Skip to content

v0.22.0

Choose a tag to compare

@bomly-release bomly-release released this 11 Aug 23:47
· 60 commits to main since this release
Immutable release. Only release title and notes can be modified.

What's Changed

  • fix(cli): make startup logo static by default, animate via BOMLY_LOGO opt-in by @bomly-guy in #371
  • feat: modular architecture — consume the SDK as Go module by @bomly-guy in #375
  • build(deps): bump the github-actions-patch group with 3 updates by @dependabot[bot] in #374
  • build(deps): bump dart-lang/setup-dart from 1.7.2 to 1.8.0 in the github-actions-minor group by @dependabot[bot] in #373
  • build(deps): bump cryptography from 49.0.0 to 50.0.0 in /.github in the pip group across 1 directory by @dependabot[bot] in #376
  • test: update smoke golden files by @github-actions[bot] in #377

Full Changelog: v0.21.3...v0.22.0


Release artifacts

  • Full builtin bomly archives for Linux, macOS, and Windows.
  • Alternate bomly-lite archives for users who prefer external Syft and Grype binaries.
  • Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
  • Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
  • SHA256SUMS for release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).
  • SLSA Build Level 3 provenance (multiple.intoto.jsonl) generated by slsa-github-generator.

Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.