v0.20.2
Immutable
release. Only release title and notes can be modified.
What's Changed
- test: update smoke golden files by @github-actions[bot] in #318
- Require explicit trust for repository configuration by @bomly-guy in #320
- fix(matchers): pass distro and upstreams to Grype for OS packages by @bomly-guy in #323
- fix(matchers): query advisories by the ecosystem-native package name by @bomly-guy in #322
- fix(osv): emit spec purl types and make the name+ecosystem fallback reachable by @bomly-guy in #321
- Clarify network and plugin trust boundaries by @bomly-guy in #324
- feat(discovery): explain why each probed manifest candidate was skipped by @bomly-guy in #333
- fix(pip): scope direct dependencies, name project roots, diagnose old pip by @bomly-guy in #338
- feat(engine): report CI-readiness hints for package-manager mismatches by @bomly-guy in #335
- Honor Bomly no-proxy with standard proxy fallback by @bomly-guy in #325
- Redact credentials from endpoint logs by @bomly-guy in #327
- Add execution boundary assurance by @bomly-guy in #328
- Verify HTTP trust boundaries by @bomly-guy in #329
- Contain automatic baseline discovery by @bomly-guy in #330
- Bound untrusted security inputs by @bomly-guy in #336
- Bound managed plugin archive resources by @bomly-guy in #332
- Verify filesystem containment boundaries by @bomly-guy in #326
- Redact MCP tool errors by @bomly-guy in #331
- Sanitize subprocess diagnostics by @bomly-guy in #334
- Document security and trust boundaries by @bomly-guy in #337
Full Changelog: v0.20.1...v0.20.2
Release artifacts
- Full builtin
bomlyarchives for Linux, macOS, and Windows. - Alternate
bomly-litearchives for users who prefer external Syft and Grype binaries. - Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
- Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
SHA256SUMSfor release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).- SLSA Build Level 3 provenance (
multiple.intoto.jsonl) generated by slsa-github-generator.
Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.