v0.1.0
0.1.0 (2026-09-30)
Features
- add ignore TLS support for actions (5e6ad55)
- added cleanup support for issues (0fba32a)
- major UI update (05285ba)
- updated support for github, forgejo and mattermost (0b25e27)
Bug Fixes
Documentation
- add artifact signature verification (4cccefa)
Docker image
ghcr.io/wenisch-tech/smtp2x:0.1.0
ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61
Helm chart
helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.1.0SBOM
CycloneDX JSON and XML SBOMs are attached as smtp2x-0.1.0-sbom.json and smtp2x-0.1.0-sbom.xml.
Signature and attestation verification
The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.
Verify the image signature:
cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the build provenance:
gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:7f58cb59ff82ada268a5f82c7895a4277ede4c24a2d6aecd26d3343d14708c61 \
--repo wenisch-tech/SMTP2XVerify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:
cosign verify-blob smtp2x-0.1.0.tgz \
--bundle smtp2x-0.1.0.tgz.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"Verify the application JAR in the same way:
cosign verify-blob smtp2x-0.1.0.jar \
--bundle smtp2x-0.1.0.jar.cosign.bundle \
--certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"