Releases: wenisch-tech/SMTP2X
Release list
v0.4.0
0.4.0 (2026-10-01)
Features
- allow editing of actions after creation (e9b2f88)
Bug Fixes
- fixed mapping of OIDC Roles so users with assigned Roles are not stuck in pending (829ff40)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.4.0
ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.4.0SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.4.0-sbom.json and smtp2x-0.4.0-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.4.0.tgz \
--bundle smtp2x-0.4.0.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.4.0.jar \
--bundle smtp2x-0.4.0.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.3.1
0.3.1 (2026-10-01)
Bug Fixes
- fixed proble authmode not properly set for SMTP (b84ee55)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.3.1
ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.3.1SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.3.1-sbom.json and smtp2x-0.3.1-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.3.1.tgz \
--bundle smtp2x-0.3.1.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.3.1.jar \
--bundle smtp2x-0.3.1.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.3.0
0.3.0 (2026-10-01)
Features
Bug Fixes
- fixed metrics for cleanup (97d1410)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.3.0
ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.3.0SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.3.0-sbom.json and smtp2x-0.3.0-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.3.0.tgz \
--bundle smtp2x-0.3.0.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.3.0.jar \
--bundle smtp2x-0.3.0.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.2.3
0.2.3 (2026-10-01)
Bug Fixes
Docker image
ghcr.io/wenisch-tech/smtp2x:0.2.3
ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.3SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.3-sbom.json and smtp2x-0.2.3-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.2.3.tgz \
--bundle smtp2x-0.2.3.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.2.3.jar \
--bundle smtp2x-0.2.3.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.2.2
0.2.2 (2026-10-01)
Bug Fixes
- update ing (5e3e0bf)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.2.2
ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.2SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.2-sbom.json and smtp2x-0.2.2-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.2.2.tgz \
--bundle smtp2x-0.2.2.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.2.2.jar \
--bundle smtp2x-0.2.2.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.2.1
0.2.1 (2026-10-01)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.2.1
ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.1SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.1-sbom.json and smtp2x-0.2.1-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.2.1.tgz \
--bundle smtp2x-0.2.1.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.2.1.jar \
--bundle smtp2x-0.2.1.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.2.0
0.2.0 (2026-10-01)
Features
- added IGNORE_TLS FLag for OIDC (6f95968)
Bug Fixes
- Added ingress and example for OIDC Configuration (160b8f3)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.2.0
ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.0SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.0-sbom.json and smtp2x-0.2.0-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.2.0.tgz \
--bundle smtp2x-0.2.0.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.2.0.jar \
--bundle smtp2x-0.2.0.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.1.2
0.1.2 (2026-09-30)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.1.2
ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.2SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.2-sbom.json and smtp2x-0.1.2-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.1.2.tgz \
--bundle smtp2x-0.1.2.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.1.2.jar \
--bundle smtp2x-0.1.2.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.1.1
0.1.1 (2026-09-30)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.1.1
ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.1SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.1-sbom.json and smtp2x-0.1.1-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.1.1.tgz \
--bundle smtp2x-0.1.1.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.1.1.jar \
--bundle smtp2x-0.1.1.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"v0.1.0
0.1.0 (2026-09-30)
Features
- add ignore TLS support for actions (5e6ad55)
- added cleanup support for issues (0fba32a)
- major UI update (05285ba)
- updated support for github, forgejo and mattermost (0b25e27)
Bug Fixes
Documentation
- add artifact signature verification (4cccefa)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.1.0
ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.0SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.0-sbom.json and smtp2x-0.1.0-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.1.0.tgz \
--bundle smtp2x-0.1.0.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.1.0.jar \
--bundle smtp2x-0.1.0.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"