Celebrating our 2024 open-source contributions
While Trail of Bits is known for developing security tools like Slither, Medusa, and Fickling, our engineering efforts extend far beyond our own projects. Throughout 2024, our team has been deeply engaged with the broader security ecosystem, tackling challenges in open-source tools and infrastructure that security engineers rely on every day.
This year, our engineers submitted over 750 pull requests that were successfully merged (a 67% increase over our 2023 contributions!) with improvements across more than 80 open-source projects, ranging from foundational cryptography libraries to package managers and software indexes. Each contribution is a response to real-world security engineering challenges—when we encounter limitations in critical tools, we dig in and improve them. When we discover ways to strengthen security primitives everyone depends on, we implement those improvements upstream where they benefit the entire community.
Some of these changes may seem small in isolation—a more robust parser here, better error handling there—but together, they represent meaningful improvements to security tooling that thousands of engineers depend on. From hardening package signing workflows to enhancing fuzzing capabilities, each contribution helps build a more secure foundation for everyone.
Let’s dive into some of the key contributions we made in 2024.
Key contributions
- LLVM: We made improvements to MLIR and AddressSanitizer. For example, we added detection of C++ container overflows for
std::string
andstd::deque
containers. Read more about this in our blog post “Sanitize your C++ containers: ASan annotations step-by-step.” - pwndbg: pwndbg is a GDB and LLDB plugin that helps with reverse engineering and exploit development. Our engineers have continued maintaining the project, fixing numerous issues and merging numerous new features such as an LLDB port, a Binary Ninja integration (see the pull request), and better support for embedded devices.
- hevm: hevm is an implementation of the EVM supporting both symbolic and concrete execution, which we use as the basis for Echidna. Throughout 2024, we contributed several performance improvements, added support for new Cancun opcodes, and implemented multiple new cheatcodes to improve the testing experience.
- Post-quantum cryptography: We released open-source implementations of two post-quantum digital signature schemes that have been standardized by NIST, helping to improve the overall community support of post-quantum cryptography. We released both Go and Rust versions of these standards, and the Rust versions have been integrated into RustCrypto.
- OSS-Fuzz: OSS-Fuzz is a continuous fuzzing tool for open-source software projects. We added support for Ruzzy, our coverage-guided fuzzer for Ruby and Ruby C extensions.
- Python packaging ecosystem: We continued our contributions to the Python packaging ecosystem, implementing PEP 740 and numerous other supply chain security improvements. Read more about these in our blog post “Attestations: A new generation of signatures on PyPI.”
The pull requests listed here capture the technical changes, but they don’t tell the whole story. Behind each merged pull request is a community of maintainers who reviewed our code, suggested improvements, and carefully considered the long-term implications of each change. These maintainers carry the real weight of open-source development—ensuring consistency, maintaining test coverage, and preserving compatibility across years of changes.
Many of our contributions started from limitations in open-source projects that we encountered during security assessments or tool development. Rather than building workarounds for these limitations, we chose to address them upstream, improving tools that the entire security community relies on. We’re able to do this work because we stand on the shoulders of giants—the maintainers and contributors who built and nurture these critical projects.
To every maintainer who reviewed our pull requests, every developer who provided feedback, and every engineer working to improve the security ecosystem—thank you. Here’s to another year of collaborative security engineering!
