata/repomd.xml", + "distro": "fedora44", + "arch": "x86_64", + "component": "everything", + "security": False, + "format": "rpm", + }, + { + "id": "fedora44-updates", + "label": "Fedora 44 — Updates", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/updates/44/Everything/x86_64/repodata/repomd.xml", + "distro": "fedora44", + "arch": "x86_64", + "component": "updates", + "security": True, + "format": "rpm", + }, # ── EPEL (Extra Packages for Enterprise Linux) ───────────────────────────── { "id": "epel8", @@ -335,6 +427,18 @@ "security": False, "format": "rpm", }, + { + # EPEL 10 est publié sous /epel/10/ (pas de sous-répertoire 10.0/10.1 — + # confirmé en direct : 404 sur les deux). + "id": "epel10", + "label": "EPEL 10 — Extra Packages", + "repomd_url": "https://dl.fedoraproject.org/pub/epel/10/Everything/x86_64/repodata/repomd.xml", + "distro": "almalinux10", + "arch": "x86_64", + "component": "epel", + "security": False, + "format": "rpm", + }, # ── openSUSE Leap 15.6 ───────────────────────────────────────────────────── { "id": "opensuse-leap-15.6-oss", @@ -356,6 +460,30 @@ "security": True, "format": "rpm", }, + # ── openSUSE Leap 16.0 ───────────────────────────────────────────────────── + # Leap est passé de 15.6 directement à 16.0 : il n'existe AUCUN 15.7 sur + # download.opensuse.org (confirmé en direct — le listing de + # /distribution/leap/ enchaîne 15.6 puis 16.0/16.1). + # Deux différences structurelles avec la série 15.x, d'où l'entrée unique + # ci-dessous là où 15.6 en a quatre : + # - le dépôt est multi-architecture (aarch64, ppc64le, s390x, x86_64 + # sous un même repomd) : /ports/aarch64/ s'arrête à 15.6, il n'y a donc + # pas d'entrée aarch64 séparée — l'arch réelle de chaque paquet vient + # de primary.xml, pas du champ "arch" de la source. + # - aucun dépôt d'updates publié : /update/leap/16.0/ renvoie 404, les + # correctifs Leap 16 ne transitent plus par ce chemin. + # 16.1 est volontairement absente : encore en développement à ce jour + # (Build41.1 face au Build178.139 de 16.0). + { + "id": "opensuse-leap-16.0-oss", + "label": "openSUSE Leap 16.0 — OSS", + "repomd_url": "https://download.opensuse.org/distribution/leap/16.0/repo/oss/repodata/repomd.xml", + "distro": "opensuse-leap-16.0", + "arch": "x86_64", + "component": "oss", + "security": False, + "format": "rpm", + }, # ── openSUSE Tumbleweed ───────────────────────────────────────────────────── { "id": "opensuse-tumbleweed-oss", @@ -480,6 +608,18 @@ "repomd_url": "https://mirror.stream.centos.org/9-stream/AppStream/aarch64/os/repodata/repomd.xml", "distro": "centos-stream9", "arch": "aarch64", "component": "appstream", "security": False, "format": "rpm", }, + { + "id": "centos-stream10-baseos-aarch64", + "label": "CentOS Stream 10 — BaseOS [aarch64]", + "repomd_url": "https://mirror.stream.centos.org/10-stream/BaseOS/aarch64/os/repodata/repomd.xml", + "distro": "centos-stream10", "arch": "aarch64", "component": "baseos", "security": False, "format": "rpm", + }, + { + "id": "centos-stream10-appstream-aarch64", + "label": "CentOS Stream 10 — AppStream [aarch64]", + "repomd_url": "https://mirror.stream.centos.org/10-stream/AppStream/aarch64/os/repodata/repomd.xml", + "distro": "centos-stream10", "arch": "aarch64", "component": "appstream", "security": False, "format": "rpm", + }, # Oracle Linux : "baseos" garde le segment /latest/ sur aarch64, mais # "appstream" ne l'a PAS (confirmé en direct : 404 avec /latest/, 200 sans) # — quirk propre au mirroir Oracle, pas une incohérence à corriger. @@ -507,6 +647,18 @@ "repomd_url": "https://yum.oracle.com/repo/OracleLinux/OL9/appstream/aarch64/repodata/repomd.xml", "distro": "oraclelinux9", "arch": "aarch64", "component": "appstream", "security": True, "format": "rpm", }, + { + "id": "oraclelinux10-baseos-aarch64", + "label": "Oracle Linux 10 — BaseOS [aarch64]", + "repomd_url": "https://yum.oracle.com/repo/OracleLinux/OL10/baseos/latest/aarch64/repodata/repomd.xml", + "distro": "oraclelinux10", "arch": "aarch64", "component": "baseos", "security": True, "format": "rpm", + }, + { + "id": "oraclelinux10-appstream-aarch64", + "label": "Oracle Linux 10 — AppStream [aarch64]", + "repomd_url": "https://yum.oracle.com/repo/OracleLinux/OL10/appstream/aarch64/repodata/repomd.xml", + "distro": "oraclelinux10", "arch": "aarch64", "component": "appstream", "security": True, "format": "rpm", + }, { "id": "fedora42-aarch64", "label": "Fedora 42 — Everything [aarch64]", @@ -519,6 +671,30 @@ "repomd_url": "https://archives.fedoraproject.org/pub/archive/fedora/linux/updates/42/Everything/aarch64/repodata/repomd.xml", "distro": "fedora", "arch": "aarch64", "component": "updates", "security": True, "format": "rpm", }, + { + "id": "fedora43-aarch64", + "label": "Fedora 43 — Everything [aarch64]", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/releases/43/Everything/aarch64/os/repodata/repomd.xml", + "distro": "fedora43", "arch": "aarch64", "component": "everything", "security": False, "format": "rpm", + }, + { + "id": "fedora43-updates-aarch64", + "label": "Fedora 43 — Updates [aarch64]", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/updates/43/Everything/aarch64/repodata/repomd.xml", + "distro": "fedora43", "arch": "aarch64", "component": "updates", "security": True, "format": "rpm", + }, + { + "id": "fedora44-aarch64", + "label": "Fedora 44 — Everything [aarch64]", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/releases/44/Everything/aarch64/os/repodata/repomd.xml", + "distro": "fedora44", "arch": "aarch64", "component": "everything", "security": False, "format": "rpm", + }, + { + "id": "fedora44-updates-aarch64", + "label": "Fedora 44 — Updates [aarch64]", + "repomd_url": "https://dl.fedoraproject.org/pub/fedora/linux/updates/44/Everything/aarch64/repodata/repomd.xml", + "distro": "fedora44", "arch": "aarch64", "component": "updates", "security": True, "format": "rpm", + }, { "id": "epel8-aarch64", "label": "EPEL 8 — Extra Packages [aarch64]", @@ -531,6 +707,12 @@ "repomd_url": "https://dl.fedoraproject.org/pub/epel/9/Everything/aarch64/repodata/repomd.xml", "distro": "rocky9", "arch": "aarch64", "component": "epel", "security": False, "format": "rpm", }, + { + "id": "epel10-aarch64", + "label": "EPEL 10 — Extra Packages [aarch64]", + "repomd_url": "https://dl.fedoraproject.org/pub/epel/10/Everything/aarch64/repodata/repomd.xml", + "distro": "almalinux10", "arch": "aarch64", "component": "epel", "security": False, "format": "rpm", + }, # openSUSE aarch64 est servi sous un préfixe /ports/aarch64/ dédié # (confirmé en direct), pas un simple swap x86_64->aarch64 dans l'URL. { diff --git a/backend/services/settings.py b/backend/services/settings.py index 5d24fa6..a54ad48 100644 --- a/backend/services/settings.py +++ b/backend/services/settings.py @@ -62,17 +62,32 @@ # Ubuntu 20.04 Focal "ubuntu-focal": True, "ubuntu-focal-universe": True, + # Ubuntu 26.04 Resolute + "ubuntu-resolute": True, + "ubuntu-resolute-universe": True, + "ubuntu-resolute-updates": True, + "ubuntu-resolute-updates-universe": True, # Debian 12 Bookworm "debian-bookworm": True, "debian-bookworm-contrib": True, "debian-bookworm-non-free": False, # désactivé par défaut (non-free) + "debian-bookworm-non-free-firmware": False, # idem : firmware non libre + # Debian 13 Trixie + "debian-trixie": True, + "debian-trixie-contrib": True, + "debian-trixie-non-free": False, # désactivé par défaut (non-free) + "debian-trixie-non-free-firmware": False, # idem : firmware non libre + "debian-trixie-updates": True, # Sources de sécurité "ubuntu-jammy-security": True, "ubuntu-jammy-security-universe": True, "ubuntu-noble-security": True, "ubuntu-noble-security-universe": True, "ubuntu-focal-security": True, + "ubuntu-resolute-security": True, + "ubuntu-resolute-security-universe": True, "debian-bookworm-security": True, + "debian-trixie-security": True, } _RPM_SOURCES: dict = { @@ -82,32 +97,56 @@ "almalinux8-extras": True, "almalinux9-baseos": True, "almalinux9-appstream": True, + "almalinux10-baseos": True, + "almalinux10-appstream": True, # ── Rocky Linux ──────────────────────────────────────────────────────────── "rocky8-baseos": True, "rocky8-appstream": True, "rocky9-baseos": True, "rocky9-appstream": True, + "rocky10-baseos": True, + "rocky10-appstream": True, # ── CentOS Stream ────────────────────────────────────────────────────────── "centos-stream9-baseos": True, "centos-stream9-appstream": True, + "centos-stream10-baseos": True, + "centos-stream10-appstream": True, # ── Oracle Linux ─────────────────────────────────────────────────────────── "oraclelinux8-baseos": True, "oraclelinux8-appstream": True, "oraclelinux9-baseos": True, - # ── Fedora ───────────────────────────────────────────────────────────────── + "oraclelinux9-appstream": True, + "oraclelinux10-baseos": True, + "oraclelinux10-appstream": True, + # ── Fedora (42 est EOL — laissée activée pour ne pas perdre l'existant) ──── "fedora42": True, "fedora42-updates": True, + "fedora43": True, + "fedora43-updates": True, + "fedora44": True, + "fedora44-updates": True, # ── EPEL (désactivé par défaut — volumineuse) ────────────────────────────── "epel8": False, "epel9": False, + "epel10": False, # ── openSUSE ─────────────────────────────────────────────────────────────── "opensuse-leap-15.6-oss": True, "opensuse-leap-15.6-updates": True, + "opensuse-leap-16.0-oss": True, "opensuse-tumbleweed-oss": True, } _APK_SOURCES: dict = { + # ── Alpine 3.24 ──────────────────────────────────────────────────────────── + "alpine3.24-main": True, + "alpine3.24-community": True, + # ── Alpine 3.23 ──────────────────────────────────────────────────────────── + "alpine3.23-main": True, + "alpine3.23-community": True, + # ── Alpine 