Files
backup-tool/docs/release/m14-provenance.md
T

14 lines
863 B
Markdown

# M14 build provenance
- **Source revision:** `396219e776aa9a115900d2b7bfd9fb5c1cfde115`
- **Application base:** `python:3.12.11-slim-bookworm@sha256:519591d6871b7bc437060736b9f7456b8731f1499a57e22e6c285135ae657bf7`
- **Frontend builder:** `node:22.17.1-alpine@sha256:5539840ce9d013fa13e3b9814c9353024be7ac75aca5db6d039504a56c04ea59`
- **Proxy base:** `nginx:1.29.7-alpine@sha256:e7257f1ef28ba17cf7c248cb8ccf6f0c6e0228ab9c315c152f9c203cd34cf6d1`
- **Build command:** `docker compose build --pull`
- **SBOM:** `docs/release/m14-sbom.json`, generated deterministically with
`python tools/generate_sbom.py` from the pinned backend manifest and frontend lockfile.
The build uses digest-pinned bases and a non-root runtime user. Provenance records
inputs and generation instructions rather than embedding a mutable image tag or a
secret-bearing build environment.