ArtifactFlow v0.0.3
Container image (pin by digest):
ghcr.io/gadsotek/artifactflow@sha256:8bbf9a1b300c4a004b0624907d078bfa2e7fd90eedb72562151bd696d4c86d8b
Verify build provenance and SBOM before running (needs the GitHub CLI):
gh attestation verify oci://ghcr.io/gadsotek/artifactflow@sha256:8bbf9a1b300c4a004b0624907d078bfa2e7fd90eedb72562151bd696d4c86d8b --repo Gadsotek/artifactflow
SLSA build provenance and a CycloneDX SBOM are keyless-signed (Sigstore) and attested to the image digest, and pushed alongside it in the registry; the SBOM is also attached to this release as sbom.cdx.json.
The image was scanned with Trivy (vuln, secret, misconfig; HIGH/CRITICAL gate) before publishing.
Self-hosting docs: docs/OPERATIONS.md. AGPL Section 13 applies to network use; see COMMERCIAL.md for the commercial path.
What's Changed
- Harden release security and MCP integration by @Gadsotek in #16
- Fix remaining audit findings by @Gadsotek in #17
- Prepare v0.0.3 release by @Gadsotek in #18
- Fix release reusable-CI permissions by @Gadsotek in #19
Full Changelog: v0.0.2...v0.0.3