v0.1.2
Corrected public-reporting guidance
v0.1.2 supersedes the v0.1.1 draft candidate. It corrects the security
policy so reports involving a real bundle, log, workflow, URL, hostname,
credential, or uncertainty about redaction must use the private advisory
channel. Public reports must use a fully synthetic, minimized reproduction.
What did not change
ci-capsule remains a Linux, owner-operated, read-only CLI. It does not execute
recovered commands, run or mutate workflows, download artifacts/caches, upload
bundles, or claim that a sanitized bundle is secret-free.
Release assets
ci-capsule_v0.1.2_linux_amd64.tar.gzci-capsule_v0.1.2_checksums.txtci-capsule_v0.1.2_sbom.cdx.json, a minimal CycloneDX 1.5 SBOM
Verify both checksummed assets after download:
sha256sum -c ci-capsule_v0.1.2_checksums.txt