Immutable
release. Only release title and notes can be modified.
What's Changed
Fixes
- fix: make historical GitHub release backfills idempotent by @mldangelo-oai in #165
- fix: safely backfill legacy signed npm releases by @mldangelo-oai in #166
- fix: make missing scan artifact failures actionable by @mldangelo-oai in #167
Other changes
- [codex-security] Polish completed scan summary by @ianw-oai in #113
- feat: Automatically match scan comparisons by @ianw-oai in #114
- [codex-security] Remove scan error prefixes by @ianw-oai in #115
- [codex-security] Support nested Git repositories in scan snapshots by @ianw-oai in #116
- release: publish protected multi-architecture Codex Security images by @dc-oai in #17
- fix: read container manifest digests without broken pipes by @mldangelo-oai in #161
- fix: authenticate registry before image attestation by @mldangelo-oai in #162
- ci: modernize and harden container workflows by @mldangelo-oai in #163
- feat: automate verified npm and GitHub releases by @mldangelo-oai in #91
- fix: allow completion when no draft manifest exists yet (#73) by @onurtirpan in #83
- fix: keep scan output private through completion and exports by @mldangelo-oai in #118
- fix: salvage malformed optional remediation fields during finding recovery by @alarcritty in #159
- fix: consolidate contributor runtime-security hardening by @mldangelo-oai in #152
New Contributors
- @dc-oai made their first contribution in #17
- @onurtirpan made their first contribution in #83
- @alarcritty made their first contribution in #159
Full Changelog: npm-v0.1.4...npm-v0.1.5