Releases: mcpg-dev/mcpg
Release list
v0.1.0-beta.35
Release of mcpg at v0.1.0-beta.35.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.35" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.35 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.33
Release of mcpg at v0.1.0-beta.33.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.33" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.33 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.32
Release of mcpg at v0.1.0-beta.32.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.32" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.32 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.29
Release of mcpg at v0.1.0-beta.29.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.29" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.29 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.28
Release of mcpg at v0.1.0-beta.28.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.28" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.28 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.27
Release of mcpg at v0.1.0-beta.27.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.27" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.27 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.26
Release of mcpg at v0.1.0-beta.26.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.26" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.26 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.24
Release of mcpg at v0.1.0-beta.24.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.24" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.24 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.23
Release of mcpg at v0.1.0-beta.23.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.23" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.23 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>
v0.1.0-beta.20
Release of mcpg at v0.1.0-beta.20.
Issues are welcome; pull requests cannot be merged here — development happens upstream.
This crate is consumed by git reference — it is not published to crates.io:
[dependencies]
mcpg = { git = "https://github.com/mcpg-dev/mcpg", tag = "v0.1.0-beta.20" }(binaries: cargo install --git https://github.com/mcpg-dev/mcpg --tag v0.1.0-beta.20 mcpg, or use the packed assets below)
Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:
gh attestation verify <file> --repo mcpg-dev/mcpg
A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.
macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:
xattr -d com.apple.quarantine ./<binary>