Skip to content

v0.20.0

Choose a tag to compare

@bomly-release bomly-release released this 24 Jul 07:06
Immutable release. Only release title and notes can be modified.

What's Changed

  • Add portable finding baselines by @bomly-guy in #297
  • feat(cli): frame-based startup banner animations with variants and env gating by @bomly-guy in #298
  • Reject unsupported finding severities in baselines by @bomly-guy in #300
  • Strengthen vulnerability consolidation assurance by @bomly-guy in #299
  • fix(osv): surface degraded batch enrichment by @bomly-guy in #301
  • test(baseline): strengthen lifecycle assurance by @bomly-guy in #302
  • test(engine): add canonical graph accounting invariants by @bomly-guy in #303
  • test(auditors): expand policy and SPDX assurance by @bomly-guy in #304
  • fix(plugin): fully isolate descriptor snapshots by @bomly-guy in #306
  • test(interfaces): strengthen compact and plugin contracts by @bomly-guy in #307
  • test(parsers): broaden hostile-input fuzz coverage by @bomly-guy in #305
  • test(performance): record reproducible run evidence by @bomly-guy in #309
  • test(sbom): add pinned interoperability assurance by @bomly-guy in #308
  • fix(jvm): parse Gradle settings on Windows by @bomly-guy in #310
  • ci(assurance): explain workflow results by @bomly-guy in #311
  • test: update smoke golden files by @github-actions[bot] in #312

Full Changelog: v0.19.2...v0.20.0


Release artifacts

  • Full builtin bomly archives for Linux, macOS, and Windows.
  • Alternate bomly-lite archives for users who prefer external Syft and Grype binaries.
  • Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
  • Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
  • SHA256SUMS for release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).
  • SLSA Build Level 3 provenance (multiple.intoto.jsonl) generated by slsa-github-generator.

Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.