Releases: airomhq/airom
Releases · airomhq/airom
Release list
v0.3.6
Changelog
Features
- 41f1379: feat(spdx): implement the SPDX 3.0.1 writer that was reserved for v2 (@Roro1727)
- 6f98e38: feat(vex): export OpenVEX over the CVE overlay (@Roro1727)
Others
- 8853cb1: chore(ci): Bump the github-actions group across 1 directory with 9 updates (@dependabot[bot])
- f3b9e47: ci(docs): build and export the documentation site, without publishing it (@Roro1727)
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.5
Changelog
Features
Others
- e2522b5: docs(readme): cut it from 427 lines to 176 and lead with the command (@Roro1727)
- ae23948: docs(readme): list the frameworks and runtimes added since v0.3.4 (@Roro1727)
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.4
Changelog
Features
- f7fbd9b: feat(pgext): read a server-side pgvector install from its control file (@Roro1727)
- 735bbe7: feat(sql): scan .sql files, widen pgvector to halfvec/sparsevec and index DDL (@Roro1727)
Bug fixes
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.3
Changelog
Features
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.2
Changelog
Features
- bff68f2: feat(rules): check airom-rules for a newer bundle before a scan (@Roro1727)
- 4c39b16: feat(rules): converge agno with the bundle's pack (@Roro1727)
- c2659f5: feat(rules): detect agno, crawl4ai, and fastmcp (@Roro1727)
Bug fixes
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.1
Changelog
Features
- 83fd4a1: feat(manifest): read installed package metadata, so a deployed scan has versions (@Roro1727)
- ef68dfa: feat(manifest): read lockfiles, and stop reporting a range as a version (@Roro1727)
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.3.0
Changelog
Features
- 452e6bb: feat(diff): add airom diff — the semantic delta between two AIBOMs (@bhatt-neel-dev)
- ef9c3ea: feat(diff): show what is dead or dangerous about the AI a PR adds (@Roro1727)
Bug fixes
- 2fd1ed4: fix(diff): refuse to gate a delta the code did not cause (@Roro1727)
- e9f119d: fix(lexer): classify Python docstrings apart from strings (@Roro1727)
- cf03d9f: fix(rules): stop bedrock and pgvector matching shapes far broader than models (@Roro1727)
- df81b12: fix: four false-positive classes surfaced by a home-directory scan (@Roro1727)
Others
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.2.2
Changelog
Bug fixes
Others
- 0eac929: ci(fuzz): add the nightly deep campaign the smoke job stopped being (@Roro1727)
- 9bc90ef: ci(fuzz): budget the gating fuzz run by exec count, not wall clock (@Roro1727)
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.2.1
Changelog
Features
Others
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
v0.2.0
Changelog
Features
- 0389cdc: feat(eol): --fail-on eol gate + docs (PR4) (@Roro1727)
- e877755: feat(eol): hosted-model end-of-life overlay — domain, catalog, matcher (PR1) (@Roro1727)
- 3a2ef17: feat(eol): project model lifecycle into every output format (PR3) (@Roro1727)
- 264ad6b: feat(eol): ship the lifecycle catalog through the signed rule channel (@Roro1727)
- ac62701: feat(eol): wire the EOL overlay into the pipeline, add --no-eol (PR2) (@Roro1727)
Verify the checksums signature (keyless cosign):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/airomhq/airom' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt