v1.0.1
v1.0.1 (2026-06-10)
This release is published under the MIT License.
Bug Fixes
- Pin third-party GitHub Actions to commit SHAs (
9e0058b)
Pin python-semantic-release, upload-to-gh-release, and gh-action-pypi-publish to immutable commit SHAs to mitigate supply-chain risk from mutable tags. Add Dependabot config to keep the pins updated.
Co-Authored-By: Claude Sonnet 4.6 noreply@anthropic.com
Detailed Changes: v1.0.0...v1.0.1