1. 24 Mar, 2026 1 commit
    • security: harden Docker and release CI workflows · a5e20269
      - Pin all GitHub Actions to commit SHA to prevent supply chain attacks
      - Enable SLSA provenance attestation (mode=max) and SBOM generation
      - Add cosign keyless signing for Docker images via GitHub OIDC
      - Capture and output image digests to GitHub Job Summary
      - Pin Dockerfile base images to digest (bun:1, golang:1.26.1-alpine, debian:bookworm-slim)
      - Add SHA256 checksum generation for binary releases (Linux/macOS/Windows)
      - Update actions/checkout v3->v4, actions/setup-go v3->v5 in release.yml
      CaIon committed
  2. 23 Mar, 2026 12 commits
  3. 22 Mar, 2026 5 commits
  4. 21 Mar, 2026 7 commits
  5. 20 Mar, 2026 9 commits
  6. 19 Mar, 2026 5 commits
  7. 18 Mar, 2026 1 commit