Skip to content

Releases: pavancharak/parmana-sign

Release list

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 19:40
0da43df
Merge pull request #42 from pavancharak/claude/new-session-au5pw1

Fix release signing for cosign v3 (Sigstore bundle)

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 02 Aug 06:49
Add Scorecard, SLSA, and Sigstore hardening

- Pin all actions in ci.yml to a commit SHA (was tag-only)
- Add .github/dependabot.yml (npm + github-actions ecosystems)
- Add dependency-review.yml (actions/dependency-review-action on PRs)
- Add codeql.yml (CodeQL javascript-typescript analysis)
- Add scorecard.yml (OSSF Scorecard, publishes results + SARIF)
- Add release.yml: tagged (v*.*.*) releases build via npm ci, generate
  SLSA Build L3 provenance via the SLSA GitHub generator, and are
  signed keylessly with cosign via GitHub OIDC; tarball + provenance +
  signature + cert attached to the GitHub release
- Add RELEASING.md documenting the release process and exact
  slsa-verifier/cosign commands to verify a release independently
- README: add Scorecard badge, "Security & Supply Chain" section

All third-party actions pinned by SHA except the SLSA generic
generator's reusable workflow, which the SLSA project's own docs
require referencing by tag (their verifier checks the ref as part of
what it attests to) -- documented as an intentional exception in
release.yml's own comments.

No signing/verification logic, public API, or product behavior
changed. Repository/CI/release hardening only.