What's Changed
- Shared setup sidebar on every scenario page by @mrwadams in #69
- docs: collapse lengthy release notes into a collapsible section by @mrwadams in #71
- fix(security): cut scan noise and clear the actionable image CVEs by @mrwadams in #73
- fix(security): stop Trivy reporting pip's vendored SBOM as installed packages by @mrwadams in #74
- chore(deps): let Dependabot track GitHub Actions by @mrwadams in #75
- feat(docker): move base image to python 3.14-slim by @mrwadams in #82
- chore(deps): move all actions off the Node 20 runtime by @mrwadams in #83
- fix(security): make the Bandit step gate on something by @mrwadams in #84
- fix(security): make pip-audit gate, drop the Safety step by @mrwadams in #85
- feat(mcp): migrate the MCP server to the mcp 2.x SDK by @mrwadams in #86
- Local runs without a secrets.toml crash on st.secrets access (feedback widget) by @mrwadams in #72
- Neutral, dead-end-free threat-group and case-study selectors by @mrwadams in #87
- Base-scenario-first phased generation by @mrwadams in #88
- release: bump version to 0.16.0 by @mrwadams in #90
Full Changelog: v0.15.0...v0.16.0