Skip to content

0.1.8

Choose a tag to compare

@github-actions github-actions released this 24 Aug 19:14
· 6 commits to main since this release
Immutable release. Only release title and notes can be modified.
0.1.8
1eaaa68
  • Added a trusted default-branch Dependabot catalog synchronizer. Failed
    same-repository Dependabot action bumps are updated in place from a
    workflow_run job that never executes candidate code; hardening and
    Scorecard validators now derive action identities from the catalog instead
    of carrying additional hardcoded SHA copies.
  • Made the synchronizer update the exact bound pull request through GitHub's
    native branch API, approve only action_required runs for its exact derived
    SHA, and keep candidate trees data-only. Transitive Docker-action image
    declarations now converge with action pin updates as well.
  • Added the machine-enforced cache trust contract v2: provider ref scopes,
    exact-first key dimensions, persistent-runner residue rules, retention and
    rate limits, hosted/fleet equivalence, and real cold/warm telemetry.
  • Added successful runtime harnesses for the real cargo-fuzz and
    ClusterFuzzLite reusable workflows, including a complete C++ libFuzzer
    builder integration and fail-closed evidence aggregation.
  • Isolated owner-only side-effect runtime fixtures from Dependabot pull
    requests so real bot commits and repository labels are never mistaken for
    disposable commitlint or label-mutation evidence.
  • Made release-ledger date reconciliation timezone-independent by deriving the
    tagged commit's UTC author date. The signed 0.1.7 tag remains immutable
    rejected evidence and has no release.