Repository navigation
Releases: grantlinehq/grantline
Release list
Grantline v0.1.0-rc.5
Grantline 0.1.0-rc.5 is a preview for self-hosted non-human identity investigation.
Download grantline-install-0.1.0-rc.5.zip (Windows/macOS/Linux) or
grantline-install-0.1.0-rc.5.tar.gz (Linux/macOS), extract it, and run
docker compose up -d --wait. Open http://127.0.0.1:8080 and follow README-FIRST.md.
The bundle pins the application digest; no Go/Node installation or source build is required.
Changes in this candidate
- Pin transitive
source-map-jsto patched 1.2.2 for GHSA-68fv-2mgg-jv7q;
retain dependency auditing in build and publication gates. - Synchronize embedded documentation with all nine rules, pipeline investigations,
related-source finding responses and schema-4 upgrade boundaries. Separate current
source from the published rc.4 packages and clarify provider/connection counts. - Add IL009: review Jenkins jobs mapped to the same collected Vault AppRole across
explicitly separated environments, with pinned-file evidence and exact reasoned
exceptions. Missing metadata remains UNKNOWN; credential names are not identities. - Show related Entra application findings under GitHub source filters using an
evidenced federation relationship, labeled separately from the root cause. - Show named subjects, known values and recorded policy thresholds in findings;
distinguish native identities from related configuration objects. - Search findings by affected subject, credential parent application or SPIFFE ID,
and select source, rule and review status without entering internal identifiers. - Keep historical policy context separate from current settings and explain rule
coverage, UNKNOWN and policy-assigned severity alongside supporting evidence. - Add three investigation walkthroughs and a sanitized ten-finding lab review.
- Clarify that six supported provider types are distinct from saved connections.
Verified distribution
- Container:
ghcr.io/grantlinehq/grantline:0.1.0-rc.5(amd64 and arm64). - Image digest:
sha256:c65e723d9423182ba95f47edf886a3329c7fed5f01992d2b50de6959ae1b0383. - Helm:
oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.5. - Chart digest:
sha256:1007f27d9d49cf780920b0934d4096e63e0be536c6e41629c567b0bee52cce0f. - Source commit:
9aea171b664ced472cd123fb780f131b38160c3a. SHA256SUMScovers every payload, with a Sigstore bundle authenticating the checksums.- Image and chart digest signatures use this repository's release workflow identity.
Single organization and one active application instance. Provider access is read-only.
This candidate is not labeled production ready: the full live-provider/IdP/SMTP and
WCAG acceptance matrix remains open. See the compatibility and security documentation.
Pilot users and contributors are welcome. Share feedback in
GitHub Discussions or the
issue forms, using
sanitized reproduction steps. Report vulnerabilities privately through SECURITY.md.
Independent verification after publication — 6 October 2026
- All 16 public assets downloaded without authentication. The Sigstore checksum bundle authenticated all 14 payload hashes before extraction.
- Image and chart signatures independently verified against this repository's release workflow and GitHub Actions OIDC issuer. Empty registry credentials pulled both artifacts; OCI chart bytes matched the signed download.
- All 499 source archive files matched the immutable source commit. The package includes patched source-map-js 1.2.2, IL009, related GitHub/Entra findings and updated docs.
- Downloaded Compose package passed clean setup, Owner/TOTP, closed initialization, nine policy defaults, schema 4, embedded pipeline docs/API, encrypted/redacted connection persistence, container recreation and session revocation.
- Public Helm chart passed fresh Kubernetes 1.37.0 installation, restricted database roles, hardened pod, migration, upgrade and restart while preserving data and independent Secrets.
- Both architecture scans have zero HIGH/CRITICAL findings. Current CodeQL, secret-scanning and Dependabot open-alert counts are zero; private reporting is enabled.
These checks use disposable accounts/data. Full live-provider failure/expiry coverage, organization IdP/SMTP and complete accessibility acceptance remain open. No social-media post has been submitted.
Grantline v0.1.0-rc.4
Grantline 0.1.0-rc.4 is a preview for self-hosted non-human identity investigation.
