Skip to content

Releases: decionis/steward

Decionis Steward 0.3.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:29
826f317

Artifacts

File What it is
decionis-steward-0.3.0.tar.gz Deployable Next.js standalone bundle
decionis-steward-0.3.0.cdx.json CycloneDX SBOM of the resolved production tree
decionis-steward-0.3.0.sigstore.json Sigstore bundle for the provenance attestation
decionis-steward-0.3.0.intoto.jsonl The same attestation as a signed in-toto statement

SHA-256 of the tarball:

d156181a9f00804fff45bef3024f4ee867f43b7b7969601e31372316f2f435a3

Verifying provenance

This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:

gh attestation verify decionis-steward-0.3.0.tar.gz --repo decionis/steward

That confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.

The attestation is also attached here, so it can be verified from the
downloaded files alone without reaching GitHub's attestation API:

gh attestation verify decionis-steward-0.3.0.tar.gz \
  --bundle decionis-steward-0.3.0.sigstore.json --repo decionis/steward

Licensing

Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.

Decionis Steward 0.2.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 15:46
c8ed1d1

Artifacts

File What it is
decionis-steward-0.2.0.tar.gz Deployable Next.js standalone bundle
decionis-steward-0.2.0.cdx.json CycloneDX SBOM of the resolved production tree
decionis-steward-0.2.0.sigstore.json Sigstore bundle for the provenance attestation
decionis-steward-0.2.0.intoto.jsonl The same attestation as a signed in-toto statement

SHA-256 of the tarball:

fea53667d1f2ed4c706bb3a02e90ae0e0893f71ec89123d2d09a9c5749f99f7c

Verifying provenance

This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:

gh attestation verify decionis-steward-0.2.0.tar.gz --repo decionis/steward

That confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.

The attestation is also attached here, so it can be verified from the
downloaded files alone without reaching GitHub's attestation API:

gh attestation verify decionis-steward-0.2.0.tar.gz \
  --bundle decionis-steward-0.2.0.sigstore.json --repo decionis/steward

Licensing

Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.

Decionis CDI 0.1.2

Choose a tag to compare

@github-actions github-actions released this 15 Aug 15:43
aa6f097

Artifacts

File What it is
decionis-cdi-0.1.2.tar.gz Deployable Next.js standalone bundle
decionis-cdi-0.1.2.cdx.json CycloneDX SBOM of the resolved production tree
decionis-cdi-0.1.2.sigstore.json Sigstore bundle for the provenance attestation

SHA-256 of the tarball:

00429837b25e2bb8802ff3d5cafa93d508937681874e97d7804103be53d1d65d

Verifying provenance

This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:

gh attestation verify decionis-cdi-0.1.2.tar.gz --repo decionis/cdi

That confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.

The attestation is also attached here, so it can be verified from the
downloaded files alone without reaching GitHub's attestation API:

gh attestation verify decionis-cdi-0.1.2.tar.gz \
  --bundle decionis-cdi-0.1.2.sigstore.json --repo decionis/cdi

Licensing

Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.

Decionis CDI 0.1.1

Choose a tag to compare

@github-actions github-actions released this 15 Aug 12:09
5324966

Artifacts

File What it is
decionis-cdi-0.1.1.tar.gz Deployable Next.js standalone bundle
decionis-cdi-0.1.1.cdx.json CycloneDX SBOM of the resolved production tree

SHA-256 of the tarball:

7ac943f44ff1d73bfb4b910a71bccc73bd8b482610acede9d03a01e6bf401d18

Verifying provenance

This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:

gh attestation verify decionis-cdi-0.1.1.tar.gz --repo decionis/cdi

That confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.

Licensing

Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.

Decionis CDI 0.1.0

Choose a tag to compare

@github-actions github-actions released this 15 Aug 10:59
0b4bfd6

Artifacts

File What it is
decionis-cdi-0.1.0.tar.gz Deployable Next.js standalone bundle
decionis-cdi-0.1.0.cdx.json CycloneDX SBOM of the resolved production tree

SHA-256 of the tarball:

8558a05ffdd070532deaace0bf13d66f78c33cf1bda746df666b7984f3a2af6f

Verifying provenance

This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:

gh attestation verify decionis-cdi-0.1.0.tar.gz --repo decionis/cdi

That confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.

Licensing

Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.