Skip to content

v1.15.1 - quality badges and Sigstore release signing

Choose a tag to compare

@verivus-open verivus-open released this 29 May 01:14

Changes

  • Add OpenSSF Scorecard and Sigstore signed-release indicators to the README.
  • Add Sigstore keyless signing to installer release artifacts with checksums and bundles.
  • Document release artifact verification with cosign.
  • Include the sanitized Windows MCP gateway configuration example in public docs.
  • Add forward-only attribution guards to prevent future Claude/Anthropic co-author trailers.

Verification

  • CI, CodeQL, Code Quality, security, OpenSSF Scorecard, Dependency Graph, and Dependabot Updates are green for commit 8c51db1.