-
released this
2026-06-20 15:33:17 +00:00 | 14 commits to main since this releaseSupersedes 0.2.3 (whose release did not publish due to the workflow bug below). Carries the full
supply-chain pinning from 0.2.3 plus the fix.Security
- Supply-chain pinning. Base images by
@sha256digest (python:3.12-slim,caddy:2,
caddy:2-builder,alpine:3); Caddyv2.11.4+ xcaddy modulescaddy-dns/desec@v1.1.0and
mholt/caddy-ratelimit@v0.1.0; Python deps exact +pip --require-hashes; thecaddyimage for
hash-password; lazydockerv0.25.2with SHA-256 verification; release-workflow image + deps.
See DESIGN.md → Supply chain.
Fixed
- Release workflow: the hashed
requirements-dev.txtwas missing pytest 9'spygments
dependency, sopip --require-hashesfailed in CI; addedpygments==2.20.0. Verified in a clean venv.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Supply-chain pinning. Base images by