Skip to content

ArtifactFlow v0.0.6

Latest

Choose a tag to compare

@github-actions github-actions released this 25 Jul 14:26

Container image (pin by digest):

ghcr.io/gadsotek/artifactflow@sha256:913bceb62f0acd22a2ab67a1103c3c4cbd29f53fc0dfae956a37c6c8a4d7a6f3

Verify build provenance and SBOM before running (needs the GitHub CLI):

gh attestation verify oci://ghcr.io/gadsotek/artifactflow@sha256:913bceb62f0acd22a2ab67a1103c3c4cbd29f53fc0dfae956a37c6c8a4d7a6f3 --repo Gadsotek/artifactflow

SLSA build provenance and a CycloneDX SBOM are keyless-signed (Sigstore) and attested to the image digest, and pushed alongside it in the registry; the SBOM is also attached to this release as sbom.cdx.json.
The image was scanned with Trivy (vuln, secret, misconfig; HIGH/CRITICAL gate) before publishing.
Self-hosting docs: docs/OPERATIONS.md. AGPL Section 13 applies to network use; see COMMERCIAL.md for the commercial path.

Full Changelog: v0.0.5...v0.0.6