This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryUpdates Other, deps, and dd9e6047b69f4a4d12e05657d777dd3ff50c3bb0 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bump actions/cache from 4.3.0 to 5.0.5. Bump actions/cache from 4.3.0 to 5.0.5. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Dependency | Low |
Bump actions/attest-build-provenance. Bump actions/attest-build-provenance. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Dependency | Low |
Bump sigstore/cosign-installer. Bump sigstore/cosign-installer. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Dependency | Low |
Bump gha-deps group with 1 directory update. Bump gha-deps group with 1 directory update. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Dependency | Low |
Bump go-deps group with 1 directory and 2 updates. Bump go-deps group with 1 directory and 2 updates. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Dependency | Low |
Bump npm-deps group across 1 directory with 13 updates. Bump npm-deps group across 1 directory with 13 updates. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
Full changelog
aegis-cli v0.29.1
Supply-chain security CLI for npm / bun / yarn / pnpm.
Verifying releases
All artifacts are checksummed (checksums.txt) and the checksums file
is signed via cosign keyless OIDC. To verify:
cosign verify-blob \
--certificate-identity-regexp 'https://github.com/qwexvf/aegis-cli/.github/workflows/release.yml.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
checksums.txt
sha256sum -c checksums.txt
SLSA build provenance is attached to every artifact and can be
verified with gh attestation verify <file> --owner qwexvf.
Changelog
Other
- 57a301f8b79a4e5006ea10945232bf5ec9377144: build(deps): bump actions/attest-build-provenance (@dependabot[bot])
- 35c18a285844f1e312045c3250432f4cf262a2e2: build(deps): bump actions/cache from 4.3.0 to 5.0.5 (@dependabot[bot])
- 405b2d6e2978c7bf93e410b390d6d68c97fc146f: build(deps): bump sigstore/cosign-installer (@dependabot[bot])
- dd9e6047b69f4a4d12e05657d777dd3ff50c3bb0: build(deps): bump the gha-deps group across 1 directory with 2 updates (@dependabot[bot])
- 3fd21b4d68e857570e1e0f2453f5d6cad64cbff0: build(deps): bump the go-deps group across 1 directory with 2 updates (@dependabot[bot])
- 2733e9e9bc2a24b8c801adc35a48027c881647d2: build(deps): bump the npm-deps group across 1 directory with 13 updates (@dependabot[bot])
Apache-2.0 — see LICENSE.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About qwexvf/aegis-cli
All releases →Beta — feedback welcome: [email protected]