Skip to content

Releases: sebastienrousseau/passmcp-reporting

passmcp-reporting 0.0.5

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:39
v0.0.5
2ff2f2b

Highlights ⭐️

  • The agentgateway processor serves TLS: -tls-cert and -tls-key put its gRPC listener behind TLS 1.2 or later, and SIGHUP or -reload-interval picks up a rotated key pair without a restart.
  • Safer denials: the processor no longer follows a redirect off https, and a denial no longer repeats the attestation URL or quotes unbounded server text.
  • A security model and a way to verify releases: docs/security-model.md sets out the threat model and a dated security review, and docs/signing.md shows how to check a tag's signature and the processor image's provenance.
  • In lockstep with passmcp 0.0.5, the family's fifth release. What Validate accepts is unchanged; sha512 subject digests (#10) follow in 0.0.6 after their notice week.

What's Changed

Checksums

This release attaches no downloadable assets.

The agentgateway processor is published as a container image instead: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.5 is sha256:ea8d0f739411de6e2ed9f66bb9ddd6de51ada152589e408152ab455acb7e9157, with SLSA build provenance attached to the digest.

Full Changelog: v0.0.4...v0.0.5

agentgateway-extmcp 0.0.5

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:39
integrations/agentgateway-extmcp/v0.0.5
2ff2f2b

Highlights ⭐️

  • TLS on the gRPC listener: -tls-cert and -tls-key serve the processor over TLS 1.2 or later, and SIGHUP or -reload-interval loads a rotated key pair without a restart; a pair that fails to load is logged and the one in service stays.
  • Safer fetches and denials: an https attestation URL that redirects off https is refused, and a denial no longer repeats the attestation URL or quotes unbounded server text.
  • Install or run it: go install satellion.com/passmcp-reporting/integrations/agentgateway-extmcp/cmd/agentgateway-extmcp@v0.0.5, or the multi-arch image ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.5, published with SLSA build provenance.

What's Changed

Checksums

This release attaches no downloadable assets.

The processor is published as a container image: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.5 is sha256:ea8d0f739411de6e2ed9f66bb9ddd6de51ada152589e408152ab455acb7e9157, with SLSA build provenance attached to the digest.

Full Changelog: integrations/agentgateway-extmcp/v0.0.4...integrations/agentgateway-extmcp/v0.0.5

passmcp-reporting 0.0.4

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:01
v0.0.4
9151a7b

Highlights ⭐️

  • A demo in the README: the verifier checking a sample MCP attestation and a sample A2A attestation offline, and reporting each one's score and failing check.
  • Release pages without hand edits: the release workflow now publishes each page in the family layout, highlights, generated changes and checksums included.
  • In lockstep with passmcp 0.0.4, the family's fourth release.

What's Changed

Checksums

This release attaches no downloadable assets.

The agentgateway processor is published as a container image instead: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.4 is sha256:eba48111e6e21e07631ced5e5883dd8af2dbb76740b5566c78229a96af2c83fa, with SLSA build provenance attached to the digest.

Full Changelog: v0.0.3...v0.0.4

passmcp-reporting 0.0.3

Choose a tag to compare

@github-actions github-actions released this 30 Sep 02:58
v0.0.3
665fc28

Highlights ⭐️

  • Nothing you import changed: The attestation, A2A and graph packages, their schemas and predicates are the 0.0.2 ones, and Validate accepts exactly what it accepted. This release carries the family's version.
  • The parsers are fuzzed: attestation.Parse and graph.Parse now have native Go fuzz targets. They check that no input panics the parser and that every statement or graph it accepts encodes and parses back to the same bytes.

What's Changed

Checksums

This release attaches no downloadable assets.

The agentgateway processor is published as a container image instead: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.3 is sha256:b53406ff4bd2d06429e0e98a87c16be300c99a9d42bcc9feea31023bf98ea391, with SLSA build provenance attached to the digest.

