Skip to content

[codex] Release sbom-diff-and-risk v0.5.0#19

Merged
stacknil merged 1 commit into
mainfrom
codex/release-v0.5.0
Apr 27, 2026
Merged

[codex] Release sbom-diff-and-risk v0.5.0#19
stacknil merged 1 commit into
mainfrom
codex/release-v0.5.0

Conversation

@stacknil
Copy link
Copy Markdown
Owner

Summary

Cuts the sbom-diff-and-risk package line to v0.5.0 for the GitHub Release.

This keeps production PyPI intentionally deferred. No .github/workflows/sbom-diff-and-risk-pypi.yml workflow is added, and no production PyPI upload path is enabled.

Changes

  • Bumps pyproject.toml package metadata to 0.5.0.
  • Syncs sbom_diff_risk.__version__ to 0.5.0.
  • Updates sample SARIF driver metadata to 0.5.0.
  • Updates the README top-level v0.5.0 release narrative.
  • Adds RELEASE_NOTES_v0.5.0.md.
  • Keeps the production PyPI decision gate deferred/conditional while acknowledging the GitHub Release version bump.

Release note boundary

The v0.5.0 release notes explicitly state: TestPyPI dry-run completed; production PyPI intentionally deferred.

Verification

  • python -m build
  • python -m twine check dist/*
  • python -m pytest
  • git diff --check
  • Confirmed .github/workflows/ still has no production PyPI workflow.

@stacknil stacknil merged commit 0012cc5 into main Apr 27, 2026
9 checks passed
@stacknil stacknil deleted the codex/release-v0.5.0 branch April 27, 2026 03:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant