Skip to content

Releases: wenisch-tech/SMTP2X

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:32

0.4.0 (2026-10-01)

Features

  • allow editing of actions after creation (e9b2f88)

Bug Fixes

  • fixed mapping of OIDC Roles so users with assigned Roles are not stuck in pending (829ff40)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.4.0
ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.4.0

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.4.0-sbom.json and smtp2x-0.4.0-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.4.0.tgz \
  --bundle smtp2x-0.4.0.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.4.0.jar \
  --bundle smtp2x-0.4.0.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 01 Oct 12:44

0.3.1 (2026-10-01)

Bug Fixes

  • fixed proble authmode not properly set for SMTP (b84ee55)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.3.1
ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.3.1

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.3.1-sbom.json and smtp2x-0.3.1-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:9639c8fc8cacd085c604be4cd3ed9cfcce1b6974ce2658e3e00353a9d6ade7ae \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.3.1.tgz \
  --bundle smtp2x-0.3.1.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.3.1.jar \
  --bundle smtp2x-0.3.1.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:19

0.3.0 (2026-10-01)

Features

Bug Fixes

  • fixed metrics for cleanup (97d1410)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.3.0
ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.3.0

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.3.0-sbom.json and smtp2x-0.3.0-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:b37abd0722f5bc33c23a796d86b886e3de4f59a55db0ac969aa0f33f4a2be121 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.3.0.tgz \
  --bundle smtp2x-0.3.0.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.3.0.jar \
  --bundle smtp2x-0.3.0.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.2.3

Choose a tag to compare

@github-actions github-actions released this 01 Oct 09:43

0.2.3 (2026-10-01)

Bug Fixes

  • improvements livenessprobe (f4a196c)
  • updated permissions for volume (db978cd)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.2.3
ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.3

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.3-sbom.json and smtp2x-0.2.3-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:650e96284caf4b40162fc41ae97f75ba4e1cc1571b927af6795b7cc11cdb768b \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.2.3.tgz \
  --bundle smtp2x-0.2.3.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.2.3.jar \
  --bundle smtp2x-0.2.3.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.2.2

Choose a tag to compare

@github-actions github-actions released this 01 Oct 08:44

0.2.2 (2026-10-01)

Bug Fixes

Docker image

ghcr.io/wenisch-tech/smtp2x:0.2.2
ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.2

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.2-sbom.json and smtp2x-0.2.2-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:56a689c08d10b24b4f49818a9a236e4ae550722f5314b421a3e8a2594a60c2a5 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.2.2.tgz \
  --bundle smtp2x-0.2.2.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.2.2.jar \
  --bundle smtp2x-0.2.2.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 01 Oct 08:26

0.2.1 (2026-10-01)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.2.1
ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.1

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.1-sbom.json and smtp2x-0.2.1-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:8bb5e45927ce2f90f339fd1828c71003b298bcdc29fd90b33ae5ce00934a71e2 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.2.1.tgz \
  --bundle smtp2x-0.2.1.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.2.1.jar \
  --bundle smtp2x-0.2.1.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 07:51

0.2.0 (2026-10-01)

Features

  • added IGNORE_TLS FLag for OIDC (6f95968)

Bug Fixes

  • Added ingress and example for OIDC Configuration (160b8f3)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.2.0
ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.2.0

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.2.0-sbom.json and smtp2x-0.2.0-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:6e8d83d1332bad79e3b213404ccb2ce95681196c3f3b5a649eb56b7dcfb70194 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.2.0.tgz \
  --bundle smtp2x-0.2.0.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.2.0.jar \
  --bundle smtp2x-0.2.0.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.1.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 20:44

0.1.2 (2026-09-30)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.1.2
ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.2

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.2-sbom.json and smtp2x-0.1.2-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:c3ec0fbf65aab276d9bf1f147e2ecfafff949ab55864bb12e3814f890423ce62 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.1.2.tgz \
  --bundle smtp2x-0.1.2.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.1.2.jar \
  --bundle smtp2x-0.1.2.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 20:33

0.1.1 (2026-09-30)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.1.1
ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.1

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.1-sbom.json and smtp2x-0.1.1-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:cafb013633435c08adc82ca4d3451a001ebe6f8444dc53d47bfd3887d9a031dd \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.1.1.tgz \
  --bundle smtp2x-0.1.1.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.1.1.jar \
  --bundle smtp2x-0.1.1.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 20:26

0.1.0 (2026-09-30)

Features

  • add ignore TLS support for actions (5e6ad55)
  • added cleanup support for issues (0fba32a)
  • major UI update (05285ba)
  • updated support for github, forgejo and mattermost (0b25e27)

Bug Fixes

Documentation

  • add artifact signature verification (4cccefa)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.1.0
ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.0

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.0-sbom.json and smtp2x-0.1.0-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.1.0.tgz \
  --bundle smtp2x-0.1.0.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.1.0.jar \
  --bundle smtp2x-0.1.0.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"