π Release Summary
ποΈ Build Information
π§ͺ Test Results
- Total Tests: 5
- Passed: 5
- Failed: 0
- Success Rate: 100.0%
π Code Coverage
- Instructions: 0%
- Branches: 0%
- Lines: 0%
π¦ Maven Central
- Coordinates:
io.github.amadeusitgroup:flamme:0.1.0/io.github.amadeusitgroup:flamme-deployment:0.1.0 - Runtime: https://central.sonatype.com/artifact/io.github.amadeusitgroup/flamme/0.1.0
- Deployment: https://central.sonatype.com/artifact/io.github.amadeusitgroup/flamme-deployment/0.1.0
π Security Attestations
This release includes comprehensive security attestations and provenance information:
π Software Bill of Materials (SBOM)
- SPDX Format: sbom.spdx.json
π‘οΈ Security Scanning
- Vulnerability Report: vulnerability-report.json
- SARIF Report: trivy-results.sarif
π Provenance & Attestations
- SLSA Provenance: *.intoto.jsonl (provenance attestations)
- Build Metadata: build-metadata.json
- Artifact Hashes: *.sha256
βοΈ Code Signing
- All artifacts are signed with GPG
π¦ Release Artifacts
Main Artifacts:
- Runtime JAR: flamme-0.1.0.jar
- Runtime POM: flamme-0.1.0.pom
- Deployment JAR: flamme-deployment-0.1.0.jar
- Deployment POM: flamme-deployment-0.1.0.pom
Attestation Artifacts:
- sbom.spdx.json - SPDX Software Bill of Materials
- vulnerability-report.json - Security vulnerability report
- build-metadata.json - Build environment metadata
- *.sha256 - SHA-256 checksums
π Verification
See the attached VERIFICATION.md file for detailed instructions on verifying GPG signatures, SHA256 hashes, SLSA provenance, and scanning SBOMs for vulnerabilities.
ποΈ Build Environment
- Runner OS: ubuntu-latest
- Build Actor: sonOfTheComet-ctrl
- Repository: AmadeusITGroup/flamme
- Event: release
All attestations are also available in Maven Central alongside the published artifacts.