CHANGELOG: record the bentopdf pin move + revert as a spike measurement, not a release
gates / gates (push) Successful in 1s

This commit is contained in:
2026-09-01 19:59:22 +02:00
parent 30bd892fd3
commit 5d8f25f611
+16
View File
@@ -1,3 +1,19 @@
## SPIKE measurement — bentopdf pin moved and reverted the same hour (2026-09-01, R-438) — NOT A RELEASE
**No template is different after this pair of commits.** `214d448` moved
`templates/bentopdf/docker-compose.yml` from `v2.8.6` to `v2.8.5`; `30bd892` reverted it. Both are on
`main` deliberately, because the measurement needed a REAL catalog change travelling the real
15-minute sync — a hand-edit on the box would have proved nothing about the syncer.
**What it measured, live on demo-hp:** the sync at 17:45:17Z rewrote the DEPLOYED app's
`docker-compose.yml` to `v2.8.5` while its container went on running `v2.8.6`, and nothing told the
customer. Then a boot reconciliation started the app on `v2.8.5` with nobody pressing anything.
**Why bentopdf:** it is deployed on demo-hp only (demo-felhom runs opengist alone; Peti's box is down
with no enrolled host), and it is file-based with no database and no volume, so no data anywhere could
be touched. Evidence and the full findings:
`felhom.eu/documentation/audits/SPIKE-app-update-2026-09-01.md`.
## the decoy sweep — can this gate be fooled by a label? (2026-09-01, R-421) — NOT A RELEASE
**No product code, no version bump, no image, no golden.** A scripts change is not a release.