Some of Trail of Bits’ 2024 open-source contributions
AI/ML
- Repo: TabbyML/tabby
- Name: feat: Add Solidity language
- #1681 ret2libc: https://github.com/TabbyML/tabby/pull/1681
- Repo: astronomer/ask-astro
- Name: Regex update to avoid over-redaction of GitHub issues
- #325 bismuthsalamander: https://github.com/astronomer/ask-astro/pull/325
- Repo: continuedev/continue
- Name: Add autocomplete support for Solidity
- #964 ret2libc: https://github.com/continuedev/continue/pull/964
- Repo: langchain-ai/langchain
- Name: core: runnables: special handling GeneratorExit because no error
- #22662 ret2libc: https://github.com/langchain-ai/langchain/pull/22662
- Repo: onyx-dot-app/onyx
- Name: backend: remove duplicated word in ANSWER_VALIDITY_PROMPT
- #1184 ret2libc: https://github.com/onyx-dot-app/onyx/pull/1184
- Repo: unoplat/vespa-helm-charts
- Name: Fix labels and service selector
- #14 oldsj: https://github.com/unoplat/vespa-helm-charts/pull/14
Cryptography
- Repo: C2SP/x509-limbo
- Name: render-testcases: fix linkification
- #162 woodruffw: https://github.com/C2SP/x509-limbo/pull/162
- Repo: C2SP/x509-limbo
- Name: gocryptox509: handle a KeyUsage edge case
- #167 woodruffw: https://github.com/C2SP/x509-limbo/pull/167
- Repo: C2SP/x509-limbo
- Name: Update URLs post-transfer
- #172 woodruffw: https://github.com/C2SP/x509-limbo/pull/172
- Repo: C2SP/x509-limbo
- Name: Add an explicit curve test
- #173 woodruffw: https://github.com/C2SP/x509-limbo/pull/173
- Repo: C2SP/x509-limbo
- Name: testcases: add CVE-2024-0567
- #176 woodruffw: https://github.com/C2SP/x509-limbo/pull/176
- Repo: C2SP/x509-limbo
- Name: site: config cleanup, grammar
- #178 woodruffw: https://github.com/C2SP/x509-limbo/pull/178
- Repo: C2SP/x509-limbo
- Name: index: mimic README
- #179 woodruffw: https://github.com/C2SP/x509-limbo/pull/179
- Repo: C2SP/x509-limbo
- Name: limbo: add RSA key size tests
- #184 woodruffw: https://github.com/C2SP/x509-limbo/pull/184
- Repo: C2SP/x509-limbo
- Name: webpki: improve pedantic “forbidden leaf key” tests
- #185 woodruffw: https://github.com/C2SP/x509-limbo/pull/185
- Repo: C2SP/x509-limbo
- Name: limbo: include peer keys, when possible
- #187 woodruffw: https://github.com/C2SP/x509-limbo/pull/187
- Repo: C2SP/x509-limbo
- Name: fixup peer_certificate_key in Go schema
- #193 woodruffw: https://github.com/C2SP/x509-limbo/pull/193
- Repo: C2SP/x509-limbo
- Name: ci: enforce schema.go’s updatedness
- #194 woodruffw: https://github.com/C2SP/x509-limbo/pull/194
- Repo: C2SP/x509-limbo
- Name: limbo: initial client testcases
- #196 woodruffw: https://github.com/C2SP/x509-limbo/pull/196
- Repo: C2SP/x509-limbo
- Name: site: undocumented REST API
- #198 woodruffw: https://github.com/C2SP/x509-limbo/pull/198
- Repo: C2SP/x509-limbo
- Name: Detect testcase regressions
- #201 woodruffw: https://github.com/C2SP/x509-limbo/pull/201
- Repo: C2SP/x509-limbo
- Name: limbo: NC DoS testcase
- #204 woodruffw: https://github.com/C2SP/x509-limbo/pull/204
- Repo: C2SP/x509-limbo
- Name: harness/openssl: multiple OpenSSL builds
- #205 woodruffw: https://github.com/C2SP/x509-limbo/pull/205
- Repo: C2SP/x509-limbo
- Name: limbo: don’t mark SAN as critical when subject is nonempty
- #206 woodruffw: https://github.com/C2SP/x509-limbo/pull/206
- Repo: C2SP/x509-limbo
- Name: PyCA harness, fix SAN
- #207 woodruffw: https://github.com/C2SP/x509-limbo/pull/207
- Repo: C2SP/x509-limbo
- Name: limbo: chonkify NC DoS cases
- #208 woodruffw: https://github.com/C2SP/x509-limbo/pull/208
- Repo: C2SP/x509-limbo
- Name: limbo, site: migrate another template
- #211 woodruffw: https://github.com/C2SP/x509-limbo/pull/211
- Repo: C2SP/x509-limbo
- Name: More template migration
- #212 woodruffw: https://github.com/C2SP/x509-limbo/pull/212
- Repo: C2SP/x509-limbo
- Name: _cli: add limbo extract
- #213 woodruffw: https://github.com/C2SP/x509-limbo/pull/213
- Repo: C2SP/x509-limbo
- Name: webpki/san: add a valid 127.0.0.1 testcase
- #214 woodruffw: https://github.com/C2SP/x509-limbo/pull/214
- Repo: C2SP/x509-limbo
- Name: add rfc5280::root-and-intermediate-swapped
- #220 woodruffw: https://github.com/C2SP/x509-limbo/pull/220
- Repo: C2SP/x509-limbo
- Name: limbo: add invalid email SAN/NC cases
- #221 woodruffw: https://github.com/C2SP/x509-limbo/pull/221
- Repo: C2SP/x509-limbo
- Name: rfc5280/nc: fix invalid-email-address
- #223 woodruffw: https://github.com/C2SP/x509-limbo/pull/223
- Repo: C2SP/x509-limbo
- Name: harness: add certvalidator
- #224 woodruffw: https://github.com/C2SP/x509-limbo/pull/224
- Repo: C2SP/x509-limbo
- Name: actions/run-harness: refine cache key
- #225 woodruffw: https://github.com/C2SP/x509-limbo/pull/225
- Repo: C2SP/x509-limbo
- Name: limbo: add othername NC testcase
- #228 woodruffw: https://github.com/C2SP/x509-limbo/pull/228
- Repo: C2SP/x509-limbo
- Name: limbo: add an OtherName NC “no-op” case
- #229 woodruffw: https://github.com/C2SP/x509-limbo/pull/229
- Repo: C2SP/x509-limbo
- Name: limbo: fixup docstrings
- #231 woodruffw: https://github.com/C2SP/x509-limbo/pull/231
- Repo: C2SP/x509-limbo
- Name: mkdocs, site: make rendered tables sortable
- #232 woodruffw: https://github.com/C2SP/x509-limbo/pull/232
- Repo: C2SP/x509-limbo
- Name: rfc5280/nc: fixup client auth EKUs
- #233 woodruffw: https://github.com/C2SP/x509-limbo/pull/233
- Repo: C2SP/x509-limbo
- Name: Add importance qualifier to each testcase
- #236 woodruffw: https://github.com/C2SP/x509-limbo/pull/236
- Repo: C2SP/x509-limbo
- Name: limbo: more validity cases
- #237 woodruffw: https://github.com/C2SP/x509-limbo/pull/237
- Repo: C2SP/x509-limbo
- Name: Add a GnuTLS harness
- #240 woodruffw: https://github.com/C2SP/x509-limbo/pull/240
- Repo: C2SP/x509-limbo
- Name: Makefile: fix test-gnutls
- #241 woodruffw: https://github.com/C2SP/x509-limbo/pull/241
- Repo: C2SP/x509-limbo
- Name: limbo: importance API in builder, fill some in
- #244 woodruffw: https://github.com/C2SP/x509-limbo/pull/244
- Repo: C2SP/x509-limbo
- Name: limbo: add san-wildcard-only test
- #250 woodruffw: https://github.com/C2SP/x509-limbo/pull/250
- Repo: C2SP/x509-limbo
- Name: schema: regenerate
- #254 woodruffw: https://github.com/C2SP/x509-limbo/pull/254
- Repo: C2SP/x509-limbo
- Name: limbo: fix ee-empty-issuer testcase
- #271 woodruffw: https://github.com/C2SP/x509-limbo/pull/271
- Repo: C2SP/x509-limbo
- Name: site: trophy case
- #272 woodruffw: https://github.com/C2SP/x509-limbo/pull/272
- Repo: C2SP/x509-limbo
- Name: remove SAN from root in nc::permitted-dn-match
- #287 woodruffw: https://github.com/C2SP/x509-limbo/pull/287
- Repo: C2SP/x509-limbo
- Name: openssl: add 3.3 harness
- #296 woodruffw: https://github.com/C2SP/x509-limbo/pull/296
- Repo: C2SP/x509-limbo
- Name: limbo: add underscore SAN test
- #305 woodruffw: https://github.com/C2SP/x509-limbo/pull/305
- Repo: C2SP/x509-limbo
- Name: limbo: add rfc5280::eku::ee-eku-empty
- #313 woodruffw: https://github.com/C2SP/x509-limbo/pull/313
- Repo: C2SP/x509-limbo
- Name: add openssl 3.4 harness
- #330 woodruffw: https://github.com/C2SP/x509-limbo/pull/330
- Repo: C2SP/x509-limbo
- Name: gocryptox509: fix schema.go
