Skip to content

Releases: openhoo/hooray

hooray 0.9.0

Choose a tag to compare

@github-actions github-actions released this 22 Sep 15:28
7f706fe

0.9.0 (2026-09-22)

Features

  • scanners: IaC checks for docker-compose and GitHub Actions (3a6cbe6)

Bug Fixes

  • parsers: resolve lockfile edge, scope, and abort defects from audit (985a893)
  • reports: harden SBOM ingestion, renderers, model, monitor, and store (362111e)
  • parity: harden corpus loading, comparison keys, gates, and recording validation (7767d39)
  • parsers: harden archive readers and expose OCI filesystem builder (99a1f78)
  • engine: harden OSV matching, graph classification, and input handling (0a5caaa)
  • scanners: close audit findings in secret, IaC, service-config, SAST, and license (9ec9d45)
  • parsers: resolve quoted and multi-version Yarn classic dependencies (9a7fa8a)
  • store: require FULL synchronous for commit durability (35e3491)
  • risk: rank Unknown severity above Low in severity_points (43cee0a)
  • input: bound serde_yaml alias expansion on untrusted lockfiles (9a24589)
  • parsers: accept multi-document pnpm-lock.yaml (#337) (2f1cd6f)

Other Changes

  • ci: align dependabot naming with hoolicy policy (#116) (de8f062)
  • parity: harden recording integrity and corpus coverage assertions (54112a3)
  • bump actions/github-script from 8.0.0 to 9.0.0 (#117) (847f10b)
  • bump rusqlite from 0.37.0 to 0.40.2 (#118) (776a160)
  • bump zstd from 0.13.3 to 0.14.0 (#119) (1c59e21)
  • bump toml from 0.9.12+spec-1.1.0 to 1.1.6+spec-1.1.0 (#120) (9ed037b)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:c3c68627c7a3ae00afd9c388e71e25f5d3847649818c1ed06bbeb9cb0feec44e

hooray 0.8.0

Choose a tag to compare

@github-actions github-actions released this 18 Sep 20:31
e7374b1

0.8.0 (2026-09-18)

Features

  • cli: add --offline flag matching documented behavior (#34) (4097058)
  • parsers: support Bun text lockfiles (#38) (945dda9)
  • parsers: add Chart.lock, composer.lock, and NuGet CPM/csproj/packages.config parsers (#52) (3b51a20)
  • parsers: add Gradle lockfile, Maven pom.xml, and Go stdlib toolchain coverage (#84) (62f91f6)
  • parsers: inventory Cabal dependencies and freeze pins (#103) (bc68185)
  • parsers: add Mix lockfile parser for Hex dependencies (#101) (e8ec136)
  • parsers: inventory Gradle version catalog declarations (#104) (190b85f)

Bug Fixes

  • scanner: exclude VCS metadata directories from repository walk (#35) (4a55ccd)
  • scanner: honor usedforsecurity=False in Python weak-hash rules (#36) (92f1172)
  • parsers: anchor asset identity to root lockfile (#37) (200232a)
  • scanners: tolerate JSONC/BOM IaC JSON, detect encrypted PEMs, skip regex literals (#51) (5e275b1)
  • parsers: pnpm v9 edges/scopes, specifier phantoms, bun asset identity (#53) (191e043)
  • core: OCI layer decompression, shared dependency-path index, honest introduced:0 (#54) (b5c2ca7)
  • cli: scope --format enums per subcommand; fix monitor target display and errors (#80) (b5a389c)
  • parsers: tolerate versionless SBOM entries, ./ tar roots, compressed tarballs (#82) (d3e7f2e)
  • parsers: indent-aware bundler/pod specs, poetry groups, honest unpinned versions (#81) (3961a76)
  • scanners: IaC anchoring/coverage, secret placeholder filtering, polyglot and SAST FPs (#83) (e5bb809)
  • parsers: preserve Composer lockfile licenses (#97) (228d4a8)
  • parsers: retain versioned yarn descriptor identities (#98) (57ea15f)
  • scanners: structure-aware PE recognition, escaped PEM detection, credential-shape suppression (#100) (82303be)
  • parsers: support legacy per-configuration Gradle lockfiles (#99) (f086600)
  • parsers: preserve Composer lockfile dependency edges (#102) (0c9de34)
  • parsers: exclude Maven template placeholders and record unresolved declarations (#105) (8d1085a)

