Skip to content

Releases: mcpg-dev/mcpg-sensitive

v0.1.0-beta.38

v0.1.0-beta.38 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Sep 23:52

Release of mcpg-sensitive at v0.1.0-beta.38.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.38" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.38 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.36

v0.1.0-beta.36 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Sep 05:09

Release of mcpg-sensitive at v0.1.0-beta.36.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.36" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.36 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.35

v0.1.0-beta.35 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 07:11

Release of mcpg-sensitive at v0.1.0-beta.35.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.35" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.35 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.34

v0.1.0-beta.34 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Sep 20:18

Release of mcpg-sensitive at v0.1.0-beta.34.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.34" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.34 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.28

v0.1.0-beta.28 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 20 Sep 23:31

Release of mcpg-sensitive at v0.1.0-beta.28.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.28" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.28 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.27

v0.1.0-beta.27 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 18 Sep 21:36

Release of mcpg-sensitive at v0.1.0-beta.27.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.27" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.27 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.26

v0.1.0-beta.26 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 14 Sep 04:39

Release of mcpg-sensitive at v0.1.0-beta.26.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.26" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.26 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.25

v0.1.0-beta.25 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 14 Sep 00:35

Release of mcpg-sensitive at v0.1.0-beta.25.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.25" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.25 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.24

v0.1.0-beta.24 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 12 Sep 22:47

Release of mcpg-sensitive at v0.1.0-beta.24.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.24" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.24 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.23

v0.1.0-beta.23 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Sep 19:35

Release of mcpg-sensitive at v0.1.0-beta.23.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-sensitive = { git = "https://github.com/mcpg-dev/mcpg-sensitive", tag = "v0.1.0-beta.23" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-sensitive --tag v0.1.0-beta.23 mcpg-sensitive, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-sensitive

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>