- #352 woodruffw: https://github.com/C2SP/x509-limbo/pull/352
- Repo: C2SP/x509-limbo
- Name: zizmor fixes
- #359 woodruffw: https://github.com/C2SP/x509-limbo/pull/359
- Repo: C2SP/x509-limbo
- Name: add rfc5280::san::ip-in-dns
- #369 woodruffw: https://github.com/C2SP/x509-limbo/pull/369
- Repo: RustCrypto/signatures
- Name: Add SLH-DSA
- #812 tjade273: https://github.com/RustCrypto/signatures/pull/812
- Repo: RustCrypto/signatures
- Name: SLH-DSA: Fix tests with –no-default-features and enable CI
- #814 tjade273: https://github.com/RustCrypto/signatures/pull/814
- Repo: RustCrypto/signatures
- Name: slh-dsa: implement changes from FIP 205 Initial Public Draft -> FIPS 205 Final
- #844 tjade273: https://github.com/RustCrypto/signatures/pull/844
- Repo: alex/rust-asn1
- Name: types: add const generics for SequenceOf length limits
- #470 woodruffw: https://github.com/alex/rust-asn1/pull/470
- Repo: alex/rust-asn1
- Name: rust-asn1: bump to 0.17.0
- #471 woodruffw: https://github.com/alex/rust-asn1/pull/471
- Repo: alex/rust-asn1
- Name: Add GeneralizedTime
- #492 DarkaMaul: https://github.com/alex/rust-asn1/pull/492
- Repo: alex/rust-asn1
- Name: Rename GeneralizedTime to X509GeneralizedTime
- #494 DarkaMaul: https://github.com/alex/rust-asn1/pull/494
- Repo: cr-marcstevens/hashclash
- Name: Fix shebang to support nixos etc.
- #45 disconnect3d: https://github.com/cr-marcstevens/hashclash/pull/45
- Repo: openssl/openssl
- Name: Add provider fuzzer
- #22964 maxammann: https://github.com/openssl/openssl/pull/22964
- Repo: pyca/cryptography
- Name: pypi-publish: tweak OIDC minting endpoint
- #10156 woodruffw: https://github.com/pyca/cryptography/pull/10156
- Repo: pyca/cryptography
- Name: docs/x509: fix verification example
- #10169 woodruffw: https://github.com/pyca/cryptography/pull/10169
- Repo: pyca/cryptography
- Name: fetch-vectors: change repo for x509-limbo
- #10199 woodruffw: https://github.com/pyca/cryptography/pull/10199
- Repo: pyca/cryptography
- Name: Migrate PKCS7 backend to Rust
- #10228 facutuesca: https://github.com/pyca/cryptography/pull/10228
- Repo: pyca/cryptography
- Name: verification: add test_verify_tz_aware
- #10229 woodruffw: https://github.com/pyca/cryptography/pull/10229
- Repo: pyca/cryptography
- Name: parsing, verification: check RSA key size against WebPKI minimum
- #10302 woodruffw: https://github.com/pyca/cryptography/pull/10302
- Repo: pyca/cryptography
- Name: verification/policy: tweak key checks
- #10311 woodruffw: https://github.com/pyca/cryptography/pull/10311
- Repo: pyca/cryptography
- Name: verification/policy: make subject optional internally
- #10335 woodruffw: https://github.com/pyca/cryptography/pull/10335
- Repo: pyca/cryptography
- Name: verification: client verification APIs
- #10345 woodruffw: https://github.com/pyca/cryptography/pull/10345
- Repo: pyca/cryptography
- Name: Support for ECDSA deterministic signing (RFC 6979)
- #10369 facutuesca: https://github.com/pyca/cryptography/pull/10369
- Repo: pyca/cryptography
- Name: Fix ASN.1 issues in PKCS#7 and S/MIME signing
- #10373 facutuesca: https://github.com/pyca/cryptography/pull/10373
- Repo: pyca/cryptography
- Name: policy: Policy::new is now Policy::server
- #10377 woodruffw: https://github.com/pyca/cryptography/pull/10377
- Repo: pyca/cryptography
- Name: Add test vectors for deterministic ECDSA (RFC6979)
- #10438 facutuesca: https://github.com/pyca/cryptography/pull/10438
- Repo: pyca/cryptography
- Name: verification: add RFC822Name
- #10487 woodruffw: https://github.com/pyca/cryptography/pull/10487
