Releases: decionis/agent-safe-pipeline
Release list
v0.1.3-rc.2
Verifiable artifacts
npm: @decionis/agent-safe-pipeline@0.1.3-rc.2
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.3-rc.2.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.3-rc.2.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- Prepare OIDC proof prerelease by @decionis-bot[bot] in #44
- Add procurement HOLD example by @decionis-bot[bot] in #40
- Document OpenSSF Best Practices evidence by @decionis-bot[bot] in #53
- Fix npm local tarball publication by @decionis-bot[bot] in #54
Full Changelog: v0.1.3-rc.1...v0.1.3-rc.2
v0.1.3-rc.1
Verifiable artifacts
npm publication was not enabled for this release.
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.3-rc.1.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.3-rc.1.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- Improve OpenSSF Scorecard controls by @decionis-bot[bot] in #39
- Add protected npm bootstrap workflow by @decionis-bot[bot] in #42
- Prepare npm OIDC prerelease by @decionis-bot[bot] in #43
Full Changelog: v0.1.2...v0.1.3-rc.1
v0.1.2
Verifiable artifacts
npm publication was not enabled for this release.
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.2.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.2.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- feat(conformance): add Unicode/numeric edge-case hash vectors by @yunaremaia in #23
- Record fixture and security ownership by @ocularminds in #24
- Add bot-authored pull request workflow by @decionis-bot[bot] in #26
- Localize repository rules for AgentSafe by @decionis-bot[bot] in #27
- Bind idempotency keys to execution intents by @decionis-bot[bot] in #28
- Harden authority response and grant validation by @decionis-bot[bot] in #29
- Freeze decisions and authorization evidence by @decionis-bot[bot] in #30
- Enforce single-use execution invariants by @decionis-bot[bot] in #31
- Bound untrusted intent traversal by @decionis-bot[bot] in #32
- Fail closed on Presence boundary errors by @decionis-bot[bot] in #34
- Enforce declared verification gates by @decionis-bot[bot] in #33
- Restrict automated discovery probes by @decionis-bot[bot] in #36
- Bound PR bot API responses by @decionis-bot[bot] in #35
- Release v0.1.2 by @ocularminds in #37
New Contributors
- @yunaremaia made their first contribution in #23
- @decionis-bot[bot] made their first contribution in #26
Full Changelog: v0.1.1...v0.1.2
v0.1.1
Verifiable artifacts
npm publication was not enabled for this release.
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.1.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.1.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- Automate verified GitHub releases by @ocularminds in #16
- Consolidate dependency updates by @ocularminds in #17
- Complete public repository hardening by @ocularminds in #18
- Fix Linux license inventory CI by @ocularminds in #25
Full Changelog: v0.1.0...v0.1.1
v0.1.0
What's Changed
- Add agent-safe execution pipeline by @ocularminds in #1
- Fix critical Vitest and Vite vulnerabilities by @ocularminds in #2
- Fix CodeQL ReDoS findings and add repository guardrails by @ocularminds in #3
- Harden public repository security posture by @ocularminds in #4
New Contributors
- @ocularminds made their first contribution in #1
Full Changelog: https://github.com/decionis/agent-safe-pipeline/commits/v0.1.0