Full Changelog: v0.0.2...v0.0.3

agentgateway-extmcp 0.0.4

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:01
integrations/agentgateway-extmcp/v0.0.4
9151a7b

Highlights ⭐️

  • Unchanged behaviour: the processor admits and denies exactly what 0.0.3 did; it moves with the family's version.
  • Its own release page: the release workflow now publishes this module's page itself, in the family layout, with the image digest.
  • Install or run it: go install satellion.com/passmcp-reporting/integrations/agentgateway-extmcp/cmd/agentgateway-extmcp@v0.0.4, or the multi-arch image ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.4, published with SLSA build provenance.

What's Changed

Checksums

This release attaches no downloadable assets.

The processor is published as a container image: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.4 is sha256:eba48111e6e21e07631ced5e5883dd8af2dbb76740b5566c78229a96af2c83fa, with SLSA build provenance attached to the digest.

Full Changelog: integrations/agentgateway-extmcp/v0.0.3...integrations/agentgateway-extmcp/v0.0.4

agentgateway-extmcp 0.0.3

Choose a tag to compare

@sebastienrousseau sebastienrousseau released this 30 Sep 03:15
integrations/agentgateway-extmcp/v0.0.3
665fc28

Highlights ⭐️

  • Unchanged, released with the family: The processor admits and denies exactly what 0.0.2 did, and still requires satellion.com/passmcp-reporting v0.0.1. This release carries the family's version.
  • Install or run it: go install satellion.com/passmcp-reporting/integrations/agentgateway-extmcp/cmd/agentgateway-extmcp@v0.0.3, or the multi-arch image ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.3, published with SLSA build provenance.

What's Changed

Checksums

This release attaches no downloadable assets.

The processor is published as a container image: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.3 is sha256:b53406ff4bd2d06429e0e98a87c16be300c99a9d42bcc9feea31023bf98ea391, with SLSA build provenance attached to the digest.

Full Changelog: integrations/agentgateway-extmcp/v0.0.2...integrations/agentgateway-extmcp/v0.0.3

passmcp-reporting 0.0.2

Choose a tag to compare

@github-actions github-actions released this 29 Sep 21:46
v0.0.2
6ef19bc

Highlights ⭐️

  • Nothing you import changed: The attestation, A2A and graph packages, their schemas and predicates are the 0.0.1 ones, and Validate accepts exactly what it accepted. This release carries the family's version.
  • The gateway processor builds against a real release: Its go.mod requires the tagged satellion.com/passmcp-reporting v0.0.1 rather than a pseudo-version of an untagged commit, and the release check refuses a pseudo-version from now on.
  • A coverage badge measured by CI: The README's coverage figure is written from the cover profile on every push to main, never typed by hand.

What's Changed

Checksums

This release attaches no downloadable assets.

The agentgateway processor is published as a container image instead: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.2 is sha256:ceeca186ef9c176a76364f42aa74d6678b39dd12f6bde451ae919d495d530dd0, with SLSA build provenance attached to the digest.

Full Changelog: v0.0.1...v0.0.2

passmcp-reporting 0.0.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 11:34
v0.0.1
ee5800a

Highlights ⭐️

  • Verify a passmcp attestation offline: The in-toto statement passmcp writes about an MCP server, its JSON Schema, and the verifier a gateway, registry or CI system embeds to check one, with no network and no dependency outside the standard library.
  • The security graph's data model: Agents, MCP servers, tools, identities and attestations, with IDs derived from what each node is, so ingesting the same evidence twice changes nothing. passmcp-graph stores it and passmcp's discovery writes into it.
  • A2A evaluations: The same envelope and verdicts about an agent that speaks the Agent2Agent protocol, under its own predicate type, so an MCP-only consumer refuses it rather than misreading it.
  • A gateway that enforces them: The agentgateway processor denies MCP backends whose attestation is missing, invalid or below policy, and is released alongside this module as its own tag and image.

What's Changed

  • build(integration): use the published module by @sebastienrousseau in #4
  • chore(release): passmcp-reporting 0.0.1 by @sebastienrousseau in #5
  • chore(actions): Bump the github-actions group across 1 directory with 2 updates by @dependabot[bot] in #3
  • chore(deps): Bump google.golang.org/protobuf from 1.36.11 to 1.36.12 by @dependabot[bot] in #2
  • chore(deps): Bump google.golang.org/grpc from 1.83.2 to 1.84.0 by @dependabot[bot] in #1

New Contributors

Checksums

This release attaches no downloadable assets.

The agentgateway processor is published as a container image instead: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.1 is sha256:81b3ad237a1c1e971df6fb58c1ead018f31cff0d34c84f625ee929c4921f7357, with SLSA build provenance attached to the digest.

Full Changelog: https://github.com/sebastienrousseau/passmcp-reporting/commits/v0.0.1

agentgateway-extmcp 0.0.2

Choose a tag to compare

@sebastienrousseau sebastienrousseau released this 29 Sep 22:06
integrations/agentgateway-extmcp/v0.0.2
6ef19bc

Highlights ⭐️

  • Built against the released verifier: The processor's go.mod requires satellion.com/passmcp-reporting v0.0.1, a tagged release, instead of a pseudo-version of an untagged commit. What it admits and denies is unchanged.
  • A client can no longer crash it: gRPC moves to v1.83.2, which fixes GO-2026-6443 (CVE-2026-84445), a server panic on a request with no :authority or Host header. The v1.84 line has no fixed release yet.
  • Install or run it: go install satellion.com/passmcp-reporting/integrations/agentgateway-extmcp/cmd/agentgateway-extmcp@v0.0.2, or the multi-arch image ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.2, published with SLSA build provenance.

What's Changed

Checksums

This release attaches no downloadable assets.

The processor is published as a container image: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.2 is sha256:ceeca186ef9c176a76364f42aa74d6678b39dd12f6bde451ae919d495d530dd0, with SLSA build provenance attached to the digest.

Full Changelog: integrations/agentgateway-extmcp/v0.0.1...integrations/agentgateway-extmcp/v0.0.2

agentgateway-extmcp 0.0.1

Choose a tag to compare

@sebastienrousseau sebastienrousseau released this 29 Sep 12:11
integrations/agentgateway-extmcp/v0.0.1
ee5800a

Highlights ⭐️

  • Gate MCP backends on passmcp attestations: An agentgateway mcpGuardrails processor that verifies one attestation per backend offline at startup and denies a backend whose statement is missing, invalid, about another endpoint, below the score floor, or failing a disqualifying category, with a reason that names it.
  • Install or run it: go install satellion.com/passmcp-reporting/integrations/agentgateway-extmcp/cmd/agentgateway-extmcp@v0.0.1, or the multi-arch image ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.1, published with SLSA build provenance.

What's Changed

  • build(integration): use the published module by @sebastienrousseau in #4
  • chore(release): passmcp-reporting 0.0.1 by @sebastienrousseau in #5
  • chore(actions): Bump the github-actions group across 1 directory with 2 updates by @dependabot[bot] in #3
  • chore(deps): Bump google.golang.org/protobuf from 1.36.11 to 1.36.12 by @dependabot[bot] in #2
  • chore(deps): Bump google.golang.org/grpc from 1.83.2 to 1.84.0 by @dependabot[bot] in #1

New Contributors

Checksums

This release attaches no downloadable assets.

The processor is published as a container image: ghcr.io/sebastienrousseau/passmcp-agentgateway-extmcp:0.0.1 is sha256:81b3ad237a1c1e971df6fb58c1ead018f31cff0d34c84f625ee929c4921f7357, with SLSA build provenance attached to the digest.

Full Changelog: https://github.com/sebastienrousseau/passmcp-reporting/commits/integrations/agentgateway-extmcp/v0.0.1