Repository navigation
Releases: pegma-dev/spine
Releases · pegma-dev/spine
Release list
v0.1.2
Security scan dispositions for 2026-07-29 (PR #2).
- Pin the release npm bootstrap by tarball digest (FINDING-002). The preparation job now downloads
npm-11.18.0.tgz, checks it against a committed SHA-256 digest, and installs from the verified file, so the one install not already covered bypackage-lock.jsonintegrity hashes is pinned by bytes rather than registry metadata. A regression test asserts the digest check precedes the install. - Correct the published-state disclaimer in both READMEs (FINDING-004). The shipped package README no longer tells consumers that Pegma's packages are unpublished, while keeping the unstable-API and not-production-ready warnings.
FINDING-001 and FINDING-003 were examined and disputed; the reasoning is recorded in docs/securityscan.md. No public API changed.
v0.1.1
No API or behaviour changes.
This release exercises the publish pipeline end to end. It is the first
@pegma package published from CI on a short-lived OIDC credential rather
than a token, and the first carrying a provenance attestation linking the
published tarball to the commit and workflow run that produced it.