github CodesWhat/drydock v1.3.1

latest releases: v1.5.0-rc.6, v1.5.0-rc.5, v1.6.0...
one month ago

Patch release — release workflow fix

Fixed

  • Release SBOM generation for multi-arch images — Replaced anchore/sbom-action (which fails on manifest list digests from multi-platform builds) with Docker buildx native SBOM generation (sbom: true), producing per-platform SBOMs embedded in image attestations.

Security

  • Pin Trivy install script by commit hash — Replaced mutable main branch reference in Dockerfile curl | sh with a pinned commit SHA to satisfy OpenSSF Scorecard pinned-dependencies check.

Full Changelog: v1.3.0...v1.3.1

Don't miss a new drydock release

NewReleases is sending notifications on new releases.