Download grantline-install-0.1.0-rc.4.zip (Windows/macOS/Linux) or
grantline-install-0.1.0-rc.4.tar.gz (Linux/macOS), extract it, and run
docker compose up -d --wait. Open http://127.0.0.1:8080 and follow README-FIRST.md.
The bundle pins the application digest; no Go/Node installation or source build is required.
Changes in this candidate
- Make security support follow the latest published preview instead of naming an
obsolete candidate. - Refresh the compatibility and implementation records with independently
verified public-package results and the guided policy editor. - Add actual-product investigation screenshots using explicitly labeled
synthetic imported evidence; no private workspace data is published. - Refresh versioned Docker, Helm and download references for the announcement.
Verified distribution
- Container:
ghcr.io/grantlinehq/grantline:0.1.0-rc.4(amd64 and arm64). - Image digest:
sha256:910e6db0f150350ca98221fb67b5b16c13d1c69b7353f47ace750826898a3119. - Helm:
oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.4. - Chart digest:
sha256:e9fcd8a8824a3d2075b4e33a50f11cb040b1ee0cf6fe6606635b84d72367a57b. - Source commit:
4719ff365f966fb92aa00e28364e91276a0a55fd. SHA256SUMScovers every payload, with a Sigstore bundle authenticating the checksums.- Image and chart digest signatures use this repository's release workflow identity.
Single organization and one active application instance. Provider access is read-only.
This candidate is not labeled production ready: the full live-provider/IdP/SMTP and
WCAG acceptance matrix remains open. See the compatibility and security documentation.
Pilot users and contributors are welcome. Share feedback in
GitHub Discussions or the
issue forms, using
sanitized reproduction steps. Report vulnerabilities privately through SECURITY.md.
Independent public-package acceptance — 2026-10-05
Anonymous image/chart pulls and independent Cosign verification passed. All 16 assets were downloaded anonymously; the checksum Sigstore bundle and all 14 payload hashes were verified before installation.
The downloaded Compose package passed fresh setup, first Owner/TOTP, encrypted connection persistence, container recreation, renewed password/TOTP login and session revocation. The anonymously downloaded OCI chart passed clean installation, migrations, hardened runtime, upgrade and application restart with retained database data and external Secrets on Kubernetes v1.37.0 / Helm v4.3.0 in an isolated kind cluster. Only disposable test resources were removed.
Native linux/amd64 runtime was verified; linux/arm64 is covered under emulation in CI. macOS/native ARM64, the full provider failure/expiry matrix, customer IdP/SMTP and full WCAG acceptance remain pending. This is an early-access candidate, not a production-ready claim.
Grantline v0.1.0-rc.3
Grantline 0.1.0-rc.3 is a preview for self-hosted non-human identity investigation.
Download grantline-install-0.1.0-rc.3.zip (Windows/macOS/Linux) or
grantline-install-0.1.0-rc.3.tar.gz (Linux/macOS), extract it, and run
docker compose up -d --wait. Open http://127.0.0.1:8080 and follow README-FIRST.md.
The bundle pins the application digest; no Go/Node installation or source build is required.
Changes in this candidate
- Add an effective-policy editor for all eight rules, required sources, lifetime
thresholds and exact exception lists, with an advanced YAML view. - Validate and preview policy changes on saved evidence without changing reports,
connections or triage; require acknowledgement when disabling rules or removing
required sources, with revision and role checks enforced by the API. - Replace GitHub, Vault and Jenkins JSON scope inputs with guided row forms,
provider preparation steps, permission examples and connection pickers. - Clarify Entra identifier types, derive tenant scope automatically, and return
field-level configuration errors without echoing submitted credential values. - Expand policy/context examples and document the validation API.
Verified distribution
- Container:
ghcr.io/grantlinehq/grantline:0.1.0-rc.3(amd64 and arm64). - Image digest:
sha256:a6309c0a13176d057f485df505550512e4ae1ec858b9354f44757d15479d9489. - Helm:
oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.3. - Chart digest:
sha256:2b3c03ae43b36dd860a3f30e7cfb5cafcce1037ee96bbac3a78f4095b9b3b985. - Source commit:
d346d82419518d310c1678edb1b287fb991305bc. SHA256SUMScovers every payload, with a Sigstore bundle authenticating the checksums.- Image and chart digest signatures use this repository's release workflow identity.
Single organization and one active application instance. Provider access is read-only.
This candidate is not labeled production ready: the full live-provider/IdP/SMTP and
WCAG acceptance matrix remains open. See the compatibility and security documentation.
Pilot users and contributors are welcome. Share feedback in
GitHub Discussions or the
issue forms, using
sanitized reproduction steps. Report vulnerabilities privately through SECURITY.md.
Public package acceptance — 2026-10-04
- Anonymous downloads and registry pulls passed; all payload checksums and independent image/chart Cosign signature verification passed.
- The downloaded Compose package passed fresh installation, Owner/TOTP setup, saved-connection persistence, restart and session-revocation checks.
- The public OCI chart passed installation, migration, upgrade and restart on Kubernetes v1.37.0; data and independently managed Secrets were retained.
- Both architecture vulnerability reports contain zero HIGH or CRITICAL findings. ARM64 execution was checked through QEMU in release CI; native ARM64 and macOS acceptance are still pending.
This is an early-access candidate for pilot use; the full live-provider, IdP/SMTP and accessibility acceptance matrix remains open.
Grantline v0.1.0-rc.2
Grantline 0.1.0-rc.2 is a preview for self-hosted non-human identity investigation.
Download grantline-install-0.1.0-rc.2.zip (Windows/macOS/Linux) or
grantline-install-0.1.0-rc.2.tar.gz (Linux/macOS), extract it, and run
docker compose up -d --wait. Open http://127.0.0.1:8080 and follow README-FIRST.md.
The bundle pins the application digest; no Go/Node installation or source build is required.
- Container:
ghcr.io/grantlinehq/grantline:0.1.0-rc.2(amd64 and arm64). - Image digest:
sha256:f9c6f9aff6d7a10b77416685e666352e862ad59345cc72554706d56e4f7075fd. - Helm:
oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.2. - Chart digest:
sha256:0f99fc323434253c8b36e710b21a695357e353ec69620c70a6ae381627af366c. - Source commit:
7f44459b542f4e5d9e18d81ad47f9c0447c4f6f7. SHA256SUMScovers every payload, with a Sigstore bundle authenticating the checksums.- Image and chart digest signatures use this repository's release workflow identity.
Single organization and one active application instance. Provider access is read-only.
This candidate is not labeled production ready: the full live-provider/IdP/SMTP and
WCAG acceptance matrix remains open. See the compatibility and security documentation.
Grantline v0.1.0-rc.1
Grantline 0.1.0-rc.1 is a preview for self-hosted non-human identity investigation.
Download grantline-install-0.1.0-rc.1.zip (Windows/macOS/Linux) or
grantline-install-0.1.0-rc.1.tar.gz (Linux/macOS), extract it, and run
docker compose up -d --wait. Open http://127.0.0.1:8080 and follow README-FIRST.md.
The bundle pins the application digest; no Go/Node installation or source build is required.
- Container:
ghcr.io/grantlinehq/grantline:0.1.0-rc.1(amd64 and arm64). - Image digest:
sha256:5a5e83248e56481d6345a8ffa4c1920d0af14f6d53285ac618ed9c28022e2224. - Helm:
oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.1. - Chart digest:
sha256:9748b470c4646ffcfe926aae0be187f2b13fb809bde1d95b59bfa2bd67293e9e. - Source commit:
05051be52246df984f83cdc7a913a27f92f3c07a. SHA256SUMScovers every payload, with a Sigstore bundle authenticating the checksums.- Image and chart digest signatures use this repository's release workflow identity.
Single organization and one active application instance. Provider access is read-only.
This candidate is not labeled production ready: the full live-provider/IdP/SMTP and
WCAG acceptance matrix remains open. See the compatibility and security documentation.