* fix(image-updates): explain persistent digest rebuilds after update
When an update completes but a same-tag digest rebuild is still detected,
the generic "update still detected" warning told operators nothing about
why. The digest comparison already knows the remaining updates are
digest-only (no higher tag), so recheckStack now returns a targeted
warning naming the two daemon-side causes: a registry mirror or cache
serving stale content, or a container still pinned to the previous image.
The digest-rebuild badge surfaces (Anatomy banner, Fleet cards, mobile)
now carry a tooltip with the same explanation, and the post-update
warning is added to the pre-update refresh sanitization set.
* fix(image-updates): surface digest warnings on editor and mobile paths
Editor Update discarded recheckWarning, digest hints were hover-only, and
service-scoped rechecks blamed the daemon when only sibling services remained stale.
* feat: add node-scoped opt-out for image update detection
Operators who use an external update authority can disable Sencho registry
polling per node without losing explicit stack Update, pull, or redeploy.
* test: fix mocks and lint for image-update checks opt-out
Scheduler tests need isChecksEnabled on the ImageUpdateService mock, and the UpdatesSection older-node fixture must not leave an unused binding.
* fix: gate update-preview and recheck when detection is off
Anatomy was still calling stack update-preview (and contacting registries)
while checks were disabled. Short-circuit those routes and skip recheckStack
writes so disabled nodes stay quiet until detection is re-enabled.
* fix(fleet): verify update status before removing readiness cards
Full-stack Apply now rechecks persisted status after the health gate starts, reloads the live preview before dropping a card, and invalidates the hub fleet aggregation so cleared updates cannot resurrect from a stale cache.
Closes#1686
* fix(fleet): align persisted update status with preview semver detection
Share digest-plus-tag detection so post-Apply sidebar status matches Fleet and Anatomy.
* fix(fleet): keep tag-only updates advisory for Compose automation
Expose digestUpdate vs tagUpdate from checkImage so scheduled and API auto-update only apply same-tag digest drift Compose can pull.
* docs: clarify scheduled auto-update applies digest drift only
Document that higher pinned tags stay advisory until Compose is changed, matching schedule and Run Now behavior.
* docs: require Compose pin edits for higher-tag advisories
Stop recommending Apply now or Update as remedies that cannot rewrite a pinned image tag.
* docs: clarify Apply now pulls pinned tags only
Align the detection-cadence bullet with digest-rebuild vs higher-tag guidance.
* fix(fleet): keep tag advisories after apply and scheduled updates
Tag-only previews were treated as cleared on Fleet reload, and scheduled/
Run Now paths wiped status without rechecking. Align post-update verification
with the manual Apply path (health gate first, recheck, no blind clear) and
block digest apply when sibling image checks failed.
* fix(fleet): clear eslint unused-arg and containers assignment