This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Summary
AI summaryUpdates Bug fixes, @qwexvf, and Other across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bumps Go toolchain to version 1.26.4. Bumps Go toolchain to version 1.26.4. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Fixes gaps in suppression, obfuscation, SARIF output and offline mode. Fixes gaps in suppression, obfuscation, SARIF output and offline mode. Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
aegis-cli v0.29.0
Supply-chain security CLI for npm / bun / yarn / pnpm.
Verifying releases
All artifacts are checksummed (checksums.txt) and the checksums file
is signed via cosign keyless OIDC. To verify:
cosign verify-blob \
--certificate-identity-regexp 'https://github.com/qwexvf/aegis-cli/.github/workflows/release.yml.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
checksums.txt
sha256sum -c checksums.txt
SLSA build provenance is attached to every artifact and can be
verified with gh attestation verify <file> --owner qwexvf.
Changelog
Bug fixes
- 823c2f8191a8eb6f673355273c298f64227d9ba0: fix: close suppression, obfuscation, sarif and offline gaps found in testing (@qwexvf)
Other
- 7d4d36bb166ca64fa8e71e9b9e81de492022ae82: build: bump Go toolchain to 1.26.4 (fixes GO-2026-5037, GO-2026-5039) (@qwexvf)
Apache-2.0 — see LICENSE.
Security Fixes
- Fixes GO-2026-5037 and GO-2026-5039 by bumping Go toolchain to 1.26.4
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About qwexvf/aegis-cli
All releases →Beta — feedback welcome: [email protected]