Releases: mcpg-dev/mcpg-plugin-audit-http
Release list
v0.1.0-alpha.22
Release of mcpg-plugin-audit-http at v0.1.0-alpha.22.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.22" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.22 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.20
Release of mcpg-plugin-audit-http at v0.1.0-alpha.20.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.20" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.20 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.19
Release of mcpg-plugin-audit-http at v0.1.0-alpha.19.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.19" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.19 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.18
Release of mcpg-plugin-audit-http at v0.1.0-alpha.18.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.18" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.18 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.12
Release of mcpg-plugin-audit-http at v0.1.0-alpha.12.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.12" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.12 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.11
Release of mcpg-plugin-audit-http at v0.1.0-alpha.11.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.11" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.11 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.9
Release of mcpg-plugin-audit-http at v0.1.0-alpha.9.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.9" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.9 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.10
Release of mcpg-plugin-audit-http at v0.1.0-alpha.10.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.10" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.10 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.8
Release of mcpg-plugin-audit-http at v0.1.0-alpha.8.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.8" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.8 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-alpha.7
Release of mcpg-plugin-audit-http at v0.1.0-alpha.7.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg-plugin-audit-http = { git = "https://github.com/mcpg-dev/mcpg-plugin-audit-http", tag = "v0.1.0-alpha.7" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-plugin-audit-http --tag v0.1.0-alpha.7 mcpg-plugin-audit-http, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg-plugin-audit-http
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>