Security
Supported Versions
Tromso images are built on every push to main and published to GHCR.
Only the most recent build of each tag has active support. A periodic job
removes older tags.
| Tag | Status |
|---|---|
latest | ✅ Supported |
<git-sha> | ⚠️ Best effort |
<date> | ⚠️ Best effort |
Reporting a Vulnerability
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately via GitHub Security Advisories:
- Go to the Security tab
- Click Report a vulnerability
- Provide a detailed description of the issue, including steps to reproduce
You can expect:
- Acknowledgment within 48 hours
- Status update within 5 business days
- Resolution timeline based on severity
Security Model
Tromso images are:
- Built in CI from fixed BuildStream elements with a content-addressed cache
- Published as OCI images to
ghcr.io/tuna-os/tromso - Built inside a pinned
bst2container with local CASD
Supply Chain Security
- Git references or SHA256 values for tarballs fix the base elements in the
elements/tree. SeeAGENTS.mdfor the paths. The project removed the formerkde-build-metajunction and moved its elements into this repository. - The
elements/freedesktop-sdk.bstjunction fixes the version of thefreedesktop-sdkbase SDK. - The content-addressable CASD store of BuildStream resolves build dependencies.
- A digest fixes the version of the build container (
bst2).
Disclosure Policy
We follow coordinated disclosure:
- The reporter submits a vulnerability through a private channel.
- We investigate and develop a fix.
- We deploy the fix to new builds.
- We publish an advisory after deployment.
See AGENTS.md and SPEC.md for full build architecture details.