Other Changes

  • issues: port issue governance and exploratory-smoke campaign skills (#28) (e6533f9)
  • ci: adopt Hoolicy v0.3.2 action check (#107) (6ed727c)
  • ci: adopt Hoonarqube v0.8.2 analyze action (#108) (878d667)
  • deps: bump tower-http from 0.6.11 to 0.7.1 (#109) (25a8cf2)
  • deps: bump sha2 from 0.10.9 to 0.11.0 (#110) (e3bc6df)
  • deps: bump spdx from 0.10.9 to 0.13.5 (#111) (cbfe559)
  • deps: bump jsonschema from 0.47.0 to 0.56.0 (#112) (0575b91)
  • deps: bump zip from 4.6.1 to 8.6.0 (#113) (cac74fa)
  • release: adopt Hooversion v1.1.2 for squash-suffix release resume (#114) (91b32d6)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:50e7e99304cd7345538a88caa4582f2d462f52f021035cf8ab1355267b8d3119

hooray 0.6.6

Choose a tag to compare

@github-actions github-actions released this 08 Sep 11:28
26aeb8c

0.6.6 (2026-09-08)

Bug Fixes

  • integrations: make GitHub and GitLab reporting portable (8fe0ba0)

Other Changes

  • ci: converge released tool pins (3cd3646)
  • ci: adopt Hoonarqube v0.3.1 (9e0d686)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:df7799f5b660f128e4ecb4c223dc2ea57a775562ebb4b069852f5f8621a86c5d

hooray 0.6.5

Choose a tag to compare

@github-actions github-actions released this 03 Sep 09:58
f2b28d7

0.6.5 (2026-09-03)

Bug Fixes

  • scanner: harden structural analysis and monitoring (0e49874)

Other Changes

  • ci: update Hoostack tool pins (#16) (d656407)
  • ci: adopt HooNeedsUpdates v0.3.0 (5118bfa)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:bc6db3324318d261561d3f569295f835ba4e751302f12866bbeeabc4e426a85e

hooray 0.6.4

Choose a tag to compare

@github-actions github-actions released this 31 Aug 12:43
5849431

0.6.4 (2026-08-31)

Bug Fixes

  • align Hoostack policy and release supply chain (5726283)
  • release: honor protected main branch (58dbc8a)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:d822a9a8614c7f80281ffa11649daf49b6f6fd2ed7b2311d146cb2a3724ad877

hooray 0.6.3

Choose a tag to compare

@github-actions github-actions released this 30 Aug 20:32

0.6.3 (2026-08-30)

Bug Fixes

Other Changes

  • standardize Hoostack dogfood (#11) (3dcdebb)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:4f695d0f20edbcb478f2d7a46753bb990ebf37c5a18b565e322bdc7b0d1d3c20

hooray 0.6.2

Choose a tag to compare

@github-actions github-actions released this 30 Aug 19:12

0.6.2 (2026-08-30)

Bug Fixes

  • scanner: make Hoostack dogfood reliable (c2fa797)
  • scanner: emit valid Swift package URLs (d80464e)
  • actions: default to next release (d07c069)

Other Changes

  • use released Hoostack actions (1f883e4)
  • test pull request head commit (1fdd4dd)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:67517e4bbd4ec6bccb8b4662e92d4ce32a699572b32ed7a50b56ce23e94ee2be

hooray 0.6.1

Choose a tag to compare

@github-actions github-actions released this 28 Aug 19:45

0.6.1 (2026-08-28)

Bug Fixes

  • harden runtime, persistence, and monitoring (3f3e632)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:85732b050a19c2f8cc9f463db594906c1b8e38f4ff156aea083a078a7e38e96b

hooray 0.6.0

Choose a tag to compare

@github-actions github-actions released this 26 Aug 11:45

0.6.0 (2026-08-26)

Other Changes

  • replace rot-prone test counts with stable coverage wording (e4277c6)
  • cut duplication and complexity hotspots (b70ddcf)

Features

  • restructure parsers, add parity harness, land review hardening (f7a0b09)

Bug Fixes

  • bound save-only bench by accumulated window (ece60ae)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:addca8cfced5938aedaac1ac8f8190f8f8974b6927269e8f73597a791fdc9f4e

hooray 0.5.1

Choose a tag to compare

@github-actions github-actions released this 25 Aug 13:15

0.5.1 (2026-08-25)

Bug Fixes

  • harden scanner after full-project agent review (a169b1f)
    Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:f9c7af24a901d8451873d17f9b08ba990aad4e67668fc8c8d4e13b80350b5b52