From 1663df69d116893bfb69c0756dbee5055821e6d6 Mon Sep 17 00:00:00 2001 From: KaraZajac Date: Mon, 1 Jun 2026 11:55:31 -0400 Subject: [PATCH] release v0.9.7: kernel_range drift fix + CI Node 24 readiness MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Tags the maintenance work landed since v0.9.6. The fragnesia drift fix (35c33df) and checkout v4->v6 bump (6c148e2) are already on main; this commit adds the remaining CI Node-24 bumps + version strings. release.yml: upload-artifact v4->v7, download-artifact v4->v8, softprops/action-gh-release v2->v3 (last of the Node-20-era actions; GitHub forces node24 on 2026-06-16). Reviewed each changelog — our default-zip/unique-name upload + full-set download is unaffected by the major-version breaking changes (opt-in direct uploads, download-by-ID path). Version bumped to 0.9.7 (skeletonkey.c, README, docs/index.html) + v0.9.7 RELEASE_NOTES entry. Tagging this commit fires release.yml — the end-to-end test of the new artifact actions, incl. the Alpine/musl static job under node24. --- .github/workflows/release.yml | 10 +++++----- README.md | 2 +- docs/RELEASE_NOTES.md | 27 +++++++++++++++++++++++++++ docs/index.html | 4 ++-- skeletonkey.c | 2 +- 5 files changed, 36 insertions(+), 9 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 65d7644..c9b4207 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -52,7 +52,7 @@ jobs: mv skeletonkey skeletonkey-${{ matrix.target }} sha256sum skeletonkey-${{ matrix.target }} > skeletonkey-${{ matrix.target }}.sha256 - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@v7 with: name: skeletonkey-${{ matrix.target }} path: | @@ -87,7 +87,7 @@ jobs: run: | mv skeletonkey skeletonkey-x86_64-static sha256sum skeletonkey-x86_64-static > skeletonkey-x86_64-static.sha256 - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@v7 with: name: skeletonkey-x86_64-static path: | @@ -130,7 +130,7 @@ jobs: run: | mv skeletonkey skeletonkey-arm64-static sha256sum skeletonkey-arm64-static > skeletonkey-arm64-static.sha256 - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@v7 with: name: skeletonkey-arm64-static path: | @@ -143,7 +143,7 @@ jobs: steps: - uses: actions/checkout@v6 - - uses: actions/download-artifact@v4 + - uses: actions/download-artifact@v8 with: path: dist @@ -181,7 +181,7 @@ jobs: fi - name: publish release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: tag_name: ${{ steps.notes.outputs.tag }} name: SKELETONKEY ${{ steps.notes.outputs.tag }} diff --git a/README.md b/README.md index 8e07792..60fcd86 100644 --- a/README.md +++ b/README.md @@ -202,7 +202,7 @@ also compile (modules with Linux-only headers stub out gracefully). ## Status -**v0.9.6 cut 2026-05-28.** 39 modules across 34 CVEs — **every +**v0.9.7 cut 2026-06-01.** 39 modules across 34 CVEs — **every year 2016 → 2026 now covered**. v0.9.0 added 5 gap-fillers (`mutagen_astronomy` / `sudo_runas_neg1` / `tioscpgrp` / `vsock_uaf` / `nft_pipapo`); v0.8.0 added 3 (`sudo_chwoot` / `udisks_libblockdev` / diff --git a/docs/RELEASE_NOTES.md b/docs/RELEASE_NOTES.md index cbe7813..d8d05f7 100644 --- a/docs/RELEASE_NOTES.md +++ b/docs/RELEASE_NOTES.md @@ -1,3 +1,30 @@ +## SKELETONKEY v0.9.7 — kernel_range drift fix + CI Node 24 readiness + +Two maintenance fixes, no new modules. + +**`fragnesia` kernel_range drift.** Debian backported CVE-2026-46300 to +the 5.10 oldstable branch (bullseye 5.10.257), a branch the module's +`kernel_patched_from` table didn't model — on a patched bullseye host +`detect()` would have false-positived VULNERABLE. Added the `{5,10,257}` +entry; the weekly `refresh-kernel-ranges.py` drift gate is green again. +(The other flagged modules are INFO-only "more permissive" thresholds +the check tolerates by design.) + +**CI Node 24 readiness.** GitHub forces the Node 24 Actions runtime on +2026-06-16 and removes Node 20. Bumped every workflow action off its +Node-20 line: + +- `actions/checkout` v4 → v6 +- `actions/upload-artifact` v4 → v7 +- `actions/download-artifact` v4 → v8 +- `softprops/action-gh-release` v2 → v3 + +Each was reviewed against its changelog: the artifact flow uploads +default-zipped, uniquely-named artifacts and downloads the full set, so +none of the major-version breaking changes (opt-in direct uploads, +download-by-ID path changes) apply. This release is itself the +end-to-end test of the new artifact actions. + ## SKELETONKEY v0.9.6 — `--auto` no longer prompts for sudo password Two sudo modules' `detect()` bodies invoked `sudo -ln` to read the diff --git a/docs/index.html b/docs/index.html index 2e809b9..860f799 100644 --- a/docs/index.html +++ b/docs/index.html @@ -56,7 +56,7 @@
- v0.9.6 — released 2026-05-28 + v0.9.7 — released 2026-06-01

SKELETONKEY @@ -598,7 +598,7 @@ uid=0(root) gid=0(root) who found the bugs.

diff --git a/skeletonkey.c b/skeletonkey.c index 9f1c7da..5910b3c 100644 --- a/skeletonkey.c +++ b/skeletonkey.c @@ -35,7 +35,7 @@ #include #include -#define SKELETONKEY_VERSION "0.9.6" +#define SKELETONKEY_VERSION "0.9.7" static const char BANNER[] = "\n"