14 lines
863 B
Markdown
14 lines
863 B
Markdown
# M14 build provenance
|
|
|
|
- **Source revision:** `396219e776aa9a115900d2b7bfd9fb5c1cfde115`
|
|
- **Application base:** `python:3.12.11-slim-bookworm@sha256:519591d6871b7bc437060736b9f7456b8731f1499a57e22e6c285135ae657bf7`
|
|
- **Frontend builder:** `node:22.17.1-alpine@sha256:5539840ce9d013fa13e3b9814c9353024be7ac75aca5db6d039504a56c04ea59`
|
|
- **Proxy base:** `nginx:1.29.7-alpine@sha256:e7257f1ef28ba17cf7c248cb8ccf6f0c6e0228ab9c315c152f9c203cd34cf6d1`
|
|
- **Build command:** `docker compose build --pull`
|
|
- **SBOM:** `docs/release/m14-sbom.json`, generated deterministically with
|
|
`python tools/generate_sbom.py` from the pinned backend manifest and frontend lockfile.
|
|
|
|
The build uses digest-pinned bases and a non-root runtime user. Provenance records
|
|
inputs and generation instructions rather than embedding a mutable image tag or a
|
|
secret-bearing build environment.
|