apiVersion: catalog.confighub.com/v1alpha1
kind: SveltosCvePatchLock
metadata:
  name: cve-patch-prerequisites
spec:
  sveltos:
    version: v1.13.0
    manifestUrl: https://raw.githubusercontent.com/projectsveltos/sveltos/v1.13.0/manifest/manifest.yaml
    manifestSha256: 5538558ad428617153f963318f22e70eb32fa949e9e0f07e07f02a0db700e2d7
    note: This chapter installs the release whose remote fetch path was verified live and recorded in docs/planning/remote-url-oci-probe.md. The management cluster fetches each approved release from the ConfigHub OCI gateway itself, so no other controller takes part. The gateway serves each release as a gzipped tar layer, and the released addon controller does not gunzip, so a run points SVELTOS_ADDON_CONTROLLER_IMAGE at a build carrying the gzip fix. The runner defaults to docker.io/projectsveltos/addon-controller at the pinned version and records the image it actually ran.
  chart:
    name: kyverno/kyverno
    repositoryURL: https://kyverno.github.io/kyverno/
    from:
      chartVersion: "3.8.1"
      chartDigest: a33f35b83b6991daf6a1b1cf995becbe369747fcd84411d5089d55a40ee4ae0d
    to:
      chartVersion: "3.8.2"
      chartDigest: f4fc787cf1d6781eefb9e9b45837edcddcfae984c872888289914e97207cc5de
      artifact: https://kyverno.github.io/kyverno/kyverno-3.8.2.tgz
    note: The chart pin is the one the patch candidate reviews, repeated here so the two records are compared before any revision is stored. The runner downloads the patched artifact and refuses to continue unless its bytes hash to the digest above. It does not scan the chart for vulnerabilities and it does not verify any advisory claim.
