Stable v2.6.2 — Security
- fix(agent): self-heal half-configured packages after the security catch-up
- feat(agent): apply pending security updates immediately after the fix + keep configs
- fix(security): apply Debian OS security updates on trixie + honest CVE feed
- feat(cra): CVE feed sourced from Debian Security Tracker (real open CVEs)
- fix(cra): CVE feed — readable severity + per-component grouping
- fix(cra): golangci-lint on CVE feed (errcheck + US spelling)
- feat(cra): live CVE feed — SBOM components matched against OSV.dev
- docs(plan): CRA cockpit stages 1-4 complete (SBOM, security.txt, incidents, snapshots)
- feat(cra): security.txt generator (RFC 9116) for coordinated disclosure