Skip to content

v0.20.2

Choose a tag to compare

@bomly-release bomly-release released this 27 Jul 10:41
Immutable release. Only release title and notes can be modified.

What's Changed

  • test: update smoke golden files by @github-actions[bot] in #318
  • Require explicit trust for repository configuration by @bomly-guy in #320
  • fix(matchers): pass distro and upstreams to Grype for OS packages by @bomly-guy in #323
  • fix(matchers): query advisories by the ecosystem-native package name by @bomly-guy in #322
  • fix(osv): emit spec purl types and make the name+ecosystem fallback reachable by @bomly-guy in #321
  • Clarify network and plugin trust boundaries by @bomly-guy in #324
  • feat(discovery): explain why each probed manifest candidate was skipped by @bomly-guy in #333
  • fix(pip): scope direct dependencies, name project roots, diagnose old pip by @bomly-guy in #338
  • feat(engine): report CI-readiness hints for package-manager mismatches by @bomly-guy in #335
  • Honor Bomly no-proxy with standard proxy fallback by @bomly-guy in #325
  • Redact credentials from endpoint logs by @bomly-guy in #327
  • Add execution boundary assurance by @bomly-guy in #328
  • Verify HTTP trust boundaries by @bomly-guy in #329
  • Contain automatic baseline discovery by @bomly-guy in #330
  • Bound untrusted security inputs by @bomly-guy in #336
  • Bound managed plugin archive resources by @bomly-guy in #332
  • Verify filesystem containment boundaries by @bomly-guy in #326
  • Redact MCP tool errors by @bomly-guy in #331
  • Sanitize subprocess diagnostics by @bomly-guy in #334
  • Document security and trust boundaries by @bomly-guy in #337

Full Changelog: v0.20.1...v0.20.2


Release artifacts

  • Full builtin bomly archives for Linux, macOS, and Windows.
  • Alternate bomly-lite archives for users who prefer external Syft and Grype binaries.
  • Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
  • Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
  • SHA256SUMS for release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).
  • SLSA Build Level 3 provenance (multiple.intoto.jsonl) generated by slsa-github-generator.

Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.