Security Deep Dive
Diffcat
Security posture and CVE patch evidence from tracked releases.
No CVEs tracked against v0.11.1.
— Signed
— SLSA
— SBOM
✗ Security policy
Weekly cadence · 0d median
Active maintainer
Trust Signals — 2 of 9 Present
Evidence already collected from releases and repository metadata.
2/9
Present
Signed releases
Unknown
Latest release artifact signature
Latest release
—
SLSA provenance
Unknown
Attestation predicate level
Latest release
—
SBOM published
Unknown
GitHub SBOM API
Latest release
—
SECURITY.md
Absent
GitHub repository metadata
Repository policy
Checked: 1d ago
Release cadence: weekly
Present
0d median over recent releases
Release history
Latest release: 6d ago
Maintainer active
Present
Recent commit activity
Repository
Last commit: 5d ago
Checksums (SHA256SUMS)
Not active yet
SHA256SUMS or equivalent
Release asset
Latest release: 6d ago
GitHub Actions attestation
Not active yet
actions/attest-build-provenance
Workflow file
Latest release: 6d ago
Signing assets
Not active yet
.sig, .crt, cosign.pub, or similar
Release asset
Latest release: 6d ago