What's Changed
- ci(pre-release): disable the uv cache by @gaborbernat in #3288
- ci: pass expressions to run scripts via env by @gaborbernat in #3292
- ci(release): audit egress in build and publish by @gaborbernat in #3289
- 📝 docs: define maintainer roles and access by @gaborbernat in #3290
- ci: resolve zizmor auditor findings by @gaborbernat in #3297
- ci(pre-commit): freeze hook revs to commit SHAs by @gaborbernat in #3298
- docs: link docs and pyvideo over https by @gaborbernat in #3300
- docs(development): add a one-year roadmap by @gaborbernat in #3304
- 🐛 fix(seed): fail closed when PyPI digest is unknown by @gaborbernat in #3302
- ✨ feat(release): publish SBOMs as release assets by @gaborbernat in #3299
- docs(security): describe the project under the CRA by @gaborbernat in #3295
- docs(template): name the trust boundary crossed by @gaborbernat in #3296
- ♻️ refactor(sbom): type the SPDX renderer by @gaborbernat in #3307
- ✨ feat(zipapp): publish an SBOM for the zipapp by @gaborbernat in #3310
- 👷 ci(check): pin test tool downloads and bump them weekly by @gaborbernat in #3293
- 📝 docs: explain what a release publishes and how to verify it by @gaborbernat in #3305
- 👷 ci(release): verify the zipapp served by bootstrap.pypa.io by @gaborbernat in #3309
- 👷 ci(release): mint app tokens instead of a PAT by @gaborbernat in #3301
- 📝 docs(security): add threat model and assurance case by @gaborbernat in #3294
- 🐛 fix(zipapp): bundle wheels pinned by a PEP 751 lock by @gaborbernat in #3306
- 📝 docs(security): sync threat model with merged fixes by @gaborbernat in #3312
- 🐛 fix(sbom): keep the build machine out of the SBOMs by @gaborbernat in #3311
Full Changelog: 21.10.0...21.11.0