Skip to content

v0.4.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:32

0.4.0 (2026-10-01)

Features

  • allow editing of actions after creation (e9b2f88)

Bug Fixes

  • fixed mapping of OIDC Roles so users with assigned Roles are not stuck in pending (829ff40)

Docker image

ghcr.io/wenisch-tech/smtp2x:0.4.0
ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5

Helm chart

helm install smtp2x oci://ghcr.io/wenisch-tech/helm-charts/smtp2x --version 0.4.0

SBOM

CycloneDX JSON and XML SBOMs are attached as smtp2x-0.4.0-sbom.json and smtp2x-0.4.0-sbom.xml.

Signature and attestation verification

The image and release artifacts are signed keylessly with Sigstore Cosign. The container also has GitHub build provenance attached.

Verify the image signature:

cosign verify ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the build provenance:

gh attestation verify oci://ghcr.io/wenisch-tech/smtp2x@sha256:718fc3a0f576044ba3ef610615fd591f69d1f36a71956f41f9a4fe14f282f4e5 \
  --repo wenisch-tech/SMTP2X

Verify the Helm chart signature after downloading the chart and its .cosign.bundle from this release:

cosign verify-blob smtp2x-0.4.0.tgz \
  --bundle smtp2x-0.4.0.tgz.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Verify the application JAR in the same way:

cosign verify-blob smtp2x-0.4.0.jar \
  --bundle smtp2x-0.4.0.jar.cosign.bundle \
  --certificate-identity-regexp="https://github.com/wenisch-tech/SMTP2X" \
  --certificate-oidc-issuer="https://token.actions.githubusercontent.com"