Releases: pavancharak/parmana-sign
Releases · pavancharak/parmana-sign
Release list
v0.2.0
v0.1.1
Add Scorecard, SLSA, and Sigstore hardening - Pin all actions in ci.yml to a commit SHA (was tag-only) - Add .github/dependabot.yml (npm + github-actions ecosystems) - Add dependency-review.yml (actions/dependency-review-action on PRs) - Add codeql.yml (CodeQL javascript-typescript analysis) - Add scorecard.yml (OSSF Scorecard, publishes results + SARIF) - Add release.yml: tagged (v*.*.*) releases build via npm ci, generate SLSA Build L3 provenance via the SLSA GitHub generator, and are signed keylessly with cosign via GitHub OIDC; tarball + provenance + signature + cert attached to the GitHub release - Add RELEASING.md documenting the release process and exact slsa-verifier/cosign commands to verify a release independently - README: add Scorecard badge, "Security & Supply Chain" section All third-party actions pinned by SHA except the SLSA generic generator's reusable workflow, which the SLSA project's own docs require referencing by tag (their verifier checks the ref as part of what it attests to) -- documented as an intentional exception in release.yml's own comments. No signing/verification logic, public API, or product behavior changed. Repository/CI/release hardening only.