Skip to content

[codex] Harden release and install guidance#13

Draft
jasoncrites wants to merge 1 commit into
perplexityai:mainfrom
jasoncrites:fix/supply-chain-hardening
Draft

[codex] Harden release and install guidance#13
jasoncrites wants to merge 1 commit into
perplexityai:mainfrom
jasoncrites:fix/supply-chain-hardening

Conversation

@jasoncrites
Copy link
Copy Markdown

Hardens Bumblebee's release and install guidance.

What changed:

  • Pin govulncheck in CI instead of installing it from @latest.
  • Replace the README's unpinned install example with a tagged release install.
  • Add SBOM generation to the GoReleaser archive artifacts.
  • Add a regression test that enforces those policy constraints.

Why:

  • Remove live install provenance from CI and docs.
  • Make release artifacts more auditable with checksums and SBOMs.

Checks:

  • go test ./cmd/bumblebee ./...
  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant