Skip to content

qwexvf/aegis-cli

v0.29.1 Maintenance

This release keeps dependencies and maintenance posture current for teams operating this tool.

Published 1mo CLI & Terminal
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ast-analysis cli cve dependency-scanner security go
+13 more
lockfile malware-detection npm-security osv python-security sbom sca shai-hulud supply-chain-attack supply-chain-security tree-sitter typosquatting vulnerability-scanning

Affected surfaces

deps

Summary

AI summary

Updates Other, deps, and dd9e6047b69f4a4d12e05657d777dd3ff50c3bb0 across a mixed release.

Changes in this release

Dependency Low

Bump actions/cache from 4.3.0 to 5.0.5.

Bump actions/cache from 4.3.0 to 5.0.5.

Source: llm_adapter@2026-06-06

Confidence: high

Dependency Low

Bump actions/attest-build-provenance.

Bump actions/attest-build-provenance.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Dependency Low

Bump sigstore/cosign-installer.

Bump sigstore/cosign-installer.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Dependency Low

Bump gha-deps group with 1 directory update.

Bump gha-deps group with 1 directory update.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Dependency Low

Bump go-deps group with 1 directory and 2 updates.

Bump go-deps group with 1 directory and 2 updates.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Dependency Low

Bump npm-deps group across 1 directory with 13 updates.

Bump npm-deps group across 1 directory with 13 updates.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Full changelog

aegis-cli v0.29.1

Supply-chain security CLI for npm / bun / yarn / pnpm.

Verifying releases

All artifacts are checksummed (checksums.txt) and the checksums file
is signed via cosign keyless OIDC. To verify:

cosign verify-blob \
  --certificate-identity-regexp 'https://github.com/qwexvf/aegis-cli/.github/workflows/release.yml.*' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  --certificate checksums.txt.pem \
  --signature   checksums.txt.sig \
  checksums.txt
sha256sum -c checksums.txt

SLSA build provenance is attached to every artifact and can be
verified with gh attestation verify <file> --owner qwexvf.

Changelog

Other

  • 57a301f8b79a4e5006ea10945232bf5ec9377144: build(deps): bump actions/attest-build-provenance (@dependabot[bot])
  • 35c18a285844f1e312045c3250432f4cf262a2e2: build(deps): bump actions/cache from 4.3.0 to 5.0.5 (@dependabot[bot])
  • 405b2d6e2978c7bf93e410b390d6d68c97fc146f: build(deps): bump sigstore/cosign-installer (@dependabot[bot])
  • dd9e6047b69f4a4d12e05657d777dd3ff50c3bb0: build(deps): bump the gha-deps group across 1 directory with 2 updates (@dependabot[bot])
  • 3fd21b4d68e857570e1e0f2453f5d6cad64cbff0: build(deps): bump the go-deps group across 1 directory with 2 updates (@dependabot[bot])
  • 2733e9e9bc2a24b8c801adc35a48027c881647d2: build(deps): bump the npm-deps group across 1 directory with 13 updates (@dependabot[bot])

Apache-2.0 — see LICENSE.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track qwexvf/aegis-cli

Get notified when new releases ship.

Sign up free

About qwexvf/aegis-cli

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]