Releases: AmadeusITGroup/flamme
Releases · AmadeusITGroup/flamme
Release list
v0.1.0
🚀 Release Summary
🏗️ Build Information
🧪 Test Results
- Total Tests: 5
- Passed: 5
- Failed: 0
- Success Rate: 100.0%
📈 Code Coverage
- Instructions: 0%
- Branches: 0%
- Lines: 0%
📦 Maven Central
- Coordinates:
io.github.amadeusitgroup:flamme:0.1.0/io.github.amadeusitgroup:flamme-deployment:0.1.0 - Runtime: https://central.sonatype.com/artifact/io.github.amadeusitgroup/flamme/0.1.0
- Deployment: https://central.sonatype.com/artifact/io.github.amadeusitgroup/flamme-deployment/0.1.0
🔒 Security Attestations
This release includes comprehensive security attestations and provenance information:
📋 Software Bill of Materials (SBOM)
- SPDX Format: sbom.spdx.json
🛡️ Security Scanning
- Vulnerability Report: vulnerability-report.json
- SARIF Report: trivy-results.sarif
🔐 Provenance & Attestations
- SLSA Provenance: *.intoto.jsonl (provenance attestations)
- Build Metadata: build-metadata.json
- Artifact Hashes: *.sha256
✍️ Code Signing
- All artifacts are signed with GPG
📦 Release Artifacts
Main Artifacts:
- Runtime JAR: flamme-0.1.0.jar
- Runtime POM: flamme-0.1.0.pom
- Deployment JAR: flamme-deployment-0.1.0.jar
- Deployment POM: flamme-deployment-0.1.0.pom
Attestation Artifacts:
- sbom.spdx.json - SPDX Software Bill of Materials
- vulnerability-report.json - Security vulnerability report
- build-metadata.json - Build environment metadata
- *.sha256 - SHA-256 checksums
🔍 Verification
See the attached VERIFICATION.md file for detailed instructions on verifying GPG signatures, SHA256 hashes, SLSA provenance, and scanning SBOMs for vulnerabilities.
🏗️ Build Environment
- Runner OS: ubuntu-latest
- Build Actor: sonOfTheComet-ctrl
- Repository: AmadeusITGroup/flamme
- Event: release
All attestations are also available in Maven Central alongside the published artifacts.