v0.25.0
·
4 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
What's Changed
- docs: plan the SDK maturity program (ADR-0036 through ADR-0039) by @bomly-guy in #411
- build: require Go 1.27 by @bomly-guy in #412
- docs: ADR-0041 — identity is the canonical PURL on typed graph nodes by @bomly-guy in #413
- docs: ADR-0041 clarifications recorded at implementation by @bomly-guy in #414
- feat!: adopt the typed graph node union (bomly-sdk v0.9.0, ADR-0041) by @bomly-guy in #423
- chore: pin bomly-sdk v0.9.1, and describe how releases actually happen by @bomly-guy in #427
- refactor: SPDX expression handling is the SDK's, not a local wrapper (phase 2.2) by @bomly-guy in #428
- feat(sbom): unrecognized licenses export as LicenseRef, not free text (phase 2.4 + SDK v0.9.2) by @bomly-guy in #429
- feat(sbom): preserve what a source document asserted, on ingest and on export (closes #396) by @bomly-guy in #430
- feat(sbom): export the whole scope set, and refuse a document that reads two ways by @bomly-guy in #431
- feat(sbom): adopt SDK v0.9.6 scope semantics, resolve ADR-0037, record ADR-0043 by @bomly-guy in #441
- refactor(output): one home for the registry lookup every presentation surface was writing out (phase 2.7) by @bomly-guy in #437
- feat(detectors): record which module root each location belongs to (phase 2.8, producer half) by @bomly-guy in #439
- Phase 3: finish and guard the PURL delegation, and truth up the model docs by @bomly-guy in #436
- fix(sbom): read the end-of-life claim back, in both formats by @bomly-guy in #438
- feat(sbom): adopt SDK v0.9.7 and close eight limitations by @bomly-guy in #440
- fix(sbom): the digest vocabulary is the SDK registry's, not local tables by @bomly-guy in #443
- fix(test): a guard file may name the module it forbids by @bomly-guy in #444
- test: update smoke golden files by @github-actions[bot] in #447
- refactor: run the Go 1.27 modernizer (go fix) across the repo by @bomly-guy in #448
- refactor(detectors): the SDK decides every detector's purl type by @bomly-guy in #446
- test(smoke): goldens stop carrying the host architecture by @bomly-guy in #450
- docs: record the declined modernizer analyzer in both guidance files by @bomly-guy in #451
- feat(detectors): the purl type stops being something a detector can pass by @bomly-guy in #452
- docs(adr): ADR-0033 names the SDK helper and what the fold does merge by @bomly-guy in #456
- fix(sbom): a transformed export mints its own identity and links its source by @bomly-guy in #461
- docs(maturity): done-criterion 2 states the measurement that was actually taken by @bomly-guy in #462
- fix(sbom): an escaped lone surrogate is refused as its own class, and the advice says so by @bomly-guy in #463
- docs(adr): a guard must be able to fail, and must know what it covers by @bomly-guy in #460
- docs(adr): qualify what MergeOrigins drops by @bomly-guy in #457
- test: update smoke golden files by @github-actions[bot] in #458
- chore(deps): consume bomly-sdk v0.11.0 and every plugin's latest tag; ADR-0045 decides the codec's home by @bomly-guy in #465
- build: replace the guard walkers with depguard, forbidigo and a go/analysis analyzer by @bomly-guy in #468
- build(deps): bump actions/setup-java from 5.7.0 to 6.0.0 by @dependabot[bot] in #422
- build(deps): bump github.com/mark3labs/mcp-go from 0.58.0 to 1.0.0 by @dependabot[bot] in #442
- build(deps): bump dart-lang/setup-dart from 1.8.0 to 1.8.1 in the github-actions-patch group across 1 directory by @dependabot[bot] in #470
- build(deps): bump the gomod-minor group across 1 directory with 2 updates by @dependabot[bot] in #473
- refactor(sbom): consume bomly-sdk v0.12.0's codec and graphview; delete the CLI copies by @bomly-guy in #474
Full Changelog: v0.24.2...v0.25.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.