Repository navigation
fix(openhands): ship Copa-patched images in 0.71.2 - #1375
Merged
Merged
Conversation
Pins enterprise-server, runtime-api, agent-server, automation, agent-canvas, plugin-directory-server, keycloak, postgresql (incl. keycloak waitForDb), redis, ohe-minio and ohe-minio-mc to their ghcr.io/openhands/patched/* copies by tag@digest, in chart values and the Replicated overrides. The chart bump tool's pin patterns accept the patched/ path. Also drops --library-patch-level from the OS-only Copa retry.
…ositories The probe image is the enterprise-server proxy base plus alpine/openssl. With enterprise-server under ghcr.io/openhands/patched, the suffix no longer matched, the probe pulled a nonexistent image, and every TLS/DNS preflight reported "No matching files".
dylan-openhands
requested review from
aivong-openhands,
jlav and
mamoodi
as code owners
October 9, 2026 02:13
Contributor
|
| Location | Value |
|---|---|
charts/openhands/Chart.yaml → appVersion |
1.64.0 |
charts/openhands/values.yaml → image.tag |
1.64.0-patched@sha256:b8180530ba277738b5177a97eac96d0a684c8c4e22a48c83d25aed2c1f5944fb |
Fix: set appVersion to 1.64.0-patched@sha256:b8180530ba277738b5177a97eac96d0a684c8c4e22a48c83d25aed2c1f5944fb in charts/openhands/Chart.yaml.
This is a notice, not a blocking check.
…hannel head Beta is semver-required, so a maintenance release tagged from a release branch (e.g. openhands/0.71.2 while Beta is on 0.79) is published but never becomes head. Deploying it would downgrade the beta instance; skip the deploy and e2e in that case. (cherry picked from commit d576312715e6366bcaad45c60652b6a360cba122)
aivong-openhands
approved these changes
Oct 9, 2026
Contributor
|
🚀 Released in openhands/0.71.2. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A customer on 0.71.1 needs vulnerability fixes without moving to a newer minor. This points 0.71.2 at Copa-patched copies of the images 0.71.1 already runs: same upstream versions, OS packages (and for some images Python libraries) upgraded in place. Merging into
release/0.71makes release-please open the 0.71.2 release PR.Patched images live at
ghcr.io/openhands/patched/<name>:<source tag>-patched, pinned by digest in the chart values and the Replicated proxy overrides. Nothing is written to existing packages.Counts are amd64 Trivy before → after. Remaining criticals are mostly packages with no upstream fix yet, Go binaries, and Keycloak's Java CVEs.
Other changes:
/ghcr.io/openhands/enterprise-serveroffimage.repository; with thepatched/path it pulled a nonexistent image and every check showed "No matching files".check_agent_server_sync.pytreatsX-patched@sha256:…as releaseX, so the sync check accepts the patched tags.patches/0.71.2.jsonis the Copa manifest for these images; the patch workflow itself is in ci: add Copa image patching workflow #1371.release-replicated-beta.ymlskips the beta-instance deploy when the new release doesn't become Beta's head. Beta is semver-required and on 0.79, so theopenhands/0.71.2tag's run publishes 0.71.2 to Beta (for Stable promotion) without downgrading the beta instance. Tag runs use the workflow at the tagged commit, so the guard has to be on this branch. Checked on a throwaway semver-required channel (head stayed 0.2.0 after 0.1.1 was published) and by running the step against live Beta.Verified on the shared Replicated fleet (shared-2, embedded cluster): clean install of 0.71.1, then upgrade through the admin console to this exact tree (chart version bumped to 0.71.2 locally to match the release-please commit). All pods Ready, every long-running service and the cronjobs on
patched/*digests, Keycloak and Postgres data intact, preflights clean, login and a new conversation work on a sandbox frompatched/agent-server.