This release adds 3 notable features for engineering teams evaluating rollout.
Published 1mo
Infrastructure as Code
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
claude-code
cli
ci-cd
dependency-scanning
security
gemini-cli
+8 more
go
guardrails
iac
mcp
opentofu
skills
supply-chain-security
terraform
Summary
AI summaryUpdates @gnana997, a6396abdceba4007152cf6831e4b55ae87c45c9d, and f5b8709f2df1b5c75777254244850acc62bb6c7f across a mixed release.
Full changelog
Changelog
- a6396abdceba4007152cf6831e4b55ae87c45c9d: feat: add CONTRIBUTING and SECURITY documents to guide contributions and report vulnerabilities (@gnana997)
- f5b8709f2df1b5c75777254244850acc62bb6c7f: feat: add Dependabot and CodeQL workflows for Go module and security checks (@gnana997)
- d19abb1511e47966164b2d945d83b1e353b0cdbe: feat: add GCP rules and test cases for security best practices (@gnana997)
- dfb5191601a77884884883ef9914416d4a214016: feat: enhance GCP hardening rules and tests (@gnana997)
Verify this release
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/gnana997/bumper/.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
checksums.txt
sha256sum -c checksums.txt --ignore-missing
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Bumper
All releases →Related context
Beta — feedback welcome: [email protected]