Repository navigation
0.1.2 - 2026-09-30
Release Notes
Added
- Releases attach a CycloneDX SBOM (
fideslang-cli.cdx.xml) generated bycargo-cyclonedx. - Every release publishes
fideslang-clito crates.io:release.ymlcallspublish-crate.ymlas
a dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (OIDC, no
stored secret), skips a version that is already published, and can be run by hand with a tag. - OpenSSF Scorecard workflow and README badge.
CITATION.cff, issue forms, pull request template andCODEOWNERS;docs/demo.tape(VHS script
for a README demo).
Changed
- README restructured: install (Homebrew, release archives), how to verify an archive with
gh attestation verifyand its SHA-256 file, a zero-config quick start, limitations, output
formats and exit codes, citation and trust sections. - The crate is published on crates.io as
fideslang-cli: README shows its badge and the
cargo binstall/cargo installlines. It no longer advertises thecurl | shinstaller. - Crate description and categories updated (
parser-implementationsreplacesdata-structures). release.ymlgrantscontents: writeonly to the jobs that create and upload the release.SECURITY.mdlinks GitHub private vulnerability reporting directly.
Install fideslang-cli 0.1.2
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.2/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.1.2
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools