v0.1.1
Verifiable artifacts
npm publication was not enabled for this release.
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.1.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.1.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- Automate verified GitHub releases by @ocularminds in #16
- Consolidate dependency updates by @ocularminds in #17
- Complete public repository hardening by @ocularminds in #18
- Fix Linux license inventory CI by @ocularminds in #25
Full Changelog: v0.1.0...v0.1.1