What's Changed
- ci: add streaming-invariant enforcement gate (Phase 1 of #1608) by @brandonrc in #2171
- fix(proxy): cross-replica single-flight for pull-through cache via Postgres advisory lock by @brandonrc in #2172
- fix: stream quality-gate content read and cap upstream metadata reads (#1608) by @brandonrc in #2174
- feat(uploads): stream chef/ansible/pub multipart uploads to storage (#1608) by @brandonrc in #2176
- feat(uploads): stream helm chart metadata-parsing upload to storage (#1608) by @brandonrc in #2180
- fix(proxy): stream pull-through artifact-blob downloads (Phase 4 of #1608) by @brandonrc in #2178
- chore(auth): consolidate require_admin onto AuthExtension gate (#1617 Phase 3) by @brandonrc in #2185
- feat(audit): audit federated logins and API-token lifecycle (#1617 Phase 1) by @brandonrc in #2187
- fix(oci): lock referenced oci_blobs FOR UPDATE before ref-insert (#1660) by @brandonrc in #2190
- fix(proxy): cap buffered upstream metadata reads (#2181) by @brandonrc in #2191
- refactor(auth): introduce AccessScope enum for repo-scope authz (#1617) by @brandonrc in #2195
- fix(repositories): purge OCI upload temp objects after repo-delete and batch the listing query by @brandonrc in #2198
- fix(storage): GCS rewrite-loop token refresh + S3 copy digest-check and abort-on-drop by @brandonrc in #2200
- feat(uploads): stream pypi and nuget uploads via shared content-addressed primitive by @brandonrc in #2199
- #1533-A + #1410: OCI upload cleanup-journal hygiene + Range integration test by @brandonrc in #2202
- fix(proxy): stream buffered blob fallback paths instead of capping them by @brandonrc in #2203
- feat(composer): cache upstream dist artifacts for remote/proxy repositories by @brandonrc in #2204
- refactor(authz): thread AccessScope through SBOM + search read-path scope sites (#2194) by @brandonrc in #2205
- refactor(storage): require StorageBackend::put_stream so backends can't inherit in-memory buffering by @brandonrc in #2207
- feat(storage-gc): pending_delete marker + idempotent blob GC delete (#1660) by @brandonrc in #2209
- test(sso): add OIDC login/callback e2e regression harness against a mock IdP by @brandonrc in #2210
- feat(storage-gc): two-phase mark-and-sweep for blob GC (#1660) by @brandonrc in #2213
- fix(deps): bump bcrypt to 0.19.2 to resolve RUSTSEC-2026-0199 by @brandonrc in #2216
- test(sso): add SAML ACS signed-assertion e2e regression harness by @brandonrc in #2214
- fix(cache): fan out authorization-cache invalidation across replicas by @cazlo in #2169
- feat(npm): cache computed packuments with stale-while-revalidate by @rob-howie-depop in #2166
- fix(metrics): collapse unmatched HTTP paths to prevent scanner-driven cardinality explosion by @Dreamacro in #2217
- fix(security): require admin for global security-policy create/update/delete by @brandonrc in #2223
- fix(auth): gate cookie Secure flag on explicit AK_ENFORCE_HTTPS (#2233) by @brandonrc in #2234
- fix(auth): auto-detect HTTPS via X-Forwarded-Proto for cookie Secure flag by @brandonrc in #2236
- fix(scanner-adapter): scope registry pull credential to the target image so the trivy DB pull is not rejected by @brandonrc in #2238
- fix(api): gate direct artifact delete on promotion-only release repos by @brandonrc in #2239
- fix(security): fail closed when a vulnerability scan errors instead of reporting clean by @brandonrc in #2240
- chore(release): bump version to 1.3.0 by @brandonrc in #2241
- chore(scanner-adapter): bump to 1.1.0 (ships #2238 credential-scoping fix) by @brandonrc in #2242
Full Changelog: v1.2.5...v1.3.0