mirror of
https://github.com/forkless/NotAlterra.git
synced 2026-08-19 09:35:12 +02:00
move attestation note from release notes to governance doc, reword
This commit is contained in:
+4
-1
@@ -13,6 +13,9 @@ extract, and run.
|
||||
• Backup archives now preserve source file modification times — restored files keep their original dates instead of showing 1970-01-01 on Windows
|
||||
• Restore backup picker navigation no longer stops before migrated entries
|
||||
• Save folder input dialog pre-fills with the currently set path
|
||||
• SLSA provenance attestation re-enabled
|
||||
• SLSA provenance attestation (automatic for tagged releases)
|
||||
|
||||
Builds: Linux (amd64) • Windows x64
|
||||
|
||||
For a full history of changes across all versions, see
|
||||
[`CHANGELOG.md`](https://github.com/forkless/NotAlterra/blob/master/CHANGELOG.md).
|
||||
|
||||
@@ -77,6 +77,10 @@ welcome. Patience is appreciated. Kindness is non-negotiable.
|
||||
CI now creates releases as drafts — binaries are built and uploaded but
|
||||
not published. The maintainer tests the draft binaries before publishing.
|
||||
|
||||
> SLSA provenance attestation is generated automatically for every
|
||||
> tagged release. The `.intoto.jsonl` file is included with the
|
||||
> binaries. No configuration needed.
|
||||
|
||||
Before signing a release tag, the maintainer verifies:
|
||||
|
||||
- [ ] Impact analysis completed — all call sites for new/changed functions identified and updated
|
||||
|
||||
Reference in New Issue
Block a user