3.22 ──────────────────────────────────────────────────────────── + "alpine3.22-main": True, + "alpine3.22-community": True, # ── Alpine 3.21 ──────────────────────────────────────────────────────────── "alpine3.21-main": True, "alpine3.21-community": True, diff --git a/backend/services/validator_apk.py b/backend/services/validator_apk.py index 4def713..684d2b8 100644 --- a/backend/services/validator_apk.py +++ b/backend/services/validator_apk.py @@ -44,7 +44,11 @@ "alpine3.19": "alpine:3.19", "alpine3.20": "alpine:3.20", "alpine3.21": "alpine:3.21", - "alpine": "alpine:3.21", + "alpine3.22": "alpine:3.22", + "alpine3.23": "alpine:3.23", + "alpine3.24": "alpine:3.24", + # Repli quand aucune version n'est précisée : la branche stable courante. + "alpine": "alpine:3.24", } # ── Étape 1 : Format ────────────────────────────────────────────────────────── diff --git a/backend/services/validator_apt.py b/backend/services/validator_apt.py index bd89a73..c71222f 100755 --- a/backend/services/validator_apt.py +++ b/backend/services/validator_apt.py @@ -35,9 +35,11 @@ def _extract_cvss(vuln: dict) -> float | None: "focal": "ubuntu:20.04", "jammy": "ubuntu:22.04", "noble": "ubuntu:24.04", + "resolute": "ubuntu:26.04", "buster": "debian:10", "bullseye": "debian:11", "bookworm": "debian:12", + "trixie": "debian:13", } diff --git a/backend/services/validator_rpm.py b/backend/services/validator_rpm.py index 2cda562..ca7692a 100644 --- a/backend/services/validator_rpm.py +++ b/backend/services/validator_rpm.py @@ -33,12 +33,22 @@ # Correspondance codename RPM → chaîne distro Grype _DISTRO_MAP: dict[str, str] = { "almalinux8": "almalinux:8", + "almalinux9": "almalinux:9", + "almalinux10": "almalinux:10", "rocky8": "rockylinux:8", + "rocky9": "rockylinux:9", + "rocky10": "rockylinux:10", "centos-stream9": "centos:9", + "centos-stream10": "centos:10", "oraclelinux8": "oraclelinux:8", - "fedora": "fedora:latest", + "oraclelinux9": "oraclelinux:9", + "oraclelinux10": "oraclelinux:10", + "fedora": "fedora:42", + "fedora43": "fedora:43", + "fedora44": "fedora:44", "opensuse-leap-15.5": "opensuse/leap:15.5", "opensuse-leap-15.6": "opensuse/leap:15.6", + "opensuse-leap-16.0": "opensuse/leap:16.0", "opensuse-leap": "opensuse/leap:latest", "opensuse-tumbleweed": "opensuse/tumbleweed:latest", } diff --git a/backend/tests/test_arch_disambiguation.py b/backend/tests/test_arch_disambiguation.py index aca27ac..839287c 100644 --- a/backend/tests/test_arch_disambiguation.py +++ b/backend/tests/test_arch_disambiguation.py @@ -203,37 +203,51 @@ class TestDistributionsConfSelfHeal: répare tout seul au prochain redémarrage plutôt que de rester bloqué en amd64-only indéfiniment.""" + @staticmethod + def _write_conf(conf_dir, architectures: str) -> None: + """ + Écrit un conf/distributions listant TOUTES les distributions APT + connues, avec la ligne Architectures fournie. + + Le contenu est dérivé de _DIST_META plutôt que codé en dur : ces deux + tests portent sur la ligne Architectures, pas sur la liste des + distributions — les figer ici ferait échouer le test "complet" à + chaque ajout d'une distro (trixie, resolute…) alors que le code se + comporte correctement. + """ + from routers.distributions_router import _DIST_META + + blocks = [ + f"Origin: Repod\nLabel: {meta['label']}\nCodename: {codename}\n" + f"Architectures: {architectures}\nComponents: main\n" + for codename, meta in _DIST_META.items() + if meta.get("pkg_type") != "apk" + ] + (conf_dir / "distributions").write_text("\n".join(blocks)) + def test_amd64_only_conf_is_incomplete(self, tmp_path): from routers.distributions_router import _distributions_conf_is_complete - conf_dir = tmp_path - (conf_dir / "distributions").write_text( - "Origin: Repod\nLabel: Ubuntu 22.04 LTS\nCodename: jammy\n" - "Architectures: amd64\nComponents: main\n\n" - "Origin: Repod\nLabel: Ubuntu 24.04 LTS\nCodename: noble\n" - "Architectures: amd64\nComponents: main\n\n" - "Origin: Repod\nLabel: Ubuntu 20.04 LTS\nCodename: focal\n" - "Architectures: amd64\nComponents: main\n\n" - "Origin: Repod\nLabel: Debian 12\nCodename: bookworm\n" - "Architectures: amd64\nComponents: main\n" - ) - assert _distributions_conf_is_complete(conf_dir) is False + self._write_conf(tmp_path, "amd64") + assert _distributions_conf_is_complete(tmp_path) is False def test_amd64_and_arm64_conf_is_complete(self, tmp_path): from routers.distributions_router import _distributions_conf_is_complete - conf_dir = tmp_path - (conf_dir / "distributions").write_text( + self._write_conf(tmp_path, "amd64 arm64") + assert _distributions_conf_is_complete(tmp_path) is True + + def test_missing_distribution_is_incomplete(self, tmp_path): + """Une distro APT connue absente du fichier doit déclencher la + régénération — c'est ce qui fait