v0.4.4
Highlights
- SBOM HTML report — releases now attach
onmsctl-v0.4.4-sbom-report.html, the CycloneDX SBOM rendered by blitsbom into one self-contained page that works offline: browse the shipped components and licenses without any SBOM tooling (#90, #91). - SLSA build provenance — binaries, SBOM, checksums and the container image carry GitHub-issued provenance attestations; verify any downloaded artifact with
gh attestation verify <file> --repo no42-org/onmsctl(#81). - Supply-chain hardening — container base images are digest-pinned, and RUSTSEC-2026-0185 (
quinn-proto; pulled in via reqwest but never compiled into the shipped binary, so not exploitable) is cleared from the lockfile (#83). - Preview channel — every merge to
mainnow publishes a signedghcr.io/no42-org/onmsctl:rcimage and a rollingpreviewprerelease with binaries for all four targets, so a fix can be tested ahead of a release. Verification recipes are in RELEASING.md (#85).
No CLI behaviour changes — this release is supply-chain and release-infrastructure work plus routine dependency updates.