Skip to content

v0.21.0

Choose a tag to compare

@bomly-release bomly-release released this 30 Jul 10:19
Immutable release. Only release title and notes can be modified.

What's Changed

  • Bound in-process repository file reads by @bomly-guy in #341
  • Bound remote Git target materialization by @bomly-guy in #342
  • build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0 by @dependabot[bot] in #346
  • build(deps): bump the github-actions-patch group with 4 updates by @dependabot[bot] in #345
  • build(deps): bump bomly-dev/bomly-guard from 1.1.0 to 1.2.0 in the github-actions-minor group by @dependabot[bot] in #344
  • build(deps): bump the gomod-minor group with 2 updates by @dependabot[bot] in #343
  • Report dependency detail changes in diff by @bomly-guy in #347
  • Review and audit risky dependency detail changes by @bomly-guy in #348
  • Expand dependency source classification by @bomly-guy in #352
  • Publish reproducible evidence cases by @bomly-guy in #353
  • docs: first wave of docs improvements (FAQ, network page, command reference, link CI) by @bomly-guy in #350
  • docs: wave 2 — expected output everywhere, integrations page, selector grammar by @bomly-guy in #354
  • docs: clarify that file-only -o SBOM runs print nothing without --format by @bomly-guy in #355
  • docs: wave 3 — end-to-end tutorial, diff-gating semantics fix, verification output by @bomly-guy in #356

Full Changelog: v0.20.2...v0.21.0


Release artifacts

  • Full builtin bomly archives for Linux, macOS, and Windows.
  • Alternate bomly-lite archives for users who prefer external Syft and Grype binaries.
  • Linux packages for Debian, RPM, Alpine, and Arch-compatible package managers.
  • Homebrew, Scoop, and WinGet package-manager manifests or publishing pull requests.
  • SHA256SUMS for release artifact verification, signed keylessly with cosign (SHA256SUMS.sigstore.json).
  • SLSA Build Level 3 provenance (multiple.intoto.jsonl) generated by slsa-github-generator.

Each archive includes LICENSE, NOTICE, and a licenses/ directory with third-party license texts. See Verify release checksums for signature and provenance verification commands.