apparaître trixie/resolute sur un + déploiement initialisé avant leur ajout.""" + from routers.distributions_router import _distributions_conf_is_complete + + (tmp_path / "distributions").write_text( "Origin: Repod\nLabel: Ubuntu 22.04 LTS\nCodename: jammy\n" - "Architectures: amd64 arm64\nComponents: main\n\n" - "Origin: Repod\nLabel: Ubuntu 24.04 LTS\nCodename: noble\n" - "Architectures: amd64 arm64\nComponents: main\n\n" - "Origin: Repod\nLabel: Ubuntu 20.04 LTS\nCodename: focal\n" - "Architectures: amd64 arm64\nComponents: main\n\n" - "Origin: Repod\nLabel: Debian 12\nCodename: bookworm\n" "Architectures: amd64 arm64\nComponents: main\n" ) - assert _distributions_conf_is_complete(conf_dir) is True + assert _distributions_conf_is_complete(tmp_path) is False def test_missing_file_is_incomplete(self, tmp_path): from routers.distributions_router import _distributions_conf_is_complete diff --git a/frontend/package-lock.json b/frontend/package-lock.json index a2e7576..9386b7d 100755 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -1,15 +1,15 @@ { "name": "apt-repo-manager", - "version": "2.0.0", + "version": "1.0.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "apt-repo-manager", - "version": "2.0.0", + "version": "1.0.0", "license": "AGPL-3.0-only", "dependencies": { - "axios": "^1.3.4", + "axios": "^1.7.9", "react": "^18.2.0", "react-dom": "^18.2.0", "react-dropzone": "^14.2.3", diff --git a/frontend/src/components/PackageList.js b/frontend/src/components/PackageList.js index 467069c..5227fb4 100755 --- a/frontend/src/components/PackageList.js +++ b/frontend/src/components/PackageList.js @@ -685,27 +685,41 @@ const DISTRIB_COLORS = { jammy: "bg-orange-100 text-orange-700", noble: "bg-green-100 text-green-700", focal: "bg-gray-100 text-gray-600", + resolute: "bg-purple-100 text-purple-700", + trixie: "bg-red-100 text-red-700", bookworm: "bg-red-100 text-red-700", bullseye: "bg-red-100 text-red-600", buster: "bg-red-50 text-red-500", // RPM — AlmaLinux almalinux8: "bg-blue-100 text-blue-700", almalinux9: "bg-blue-100 text-blue-700", + almalinux10: "bg-blue-100 text-blue-700", // RPM — Rocky Linux rocky8: "bg-emerald-100 text-emerald-700", rocky9: "bg-emerald-100 text-emerald-700", + rocky10: "bg-emerald-100 text-emerald-700", // RPM — CentOS Stream "centos-stream9": "bg-purple-100 text-purple-700", + "centos-stream10": "bg-purple-100 text-purple-700", "centos-stream8": "bg-purple-100 text-purple-600", // RPM — Oracle Linux oraclelinux8: "bg-red-100 text-red-800", oraclelinux9: "bg-red-100 text-red-800", + oraclelinux10: "bg-red-100 text-red-800", // RPM — Fedora fedora: "bg-indigo-100 text-indigo-700", fedora42: "bg-indigo-100 text-indigo-700", + fedora43: "bg-indigo-100 text-indigo-700", + fedora44: "bg-indigo-100 text-indigo-700", // RPM — openSUSE "opensuse-leap-15.6": "bg-teal-100 text-teal-700", + "opensuse-leap-16.0": "bg-teal-100 text-teal-700", "opensuse-tumbleweed": "bg-teal-100 text-teal-600", + // APK — Alpine + "alpine3.21": "bg-sky-100 text-sky-700", + "alpine3.22": "bg-sky-100 text-sky-700", + "alpine3.23": "bg-sky-100 text-sky-700", + "alpine3.24": "bg-sky-100 text-sky-700", }; // Fallback statique si l'API distributions n'est pas disponible @@ -715,16 +729,24 @@ const DISTRIB_TABS_FALLBACK = [ { id: "jammy", label: "Jammy 22.04", group: "apt" }, { id: "noble", label: "Noble 24.04", group: "apt" }, { id: "focal", label: "Focal 20.04", group: "apt" }, + { id: "resolute", label: "Resolute 26.04", group: "apt" }, + { id: "trixie", label: "Trixie 13", group: "apt" }, { id: "bookworm", label: "Bookworm 12", group: "apt" }, // RPM — RHEL family + { id: "almalinux10", label: "AlmaLinux 10", group: "rpm" }, { id: "almalinux9", label: "AlmaLinux 9", group: "rpm" }, { id: "almalinux8", label: "AlmaLinux 8", group: "rpm" }, + { id: "rocky10", label: "Rocky 10", group: "rpm" }, { id: "rocky9", label: "Rocky 9", group: "rpm" }, { id: "rocky8", label: "Rocky 8", group: "rpm" }, + { id: "centos-stream10", label: "CentOS Stream 10", group: "rpm" }, { id: "centos-stream9", label: "CentOS Stream 9", group: "rpm" }, + { id: "oraclelinux10", label: "Oracle Linux 10", group: "rpm" }, { id: "oraclelinux9", label: "Oracle Linux 9", group: "rpm" }, - { id: "fedora42", label: "Fedora 42", group: "rpm" }, + { id: "fedora44", label: "Fedora 44", group: "rpm" }, + { id: "fedora43", label: "Fedora 43", group: "rpm" }, // RPM — openSUSE + { id: "opensuse-leap-16.0", label: "Leap 16.0", group: "zypper" }, { id: "opensuse-leap-15.6", label: "Leap 15.6", group: "zypper" }, { id: "opensuse-tumbleweed", label: "Tumbleweed", group: "zypper" }, ]; diff --git a/frontend/src/components/UploadForm.js b/frontend/src/components/UploadForm.js index 33d3255..d91ff5b 100755 --- a/frontend/src/components/UploadForm.js +++ b/frontend/src/components/UploadForm.js @@ -239,6 +239,8 @@ export default function UploadForm() { { codename: "jammy", name: "Ubuntu 22.04 LTS (Jammy)", format: "deb" }, { codename: "noble", name: "Ubuntu 24.04 LTS (Noble)", format: "deb" }, { codename: "focal", name: "Ubuntu 20.04 LTS (Focal)", format: "deb" }, + { codename: "resolute", name: "Ubuntu 26.04 LTS (Resolute)", format: "deb" }, + { codename: "trixie", name: "Debian 13 (Trixie)", format: "deb" }, { codename: "bookworm", name: "Debian 12 (Bookworm)", format: "deb" }, ]); }); diff --git a/frontend/src/pages/ClientSetupPage.js b/frontend/src/pages/ClientSetupPage.js index 11c2c87..a393bff 100755 --- a/frontend/src/pages/ClientSetupPage.js +++ b/frontend/src/pages/ClientSetupPage.js @@ -841,21 +841,33 @@ const DISTROS = [ // APT (Debian/Ubuntu) { id: "jammy", label: "Ubuntu 22.04 (Jammy)", family: "apt" }, { id: "noble", label: "Ubuntu 24.04 (Noble)", family: "apt" }, + { id: "resolute", label: "Ubuntu 26.04 (Resolute)", family: "apt" }, + { id: "trixie", label: "Debian 13 (Trixie)", family: "apt" }, { id: "bookworm", label: "Debian 12 (Bookworm)", family: "apt" }, { id: "bullseye", label: "Debian 11 (Bullseye)", family: "apt" }, // RPM — DNF (RHEL family) + { id: "almalinux10", label: "AlmaLinux 10", family: "dnf" }, { id: "almalinux9", label: "AlmaLinux 9", family: "dnf" }, { id: "almalinux8", label: "AlmaLinux 8", family: "dnf" }, + { id: "rocky10", label: "Rocky Linux 10", family: "dnf" }, { id: "rocky9", label: "Rocky Linux 9", family: "dnf" }, { id: "rocky8", label: "Rocky Linux 8", family: "dnf" }, + { id: "centos-stream10", label: "CentOS Stream 10", family: "dnf" }, { id: "centos-stream9", label: "CentOS Stream 9", family: "dnf" }, + { id: "oraclelinux10", label: "Oracle Linux 10", family: "dnf" }, { id: "oraclelinux9", label: "Oracle Linux 9", family: "dnf" }, { id: "oraclelinux8", label: "Oracle Linux 8", family: "dnf" }, - { id: "fedora", label: "Fedora", family: "dnf" }, + { id: "fedora44", label: "Fedora 44", family: "dnf" }, + { id: "fedora43", label: "Fedora 43", family: "dnf" }, + { id: "fedora", label: "Fedora 42 (EOL)", family: "dnf" }, // RPM — Zypper (openSUSE) + { id: "opensuse-leap-16.0", label: "openSUSE Leap 16.0", family: "zypper" }, { id: "opensuse-leap-15.6", label: "openSUSE Leap 15.6", family: "zypper" }, { id: "opensuse-tumbleweed", label: "openSUSE Tumbleweed", family: "zypper" }, // APK — Alpine Linux + { id: "alpine3.24", label: "Alpine Linux 3.24", family: "apk" }, + { id: "alpine3.23", label: "Alpine Linux 3.23", family: "apk" }, + { id: "alpine3.22", label: "Alpine Linux 3.22", family: "apk" }, { id: "alpine3.21", label: "Alpine Linux 3.21", family: "apk" }, { id: "alpine3.20", label: "Alpine Linux 3.20", family: "apk" }, { id: "alpine3.19", label: "Alpine Linux 3.19", family: "apk" }, diff --git a/frontend/src/pages/DockerfilePage.js b/frontend/src/pages/DockerfilePage.js index 18eac85..4103c1f 100644 --- a/frontend/src/pages/DockerfilePage.js +++ b/frontend/src/pages/DockerfilePage.js @@ -25,6 +25,8 @@ const DISTRIBUTION_GROUPS = [ { codename: "jammy", label: "Ubuntu 22.04 LTS (Jammy)" }, { codename: "noble", label: "Ubuntu 24.04 (Noble)" }, { codename: "focal", label: "Ubuntu 20.04 LTS (Focal)" }, + { codename: "resolute", label: "Ubuntu 26.04 LTS (Resolute)" }, + { codename: "trixie", label: "Debian 13 (Trixie)" }, { codename: "bookworm", label: "Debian 12 (Bookworm)" }, { codename: "bullseye", label: "Debian 11 (Bullseye)" }, ], @@ -33,10 +35,11 @@ const DISTRIBUTION_GROUPS = [ group: "RPM — RHEL / AlmaLinux / Rocky / Fedora", pm: "rpm", items: [ + { codename: "el10", label: "RHEL / AlmaLinux / Rocky 10" }, { codename: "el9", label: "RHEL / AlmaLinux / Rocky 9" }, { codename: "el8", label: "RHEL / AlmaLinux / Rocky 8" }, - { codename: "fc41", label: "Fedora 41" }, - { codename: "fc40", label: "Fedora 40" }, + { codename: "fc44", label: "Fedora 44" }, + { codename: "fc43", label: "Fedora 43" }, ], }, { @@ -101,9 +104,11 @@ function detectBaseImage(content) { distribution = `fc${ver}`; } else { const aptCodenames = { + "resolute": "resolute", "26.04": "resolute", "noble": "noble", "24.04": "noble", "jammy": "jammy", "22.04": "jammy", "focal": "focal", "20.04": "focal", + "trixie": "trixie", "bookworm": "bookworm", "bullseye": "bullseye", "buster": "buster", }; for (const [key, codename] of Object.entries(aptCodenames)) { diff --git a/frontend/src/pages/ImportPage.js b/frontend/src/pages/ImportPage.js index 2355940..1db87e8 100755 --- a/frontend/src/pages/ImportPage.js +++ b/frontend/src/pages/ImportPage.js @@ -239,19 +239,31 @@ const DISTRIBUTIONS = [ { codename: "jammy", label: "Jammy 22.04 (LTS)", format: "deb" }, { codename: "noble", label: "Noble 24.04", format: "deb" }, { codename: "focal", label: "Focal 20.04", format: "deb" }, + { codename: "resolute", label: "Resolute 26.04 (LTS)", format: "deb" }, + { codename: "trixie", label: "Trixie 13", format: "deb" }, { codename: "bookworm", label: "Bookworm 12", format: "deb" }, // RPM — RHEL family + { codename: "almalinux10", label: "AlmaLinux 10", format: "rpm" }, { codename: "almalinux9", label: "AlmaLinux 9", format: "rpm" }, { codename: "almalinux8", label: "AlmaLinux 8", format: "rpm" }, + { codename: "rocky10", label: "Rocky 10", format: "rpm" }, { codename: "rocky9", label: "Rocky 9", format: "rpm" }, { codename: "rocky8", label: "Rocky 8", format: "rpm" }, + { codename: "centos-stream10", label: "CentOS Stream 10", format: "rpm" }, { codename: "centos-stream9", label: "CentOS Stream 9", format: "rpm" }, + { codename: "oraclelinux10", label: "Oracle Linux 10", format: "rpm" }, { codename: "oraclelinux9", label: "Oracle Linux 9", format: "rpm" }, - { codename: "fedora", label: "Fedora", format: "rpm" }, + { codename: "fedora44", label: "Fedora 44", format: "rpm" }, + { codename: "fedora43", label: "Fedora 43", format: "rpm" }, + { codename: "fedora", label: "Fedora 42 (EOL)", format: "rpm" }, // RPM — openSUSE + { codename: "opensuse-leap-16.0", label: "openSUSE Leap 16.0", format: "rpm" }, { codename: "opensuse-leap-15.6", label: "openSUSE Leap 15.6", format: "rpm" }, { codename: "opensuse-tumbleweed", label: "openSUSE Tumbleweed", format: "rpm" }, // APK — Alpine Linux + { codename: "alpine3.24", label: "Alpine 3.24", format: "apk" }, + { codename: "alpine3.23", label: "Alpine 3.23", format: "apk" }, + { codename: "alpine3.22", label: "Alpine 3.22", format: "apk" }, { codename: "alpine3.21", label: "Alpine 3.21", format: "apk" }, { codename: "alpine3.20", label: "Alpine 3.20", format: "apk" }, { codename: "alpine3.19", label: "Alpine 3.19", format: "apk" }, @@ -263,24 +275,36 @@ function guessDistrib(distro) { // APT if (distro.startsWith("focal")) return "focal"; if (distro.startsWith("noble")) return "noble"; + if (distro.startsWith("resolute")) return "resolute"; + if (distro.startsWith("trixie")) return "trixie"; if (distro.startsWith("bookworm")) return "bookworm"; if (distro.startsWith("jammy")) return "jammy"; // RPM + if (distro.includes("almalinux10")) return "almalinux10"; if (distro.includes("almalinux9")) return "almalinux9"; if (distro.includes("almalinux8")) return "almalinux8"; + if (distro.includes("rocky10")) return "rocky10"; if (distro.includes("rocky9")) return "rocky9"; if (distro.includes("rocky8")) return "rocky8"; + if (distro.includes("centos") && distro.includes("10")) return "centos-stream10"; if (distro.includes("centos")) return "centos-stream9"; + if (distro.includes("oracle") && distro.includes("10")) return "oraclelinux10"; if (distro.includes("oracle") && distro.includes("9")) return "oraclelinux9"; + if (distro.includes("fedora44")) return "fedora44"; + if (distro.includes("fedora43")) return "fedora43"; if (distro.includes("fedora")) return "fedora"; if (distro.includes("tumbleweed")) return "opensuse-tumbleweed"; + if (distro.includes("leap") && distro.includes("16")) return "opensuse-leap-16.0"; if (distro.includes("leap")) return "opensuse-leap-15.6"; // APK — Alpine + if (distro.includes("alpine3.24")) return "alpine3.24"; + if (distro.includes("alpine3.23")) return "alpine3.23"; + if (distro.includes("alpine3.22")) return "alpine3.22"; if (distro.includes("alpine3.21")) return "alpine3.21"; if (distro.includes("alpine3.20")) return "alpine3.20"; if (distro.includes("alpine3.19")) return "alpine3.19"; if (distro.includes("alpine3.18")) return "alpine3.18"; - if (distro.includes("alpine")) return "alpine3.21"; + if (distro.includes("alpine")) return "alpine3.24"; return "jammy"; } diff --git a/frontend/src/pages/PromotionsPage.js b/frontend/src/pages/PromotionsPage.js index 816c183..dd5605d 100644 --- a/frontend/src/pages/PromotionsPage.js +++ b/frontend/src/pages/PromotionsPage.js @@ -37,6 +37,8 @@ const DIST_COLORS = { jammy: { bg: "#EFF6FF", text: "#1D4ED8", border: "#BFDBFE" }, noble: { bg: "#F0FDF4", text: "#15803D", border: "#BBF7D0" }, focal: { bg: "#FFF7ED", text: "#C2410C", border: "#FED7AA" }, + resolute: { bg: "#F5F3FF", text: "#6D28D9", border: "#DDD6FE" }, + trixie: { bg: "#FEF2F2", text: "#B91C1C", border: "#FECACA" }, bookworm: { bg: "#FDF4FF", text: "#7E22CE", border: "#E9D5FF" }, bullseye: { bg: "#FEF9C3", text: "#854D0E", border: "#FEF08A" }, }; diff --git a/frontend/src/pages/SettingsPage.js b/frontend/src/pages/SettingsPage.js index 44debcc..53275a3 100644 --- a/frontend/src/pages/SettingsPage.js +++ b/frontend/src/pages/SettingsPage.js @@ -28,32 +28,54 @@ const SOURCE_META = { "ubuntu-jammy-updates": { label: "Ubuntu 22.04 (Jammy) — updates", security: false, format: "deb" }, "ubuntu-noble": { label: "Ubuntu 24.04 (Noble) — base", security: false, format: "deb" }, "ubuntu-focal": { label: "Ubuntu 20.04 (Focal) — base", security: