v0.24.0
·
49 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
What's Changed
- feat(sbom): consistent primary component, document identity, and CRA metadata by @bomly-guy in #364
- feat(sbom): detector-asserted package origin in SBOM export by @bomly-guy in #397
- build(deps): bump the github-actions-patch group with 3 updates by @dependabot[bot] in #393
- build(deps): bump github.com/mark3labs/mcp-go from 0.57.0 to 0.58.0 in the gomod-minor group across 1 directory by @dependabot[bot] in #402
- build(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 by @dependabot[bot] in #394
- docs: extract architecture decision log into dev-docs/adr by @bomly-guy in #403
- test: update smoke golden files by @github-actions[bot] in #404
- fix(security): resolve cache-poisoning and vulnerability code scanning alerts by @bomly-guy in #405
Full Changelog: v0.23.0...v0.24.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.