Skip to content

v0.4.4

Choose a tag to compare

@github-actions github-actions released this 30 Jul 08:49
· 52 commits to main since this release
v0.4.4
8701122

Highlights

  • SBOM HTML report — releases now attach onmsctl-v0.4.4-sbom-report.html, the CycloneDX SBOM rendered by blitsbom into one self-contained page that works offline: browse the shipped components and licenses without any SBOM tooling (#90, #91).
  • SLSA build provenance — binaries, SBOM, checksums and the container image carry GitHub-issued provenance attestations; verify any downloaded artifact with gh attestation verify <file> --repo no42-org/onmsctl (#81).
  • Supply-chain hardening — container base images are digest-pinned, and RUSTSEC-2026-0185 (quinn-proto; pulled in via reqwest but never compiled into the shipped binary, so not exploitable) is cleared from the lockfile (#83).
  • Preview channel — every merge to main now publishes a signed ghcr.io/no42-org/onmsctl:rc image and a rolling preview prerelease with binaries for all four targets, so a fix can be tested ahead of a release. Verification recipes are in RELEASING.md (#85).

No CLI behaviour changes — this release is supply-chain and release-infrastructure work plus routine dependency updates.