Decionis Steward 0.2.0
Artifacts
| File | What it is |
|---|---|
decionis-steward-0.2.0.tar.gz |
Deployable Next.js standalone bundle |
decionis-steward-0.2.0.cdx.json |
CycloneDX SBOM of the resolved production tree |
decionis-steward-0.2.0.sigstore.json |
Sigstore bundle for the provenance attestation |
decionis-steward-0.2.0.intoto.jsonl |
The same attestation as a signed in-toto statement |
SHA-256 of the tarball:
fea53667d1f2ed4c706bb3a02e90ae0e0893f71ec89123d2d09a9c5749f99f7c
Verifying provenance
This build carries a signed SLSA provenance attestation. Verify it against
this repository before deploying:
gh attestation verify decionis-steward-0.2.0.tar.gz --repo decionis/stewardThat confirms the artifact was produced by this workflow from this commit,
not rebuilt elsewhere.
The attestation is also attached here, so it can be verified from the
downloaded files alone without reaching GitHub's attestation API:
gh attestation verify decionis-steward-0.2.0.tar.gz \
--bundle decionis-steward-0.2.0.sigstore.json --repo decionis/stewardLicensing
Apache-2.0. Third-party components are inventoried in ThirdPartyLicenses.md;
the SBOM attached here is the deployment-accurate equivalent, generated on
the Linux build platform.