Skip to content

cobolwork 0.2.117

Choose a tag to compare

@Portll Portll released this 30 Sep 05:28
· 318 commits to main since this release

cobolwork 0.2.117.

Install: npm install -g @portll/cobolwork or pip install cobolwork; either gives the command cobolwork. The PyPI package runs the same files with the Node.js on your PATH. The npm package is attached here as cobolwork-0.2.117.tgz to pin, and as cobolwork.tgz.

The package's lib/revision.json names the commit it was built from, b144074.

Summary

Every path finding says whether an attacker can use it.

  • explain carries a verification plan for each path finding.
  • The build gate compiles IBM estates with ironwork check, reads gcobol’s options as it reads cobc’s, and can require an ironwork equivalence statement for each program a change edits.
  • cobolwork sbom writes a CycloneDX bill of materials, and build --provenance-format slsa an SLSA provenance statement.
  • New rules: the three from ironwork’s model, and those the z/OS advisories justify.
  • A GitHub Action for the build gate, sealed evidence of a run, and tighter subscript bounds.