Skip to content
This repository was archived by the owner on May 11, 2026. It is now read-only.

v3.9.5

Latest

Choose a tag to compare

@github-actions github-actions released this 10 May 15:35
· 1 commit to master since this release
Immutable release. Only release title and notes can be modified.

🚀 Automatically Published Release

Version 3.9.5 has been successfully published:

📦 NPM Package

🐳 Docker Image

Docker images built from this release use the same dist/ artifact as the NPM package:

  • Pull: docker pull ghcr.io/gander-tools/osm-tagging-schema-mcp:3.9.5
  • Build artifact: dist.tar.gz (attached to this release)

🔐 Provenance & Security

This package was published with comprehensive supply chain security:

NPM Provenance

  • npm provenance enabled
  • Verified build from GitHub Actions
  • Cryptographic attestations linking package to source

SLSA Build Provenance

  • SLSA Level 3 build provenance attestations
  • Tamper-proof build metadata
  • Verifiable build environment and process

SBOM (Software Bill of Materials)

  • CycloneDX SBOM generated and attested
  • Complete dependency transparency
  • Supply chain risk assessment

🔍 Verification

Verify npm provenance:

npm audit signatures @gander-tools/osm-tagging-schema-mcp

Verify SLSA attestations:

gh attestation verify oci://ghcr.io/gander-tools/osm-tagging-schema-mcp:3.9.5 --owner gander-tools

📋 Release Process

Release steps:

  1. ✅ Build and test validation
  2. ✅ NPM package published with provenance
  3. ✅ Git tag created by Publish NPM workflow
  4. ✅ GitHub release published with artifacts

📝 Changelog

See CHANGELOG.md for detailed changes in this release.