Skip to content

fix(openhands): ship Copa-patched images in 0.71.2 - #1375

Merged
dylan-openhands merged 8 commits into
release/0.71from
dj/copa-0.71.2
Oct 9, 2026
Merged

dylan-openhands merged 8 commits into
release/0.71from
dj/copa-0.71.2

Conversation

@dylan-openhands

@dylan-openhands dylan-openhands commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

A customer on 0.71.1 needs vulnerability fixes without moving to a newer minor. This points 0.71.2 at Copa-patched copies of the images 0.71.1 already runs: same upstream versions, OS packages (and for some images Python libraries) upgraded in place. Merging into release/0.71 makes release-please open the 0.71.2 release PR.

Patched images live at ghcr.io/openhands/patched/<name>:<source tag>-patched, pinned by digest in the chart values and the Replicated proxy overrides. Nothing is written to existing packages.

Image Critical High Ships patched
enterprise-server 1.64.0 18 → 5 183 → 127 yes
runtime-api 0.10.0 5 → 0 76 → 53 yes
agent-server 1.49.5-python 10 → 9 435 → 422 yes
agent-canvas 1.23.0 10 → 9 437 → 424 yes
automation 1.14.0 14 → 2 87 → 64 yes
plugin-directory-server 1.2.0 8 → 2 76 → 61 yes
plugin-directory-client 1.2.0 4 → 1 125 → 78 yes (OS packages only)
ohe-minio 6 → 6 173 → 99 yes
ohe-minio-mc 3 → 3 151 → 75 yes
keycloak 26.3.0 (also its waitForDb) 27 → 11 249 → 177 yes
postgresql 16.4.0 20 → 3 131 → 63 yes
redis 7.4.1 18 → 2 129 → 74 yes
keycloak-config-cli 6.4.0 17 → 1 152 → 103 no (not deployed)
litellm-database 1.100.1 2 → 2 23 → 23 no (Copa changed nothing)

Counts are amd64 Trivy before → after. Remaining criticals are mostly packages with no upstream fix yet, Go binaries, and Keycloak's Java CVEs.

Other changes:

  • The TLS/DNS preflight derived its probe image by trimming /ghcr.io/openhands/enterprise-server off image.repository; with the patched/ path it pulled a nonexistent image and every check showed "No matching files".
  • check_agent_server_sync.py treats X-patched@sha256:… as release X, so the sync check accepts the patched tags.
  • patches/0.71.2.json is the Copa manifest for these images; the patch workflow itself is in ci: add Copa image patching workflow #1371.
  • release-replicated-beta.yml skips the beta-instance deploy when the new release doesn't become Beta's head. Beta is semver-required and on 0.79, so the openhands/0.71.2 tag's run publishes 0.71.2 to Beta (for Stable promotion) without downgrading the beta instance. Tag runs use the workflow at the tagged commit, so the guard has to be on this branch. Checked on a throwaway semver-required channel (head stayed 0.2.0 after 0.1.1 was published) and by running the step against live Beta.

Verified on the shared Replicated fleet (shared-2, embedded cluster): clean install of 0.71.1, then upgrade through the admin console to this exact tree (chart version bumped to 0.71.2 locally to match the release-please commit). All pods Ready, every long-running service and the cronjobs on patched/* digests, Keycloak and Postgres data intact, preflights clean, login and a new conversation work on a sandbox from patched/agent-server.

Pins enterprise-server, runtime-api, agent-server, automation, agent-canvas,
plugin-directory-server, keycloak, postgresql (incl. keycloak waitForDb),
redis, ohe-minio and ohe-minio-mc to their ghcr.io/openhands/patched/*
copies by tag@digest, in chart values and the Replicated overrides. The chart
bump tool's pin patterns accept the patched/ path. Also drops
--library-patch-level from the OS-only Copa retry.
…ositories

The probe image is the enterprise-server proxy base plus alpine/openssl. With enterprise-server under ghcr.io/openhands/patched, the suffix no longer matched, the probe pulled a nonexistent image, and every TLS/DNS preflight reported "No matching files".
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

⚠️ Chart appVersion has drifted from the image tag

The openhands chart's appVersion no longer matches the deployed image tag. These are meant to stay in sync.

Location Value
charts/openhands/Chart.yaml → appVersion 1.64.0
charts/openhands/values.yaml → image.tag 1.64.0-patched@sha256:b8180530ba277738b5177a97eac96d0a684c8c4e22a48c83d25aed2c1f5944fb

Fix: set appVersion to 1.64.0-patched@sha256:b8180530ba277738b5177a97eac96d0a684c8c4e22a48c83d25aed2c1f5944fb in charts/openhands/Chart.yaml.

This is a notice, not a blocking check.

@github-actions github-actions Bot added the type: fix A bug fix label Oct 9, 2026
…hannel head

Beta is semver-required, so a maintenance release tagged from a release branch (e.g. openhands/0.71.2 while Beta is on 0.79) is published but never becomes head. Deploying it would downgrade the beta instance; skip the deploy and e2e in that case.

(cherry picked from commit d576312715e6366bcaad45c60652b6a360cba122)
@dylan-openhands
dylan-openhands merged commit ac153ba into release/0.71 Oct 9, 2026
26 checks passed
@dylan-openhands
dylan-openhands deleted the dj/copa-0.71.2 branch October 9, 2026 16:44
@openhands-release-bot openhands-release-bot Bot added the released: openhands/0.71.2 Shipped in openhands/0.71.2 label Oct 9, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in openhands/0.71.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released: openhands/0.71.2 Shipped in openhands/0.71.2 type: fix A bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants