Skip to content

0.1.2 - 2026-09-30

Choose a tag to compare

@github-actions github-actions released this 01 Oct 05:46
9bfcc6c

Release Notes

Added

  • Releases attach a CycloneDX SBOM (fideslang-cli.cdx.xml) generated by cargo-cyclonedx.
  • Every release publishes fideslang-cli to crates.io: release.yml calls publish-crate.yml as
    a dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (OIDC, no
    stored secret), skips a version that is already published, and can be run by hand with a tag.
  • OpenSSF Scorecard workflow and README badge.
  • CITATION.cff, issue forms, pull request template and CODEOWNERS; docs/demo.tape (VHS script
    for a README demo).

Changed

  • README restructured: install (Homebrew, release archives), how to verify an archive with
    gh attestation verify and its SHA-256 file, a zero-config quick start, limitations, output
    formats and exit codes, citation and trust sections.
  • The crate is published on crates.io as fideslang-cli: README shows its badge and the
    cargo binstall / cargo install lines. It no longer advertises the curl | sh installer.
  • Crate description and categories updated (parser-implementations replaces data-structures).
  • release.yml grants contents: write only to the jobs that create and upload the release.
  • SECURITY.md links GitHub private vulnerability reporting directly.

Install fideslang-cli 0.1.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.2/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.1.2

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools