v0.1.3-rc.2
Pre-release
Pre-release
Verifiable artifacts
npm: @decionis/agent-safe-pipeline@0.1.3-rc.2
shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.3-rc.2.tgz \
--repo decionis/agent-safe-pipeline \
--bundle agent-safe-pipeline-0.1.3-rc.2.provenance.sigstore.json \
--custom-trusted-root trusted_root.jsonlThe CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.
What's Changed
- Prepare OIDC proof prerelease by @decionis-bot[bot] in #44
- Add procurement HOLD example by @decionis-bot[bot] in #40
- Document OpenSSF Best Practices evidence by @decionis-bot[bot] in #53
- Fix npm local tarball publication by @decionis-bot[bot] in #54
Full Changelog: v0.1.3-rc.1...v0.1.3-rc.2