Follow-up to #4756 feedback.
Once the workflow has run for a while and is stable, expand the library patch level to minor (and evaluate major per-package) so more/all fixable library CVEs are remediated directly in the patched image.
To verify before implementing:
- Re-test minor on the current Copa version across latest + prev-minor releases and confirm the rebuild compiles. note: Copa 0.15.0 added deterministic go updates, which may already resolve the incoherent bump break.
- Confirm CVE reduction improves and the per-arch regression / set-based publish gate stays green (no newly-introduced CVEs).
- major needs extra care: evaluate separately, likely per-package.
Follow-up to #4756 feedback.
Once the workflow has run for a while and is stable, expand the library patch level to minor (and evaluate major per-package) so more/all fixable library CVEs are remediated directly in the patched image.
To verify before implementing: