Repository navigation
Releases: bomly-dev/bomly-cli
Release list
v0.28.2
What's Changed
- ci(release): shorten the release pipeline without dropping a check by @bomly-guy in #499
- feat(assurance): compare only declared measurements, each with a plain explanation by @bomly-guy in #498
- fix(test): keep Go's module and build caches when a test redirects HOME by @bomly-guy in #500
Full Changelog: v0.28.1...v0.28.2
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.28.1
What's Changed
- fix(release): attach provenance to the draft before the gate inspects it by @bomly-guy in #494
- feat(assurance): check SBOM interoperability before a tag, not after a release by @bomly-guy in #495
Full Changelog: v0.28.0...v0.28.1
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.28.0
What's Changed
- feat(assurance): three-stage release assurance framework with a published per-release report by @bomly-guy in #398
- fix(assurance): a claim names its files by path, with no stored checksum by @bomly-guy in #492
Full Changelog: v0.27.1...v0.28.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.27.1
What's Changed
- build(deps): bump go.opentelemetry.io/otel/sdk from 1.45.0 to 1.47.0 by @dependabot[bot] in #488
- build(deps): bump github.com/containerd/containerd/v2 from 2.3.5 to 2.3.6 by @dependabot[bot] in #489
- chore: build against a local SDK; the pre-push hook runs unit tests; AGENTS.md only by @bomly-guy in #490
- docs: the SDK's CLI compatibility job is opt-in; smoke goldens stop pinning the tool version by @bomly-guy in #491
Full Changelog: v0.27.0...v0.27.1
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.27.0
What's Changed
- docs: name the owning package in doc comments that still said sdk. by @bomly-guy in #477
- Adopt bomly-sdk v0.14 and emit the scan record by @bomly-guy in #483
- build(deps): bump anyio from 4.14.1 to 4.14.2 in /.github in the pip group across 1 directory by @dependabot[bot] in #478
- build(deps): bump actions/setup-java from 6.0.0 to 6.0.1 in the github-actions-patch group by @dependabot[bot] in #482
- build(deps): bump the github-actions-minor group with 4 updates by @dependabot[bot] in #481
- build(deps): bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.45.0 by @dependabot[bot] in #479
- build(deps): bump github.com/mark3labs/mcp-go from 1.0.0 to 1.1.1 in the gomod-minor group across 1 directory by @dependabot[bot] in #485
- build(deps): bump the pip group across 1 directory with 3 updates by @dependabot[bot] in #487
Full Changelog: v0.26.0...v0.27.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.26.0
What's Changed
- build(deps): bump github.com/containerd/containerd/v2 from 2.3.3 to 2.3.5 by @dependabot[bot] in #475
- refactor: adopt bomly-sdk v0.13.0's package split by @bomly-guy in #476
Full Changelog: v0.25.0...v0.26.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.25.0
What's Changed
- docs: plan the SDK maturity program (ADR-0036 through ADR-0039) by @bomly-guy in #411
- build: require Go 1.27 by @bomly-guy in #412
- docs: ADR-0041 — identity is the canonical PURL on typed graph nodes by @bomly-guy in #413
- docs: ADR-0041 clarifications recorded at implementation by @bomly-guy in #414
- feat!: adopt the typed graph node union (bomly-sdk v0.9.0, ADR-0041) by @bomly-guy in #423
- chore: pin bomly-sdk v0.9.1, and describe how releases actually happen by @bomly-guy in #427
- refactor: SPDX expression handling is the SDK's, not a local wrapper (phase 2.2) by @bomly-guy in #428
- feat(sbom): unrecognized licenses export as LicenseRef, not free text (phase 2.4 + SDK v0.9.2) by @bomly-guy in #429
- feat(sbom): preserve what a source document asserted, on ingest and on export (closes #396) by @bomly-guy in #430
- feat(sbom): export the whole scope set, and refuse a document that reads two ways by @bomly-guy in #431
- feat(sbom): adopt SDK v0.9.6 scope semantics, resolve ADR-0037, record ADR-0043 by @bomly-guy in #441
- refactor(output): one home for the registry lookup every presentation surface was writing out (phase 2.7) by @bomly-guy in #437
- feat(detectors): record which module root each location belongs to (phase 2.8, producer half) by @bomly-guy in #439
- Phase 3: finish and guard the PURL delegation, and truth up the model docs by @bomly-guy in #436
- fix(sbom): read the end-of-life claim back, in both formats by @bomly-guy in #438
- feat(sbom): adopt SDK v0.9.7 and close eight limitations by @bomly-guy in #440
- fix(sbom): the digest vocabulary is the SDK registry's, not local tables by @bomly-guy in #443
- fix(test): a guard file may name the module it forbids by @bomly-guy in #444
- test: update smoke golden files by @github-actions[bot] in #447
- refactor: run the Go 1.27 modernizer (go fix) across the repo by @bomly-guy in #448
- refactor(detectors): the SDK decides every detector's purl type by @bomly-guy in #446
- test(smoke): goldens stop carrying the host architecture by @bomly-guy in #450
- docs: record the declined modernizer analyzer in both guidance files by @bomly-guy in #451
- feat(detectors): the purl type stops being something a detector can pass by @bomly-guy in #452
- docs(adr): ADR-0033 names the SDK helper and what the fold does merge by @bomly-guy in #456
- fix(sbom): a transformed export mints its own identity and links its source by @bomly-guy in #461
- docs(maturity): done-criterion 2 states the measurement that was actually taken by @bomly-guy in #462
- fix(sbom): an escaped lone surrogate is refused as its own class, and the advice says so by @bomly-guy in #463
- docs(adr): a guard must be able to fail, and must know what it covers by @bomly-guy in #460
- docs(adr): qualify what MergeOrigins drops by @bomly-guy in #457
- test: update smoke golden files by @github-actions[bot] in #458
- chore(deps): consume bomly-sdk v0.11.0 and every plugin's latest tag; ADR-0045 decides the codec's home by @bomly-guy in #465
- build: replace the guard walkers with depguard, forbidigo and a go/analysis analyzer by @bomly-guy in #468
- build(deps): bump actions/setup-java from 5.7.0 to 6.0.0 by @dependabot[bot] in #422
- build(deps): bump github.com/mark3labs/mcp-go from 0.58.0 to 1.0.0 by @dependabot[bot] in #442
- build(deps): bump dart-lang/setup-dart from 1.8.0 to 1.8.1 in the github-actions-patch group across 1 directory by @dependabot[bot] in #470
- build(deps): bump the gomod-minor group across 1 directory with 2 updates by @dependabot[bot] in #473
- refactor(sbom): consume bomly-sdk v0.12.0's codec and graphview; delete the CLI copies by @bomly-guy in #474
Full Changelog: v0.24.2...v0.25.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.24.2
What's Changed
- fix(security): resolve code scanning alerts 228/229 by removing the source_ref input by @bomly-guy in #408
- fix(sbom): validate license emission, complete the primary component by @bomly-guy in #409
Full Changelog: v0.24.1...v0.24.2
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.24.1
What's Changed
- fix(detectors): union scopes when duplicate nodes fold by @bomly-guy in #406
- fix(cargo): resolve workspace membership by identity, not name alone by @bomly-guy in #407
Full Changelog: v0.24.0...v0.24.1
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.
v0.24.0
What's Changed
- feat(sbom): consistent primary component, document identity, and CRA metadata by @bomly-guy in #364
- feat(sbom): detector-asserted package origin in SBOM export by @bomly-guy in #397
- build(deps): bump the github-actions-patch group with 3 updates by @dependabot[bot] in #393
- build(deps): bump github.com/mark3labs/mcp-go from 0.57.0 to 0.58.0 in the gomod-minor group across 1 directory by @dependabot[bot] in #402
- build(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 by @dependabot[bot] in #394
- docs: extract architecture decision log into dev-docs/adr by @bomly-guy in #403
- test: update smoke golden files by @github-actions[bot] in #404
- fix(security): resolve cache-poisoning and vulnerability code scanning alerts by @bomly-guy in #405
Full Changelog: v0.23.0...v0.24.0
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.