false, format: "deb" }, + "ubuntu-resolute": { label: "Ubuntu 26.04 (Resolute) — base", security: false, format: "deb" }, + "ubuntu-resolute-updates": { label: "Ubuntu 26.04 (Resolute) — updates", security: true, format: "deb" }, "debian-bookworm": { label: "Debian 12 (Bookworm) — base", security: false, format: "deb" }, + "debian-trixie": { label: "Debian 13 (Trixie) — base", security: false, format: "deb" }, + "debian-trixie-contrib": { label: "Debian 13 (Trixie) — contrib", security: false, format: "deb" }, + "debian-trixie-updates": { label: "Debian 13 (Trixie) — updates", security: true, format: "deb" }, "ubuntu-jammy-security": { label: "Ubuntu 22.04 Security", security: true, format: "deb" }, "ubuntu-noble-security": { label: "Ubuntu 24.04 Security", security: true, format: "deb" }, "ubuntu-focal-security": { label: "Ubuntu 20.04 Security", security: true, format: "deb" }, + "ubuntu-resolute-security": { label: "Ubuntu 26.04 Security", security: true, format: "deb" }, "debian-bookworm-security": { label: "Debian 12 Security", security: true, format: "deb" }, + "debian-trixie-security": { label: "Debian 13 Security", security: true, format: "deb" }, // ── RPM (RHEL / Fedora / openSUSE) ─────────────────────────────────────── "almalinux8-baseos": { label: "AlmaLinux 8 — BaseOS", security: false, format: "rpm" }, "almalinux8-appstream": { label: "AlmaLinux 8 — AppStream", security: false, format: "rpm" }, "almalinux8-extras": { label: "AlmaLinux 8 — Extras", security: false, format: "rpm" }, "almalinux9-baseos": { label: "AlmaLinux 9 — BaseOS", security: false, format: "rpm" }, "almalinux9-appstream": { label: "AlmaLinux 9 — AppStream", security: false, format: "rpm" }, + "almalinux10-baseos": { label: "AlmaLinux 10 — BaseOS", security: false, format: "rpm" }, + "almalinux10-appstream": { label: "AlmaLinux 10 — AppStream", security: false, format: "rpm" }, "rocky8-baseos": { label: "Rocky Linux 8 — BaseOS", security: false, format: "rpm" }, "rocky8-appstream": { label: "Rocky Linux 8 — AppStream", security: false, format: "rpm" }, "rocky9-baseos": { label: "Rocky Linux 9 — BaseOS", security: false, format: "rpm" }, "rocky9-appstream": { label: "Rocky Linux 9 — AppStream", security: false, format: "rpm" }, + "rocky10-baseos": { label: "Rocky Linux 10 — BaseOS", security: false, format: "rpm" }, + "rocky10-appstream": { label: "Rocky Linux 10 — AppStream", security: false, format: "rpm" }, "centos-stream9-baseos": { label: "CentOS Stream 9 — BaseOS", security: false, format: "rpm" }, "centos-stream9-appstream": { label: "CentOS Stream 9 — AppStream", security: false, format: "rpm" }, + "centos-stream10-baseos": { label: "CentOS Stream 10 — BaseOS", security: false, format: "rpm" }, + "centos-stream10-appstream":{ label: "CentOS Stream 10 — AppStream", security: false, format: "rpm" }, "oraclelinux8-baseos": { label: "Oracle Linux 8 — BaseOS", security: false, format: "rpm" }, "oraclelinux8-appstream": { label: "Oracle Linux 8 — AppStream", security: false, format: "rpm" }, "oraclelinux9-baseos": { label: "Oracle Linux 9 — BaseOS", security: false, format: "rpm" }, - "fedora42": { label: "Fedora 42", security: false, format: "rpm" }, - "fedora42-updates": { label: "Fedora 42 — Updates", security: false, format: "rpm" }, + "oraclelinux9-appstream": { label: "Oracle Linux 9 — AppStream", security: false, format: "rpm" }, + "oraclelinux10-baseos": { label: "Oracle Linux 10 — BaseOS", security: false, format: "rpm" }, + "oraclelinux10-appstream": { label: "Oracle Linux 10 — AppStream", security: false, format: "rpm" }, + "fedora42": { label: "Fedora 42 (EOL)", security: false, format: "rpm" }, + "fedora42-updates": { label: "Fedora 42 — Updates (EOL)", security: false, format: "rpm" }, + "fedora43": { label: "Fedora 43", security: false, format: "rpm" }, + "fedora43-updates": { label: "Fedora 43 — Updates", security: true, format: "rpm" }, + "fedora44": { label: "Fedora 44", security: false, format: "rpm" }, + "fedora44-updates": { label: "Fedora 44 — Updates", security: true, format: "rpm" }, "epel8": { label: "EPEL 8 (extras RHEL 8)", security: false, format: "rpm" }, "epel9": { label: "EPEL 9 (extras RHEL 9)", security: false, format: "rpm" }, + "epel10": { label: "EPEL 10 (extras RHEL 10)", security: false, format: "rpm" }, "opensuse-leap-15.6-oss": { label: "openSUSE Leap 15.6 — OSS", security: false, format: "rpm" }, "opensuse-leap-15.6-updates":{ label: "openSUSE Leap 15.6 — Updates", security: false, format: "rpm" }, + "opensuse-leap-16.0-oss": { label: "openSUSE Leap 16.0 — OSS", security: false, format: "rpm" }, "opensuse-tumbleweed-oss": { label: "openSUSE Tumbleweed — OSS", security: false, format: "rpm" }, // ── APK (Alpine Linux) ─────────────────────────────────────────────────── "alpine3.18-main": { label: "Alpine 3.18 — main", security: false, format: "apk" }, @@ -64,6 +86,12 @@ const SOURCE_META = { "alpine3.20-community": { label: "Alpine 3.20 — community", security: false, format: "apk" }, "alpine3.21-main": { label: "Alpine 3.21 — main", security: false, format: "apk" }, "alpine3.21-community": { label: "Alpine 3.21 — community", security: false, format: "apk" }, + "alpine3.22-main": { label: "Alpine 3.22 — main", security: false, format: "apk" }, + "alpine3.22-community": { label: "Alpine 3.22 — community", security: false, format: "apk" }, + "alpine3.23-main": { label: "Alpine 3.23 — main", security: false, format: "apk" }, + "alpine3.23-community": { label: "Alpine 3.23 — community", security: false, format: "apk" }, + "alpine3.24-main": { label: "Alpine 3.24 — main", security: false, format: "apk" }, + "alpine3.24-community": { label: "Alpine 3.24 — community", security: false, format: "apk" }, }; // ─── Composants utilitaires ─────────────────────────────────────────────────── @@ -1534,7 +1562,7 @@ services: context: . args: RPM_REPO_URL: "${RPM_REPO_URL}" - RPM_DISTRO: "almalinux9" # almalinux8/9 | rocky8/9 | centos-stream9 | fedora + RPM_DISTRO: "almalinux9" # almalinux8/9/10 | rocky8/9/10 | centos-stream9/10 | fedora43/44 # Dockerfile correspondant : # FROM almalinux:9 @@ -1556,7 +1584,7 @@ services: context: . args: APK_REPO_URL: "${REPO_URL}" - ALPINE_VERSION: "alpine3.21" # alpine3.18 | alpine3.19 | alpine3.20 | alpine3.21 + ALPINE_VERSION: "alpine3.24" # alpine3.18 → alpine3.24 # Dockerfile correspondant : # FROM alpine:3.21 @@ -1614,7 +1642,7 @@ services: image: alpine:3.21 environment: <<: *repod-env - ALPINE_VERSION: "alpine3.21" + ALPINE_VERSION: "alpine3.24" command: | sh -c " echo $$APK_REPO_URL/apk/$$ALPINE_VERSION/main >> /etc/apk/repositories diff --git a/scripts/gen-upstream-keyring.sh b/scripts/gen-upstream-keyring.sh index 8ba3a7c..6a42711 100755 --- a/scripts/gen-upstream-keyring.sh +++ b/scripts/gen-upstream-keyring.sh @@ -36,12 +36,30 @@ trap 'rm -rf "$WORK_DIR"' EXIT mkdir -p "$OUT_DIR" rm -f "$OUT_FILE" -echo "== Clés Ubuntu (paquet ubuntu-keyring, déjà installé sur Ubuntu) ==" -if [ ! -f /usr/share/keyrings/ubuntu-archive-keyring.gpg ]; then - sudo apt-get update -y && sudo apt-get install -y ubuntu-keyring +echo "== Clés Ubuntu (paquet ubuntu-keyring) ==" +# Sur une machine Ubuntu le trousseau est déjà là ; ailleurs (ou sans apt) on +# récupère le paquet officiel exactement comme on le fait plus bas pour Debian, +# afin que ce script reste rejouable depuis n'importe quel poste. +UBUNTU_KEYRING=/usr/share/keyrings/ubuntu-archive-keyring.gpg +if [ ! -f "$UBUNTU_KEYRING" ]; then + if command -v apt-get >/dev/null 2>&1; then + sudo apt-get update -y && sudo apt-get install -y ubuntu-keyring + else + echo " (apt indisponible — téléchargement direct depuis archive.ubuntu.com)" + UBUNTU_KEYRING_DEB="$( + curl -sSL https://archive.ubuntu.com/ubuntu/pool/main/u/ubuntu-keyring/ \ + | grep -oE 'ubuntu-keyring_[0-9.]+_all\.deb' | sort -uV | tail -1 + )" + mkdir -p "$WORK_DIR/ubuntu" + curl -sSL -o "$WORK_DIR/ubuntu/ubuntu-keyring.deb" \ + "https://archive.ubuntu.com/ubuntu/pool/main/u/ubuntu-keyring/$UBUNTU_KEYRING_DEB" + # Extrait dans son propre sous-dossier : le paquet Debian plus bas est + # dépaqueté dans $WORK_DIR et écraserait sinon les mêmes data.tar.* + ( cd "$WORK_DIR/ubuntu" && ar x ubuntu-keyring.deb && tar xf data.tar.* ) + UBUNTU_KEYRING="$WORK_DIR/ubuntu/usr/share/keyrings/ubuntu-archive-keyring.gpg" + fi fi -gpg --no-default-keyring --keyring "$OUT_FILE" \ - --import /usr/share/keyrings/ubuntu-archive-keyring.gpg +gpg --no-default-keyring --keyring "$OUT_FILE" --import "$UBUNTU_KEYRING" echo "== Clés Debian (paquet debian-archive-keyring, téléchargé direct depuis ftp.debian.org) ==" DEBIAN_KEYRING_DEB_URL="$( @@ -54,9 +72,20 @@ curl -sSL -o "$WORK_DIR/debian-archive-keyring.deb" \ # Une clé par release Debian activement synchronisée dans DEFAULT_SOURCES — # ajouter une ligne ici pour chaque nouvelle distro Debian ajoutée au projet. +# Note trixie : son InRelease est aujourd'hui encore co-signé par les clés +# bookworm, donc la vérification passerait même sans les clés trixie — mais +# uniquement par accident de transition. Debian retirera cette co-signature, +# et la vérification étant fail-closed, trixie cesserait alors de se +# synchroniser. Les trois clés trixie sont donc importées dès maintenant +# (-stable en plus des deux -automatic : c'est la troisième signature portée +# par l'InRelease de trixie). for key in \ debian-archive-bookworm-automatic \ debian-archive-bookworm-security-automatic \ + debian-archive-bookworm-stable \ + debian-archive-trixie-automatic \ + debian-archive-trixie-security-automatic \ + debian-archive-trixie-stable \ ; do gpg --no-default-keyring --keyring "$OUT_FILE" \ --import "$WORK_DIR/usr/share/keyrings/${key}.gpg"