Skip to content

Releases: pegma-dev/spine

Release list

v0.1.2

Choose a tag to compare

@FlyOverCoderKY FlyOverCoderKY released this 30 Jul 00:41
v0.1.2
838aa14

Security scan dispositions for 2026-07-29 (PR #2).

  • Pin the release npm bootstrap by tarball digest (FINDING-002). The preparation job now downloads npm-11.18.0.tgz, checks it against a committed SHA-256 digest, and installs from the verified file, so the one install not already covered by package-lock.json integrity hashes is pinned by bytes rather than registry metadata. A regression test asserts the digest check precedes the install.
  • Correct the published-state disclaimer in both READMEs (FINDING-004). The shipped package README no longer tells consumers that Pegma's packages are unpublished, while keeping the unstable-API and not-production-ready warnings.

FINDING-001 and FINDING-003 were examined and disputed; the reasoning is recorded in docs/securityscan.md. No public API changed.

v0.1.1

Choose a tag to compare

@FlyOverCoderKY FlyOverCoderKY released this 26 Jul 06:12

No API or behaviour changes.

This release exercises the publish pipeline end to end. It is the first
@pegma package published from CI on a short-lived OIDC credential rather
than a token, and the first carrying a provenance attestation linking the
published tarball to the commit and workflow run that produced it.