This repository was archived by the owner on May 11, 2026. It is now read-only.
·
1 commit
to master
since this release
Immutable
release. Only release title and notes can be modified.
🚀 Automatically Published Release
Version 3.9.5 has been successfully published:
📦 NPM Package
- Package: @gander-tools/osm-tagging-schema-mcp
- Install:
npx @gander-tools/osm-tagging-schema-mcp@3.9.5
🐳 Docker Image
Docker images built from this release use the same dist/ artifact as the NPM package:
- Pull:
docker pull ghcr.io/gander-tools/osm-tagging-schema-mcp:3.9.5 - Build artifact:
dist.tar.gz(attached to this release)
🔐 Provenance & Security
This package was published with comprehensive supply chain security:
NPM Provenance
- npm provenance enabled
- Verified build from GitHub Actions
- Cryptographic attestations linking package to source
SLSA Build Provenance
- SLSA Level 3 build provenance attestations
- Tamper-proof build metadata
- Verifiable build environment and process
SBOM (Software Bill of Materials)
- CycloneDX SBOM generated and attested
- Complete dependency transparency
- Supply chain risk assessment
🔍 Verification
Verify npm provenance:
npm audit signatures @gander-tools/osm-tagging-schema-mcpVerify SLSA attestations:
gh attestation verify oci://ghcr.io/gander-tools/osm-tagging-schema-mcp:3.9.5 --owner gander-tools📋 Release Process
Release steps:
- ✅ Build and test validation
- ✅ NPM package published with provenance
- ✅ Git tag created by Publish NPM workflow
- ✅ GitHub release published with artifacts
📝 Changelog
See CHANGELOG.md for detailed changes in this release.