v0.1.2
Security scan remediation (docs/securityscan.md, 2026-07-28 scan). No adapter behavior or public API change.
- Publish pipeline:
preparepins the SHA-256 of the preparedpackage-manifest.jsonas a job output andpublishverifies the downloaded manifest against it, so the file that authenticates every tarball hash is no longer checked only against itself. - Publish pipeline: the reviewed npm release is installed from a digest-pinned tarball (verified SHA-512) instead of a version resolved from the registry at run time.
- Added
.github/dependabot.ymlfor monthly npm and GitHub Actions updates. - Added
SECURITY.mdwith the private vulnerability reporting channel, supported versions, and the adapters' documented non-guarantees. - Workflow property tests in
tests/release-packages.test.tscover both pipeline changes.