github jdx/fnox v1.35.1
v1.35.1: Signed release provenance

4 hours ago

A small release with no changes to fnox's runtime behavior. The one user-facing improvement is that release downloads can now be verified against a signed provenance manifest; the rest is documentation and internal tooling.

Changed

  • Signed packslip published with each release (#807) -- @jdx. Every release now ships a keyless-signed packslip.sigstore.json beside the archives, listing each artifact's sha256/sha512, the bundled executable, host shared-library requirements, and build-provenance attestations, all tied to the github.com/jdx/fnox OIDC identity. Installers can verify a download against that identity rather than a signing key the project would have to hold and rotate. A fnox.usage.kdl CLI spec is also published so consumers can generate completions, man pages, and docs without executing fnox locally.

Full Changelog: v1.35.0...v1.35.1

💚 Sponsor fnox

fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

Don't miss a new fnox release

NewReleases is sending notifications on new releases.