Skip to content

v0.1.3-rc.2

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 16 Aug 14:51
8997f0b

Verifiable artifacts

npm: @decionis/agent-safe-pipeline@0.1.3-rc.2

shasum -a 256 -c SHA256SUMS
gh attestation verify decionis-agent-safe-pipeline-0.1.3-rc.2.tgz \
  --repo decionis/agent-safe-pipeline \
  --bundle agent-safe-pipeline-0.1.3-rc.2.provenance.sigstore.json \
  --custom-trusted-root trusted_root.jsonl

The CycloneDX SBOM was generated from the extracted npm tarball and contains at least five dependency components. Raw in-toto statements and their signed Sigstore bundles are attached for mirrors and offline verification.

What's Changed

  • Prepare OIDC proof prerelease by @decionis-bot[bot] in #44
  • Add procurement HOLD example by @decionis-bot[bot] in #40
  • Document OpenSSF Best Practices evidence by @decionis-bot[bot] in #53
  • Fix npm local tarball publication by @decionis-bot[bot] in #54

Full Changelog: v0.1.3-rc.1...v0.1.3-rc.2