- Repo: pyca/cryptography
- Name: verification: add RFC822Constraint
- #10497 woodruffw: https://github.com/pyca/cryptography/pull/10497
- Repo: pyca/cryptography
- Name: test_limbo: skip non-SERVER cases for now
- #10538 woodruffw: https://github.com/pyca/cryptography/pull/10538
- Repo: pyca/cryptography
- Name: test_limbo: skip things more idiomatically
- #10539 woodruffw: https://github.com/pyca/cryptography/pull/10539
- Repo: pyca/cryptography
- Name: verification: forbid unsupported NCs
- #10570 woodruffw: https://github.com/pyca/cryptography/pull/10570
- Repo: pyca/cryptography
- Name: verification: abbreviate two errors slightly
- #10575 woodruffw: https://github.com/pyca/cryptography/pull/10575
- Repo: pyca/cryptography
- Name: Revert “verification: abbreviate two errors slightly (#10575)”
- #10576 woodruffw: https://github.com/pyca/cryptography/pull/10576
- Repo: pyca/cryptography
- Name: CHANGELOG: record new X.509 client verification APIs
- #10615 woodruffw: https://github.com/pyca/cryptography/pull/10615
- Repo: pyca/cryptography
- Name: sign: bound-ify sig_alg APIs
- #10679 woodruffw: https://github.com/pyca/cryptography/pull/10679
- Repo: pyca/cryptography
- Name: Start converting src/backend/rsa.rs to the new pyo3 APIs
- #10693 facutuesca: https://github.com/pyca/cryptography/pull/10693
- Repo: pyca/cryptography
- Name: Convert src/backend/hashes.rs to new pyo3 APIs
- #10705 facutuesca: https://github.com/pyca/cryptography/pull/10705
- Repo: pyca/cryptography
- Name: Convert private_bytes methods to new pyo3 APIs
- #10707 facutuesca: https://github.com/pyca/cryptography/pull/10707
- Repo: pyca/cryptography
- Name: Convert more utils.rs APIs to new pyo3 APIs
- #10708 facutuesca: https://github.com/pyca/cryptography/pull/10708
- Repo: pyca/cryptography
- Name: Convert more APIs in certificate.rs to new pyo3 APIs
- #10709 facutuesca: https://github.com/pyca/cryptography/pull/10709
- Repo: pyca/cryptography
- Name: Finish migrating certificate.rs to new pyo3 APIs
- #10710 facutuesca: https://github.com/pyca/cryptography/pull/10710
- Repo: pyca/cryptography
- Name: Convert src/backend/hmac.rs to new pyo3 APIs
- #10726 facutuesca: https://github.com/pyca/cryptography/pull/10726
- Repo: pyca/cryptography
- Name: Convert src/backend/poly1305.rs to new pyo3 APIs
- #10728 facutuesca: https://github.com/pyca/cryptography/pull/10728
- Repo: pyca/cryptography
- Name: Finish conversion of src/backend/rsa.rs to new pyo3 APIs
- #10729 facutuesca: https://github.com/pyca/cryptography/pull/10729
- Repo: pyca/cryptography
- Name: Convert src/backend/x25519.rs to new pyo3 APIs
- #10730 facutuesca: https://github.com/pyca/cryptography/pull/10730
- Repo: pyca/cryptography
- Name: Convert src/x509/common.rs to new pyo3 APIs
- #10732 facutuesca: https://github.com/pyca/cryptography/pull/10732
- Repo: pyca/cryptography
- Name: Start converting src/x509/csr.rs to new pyo3 APIs
- #10733 facutuesca: https://github.com/pyca/cryptography/pull/10733
- Repo: pyca/cryptography
- Name: Start converting src/x509/verify.rs to new pyo3 APIs
- #10736 facutuesca: https://github.com/pyca/cryptography/pull/10736
- Repo: pyca/cryptography
- Name: Convert more of src/pkcs7.rs to new pyo3 APIs
- #10741 facutuesca: https://github.com/pyca/cryptography/pull/10741
- Repo: pyca/cryptography
- Name: Convert more of src/x509/ocsp_req.rs to new pyo3 APIs
- #10743 facutuesca: https://github.com/pyca/cryptography/pull/10743
- Repo: pyca/cryptography
- Name: Convert src/x509/crl.rs to new pyo3 APIs
- #10744 facutuesca: https://github.com/pyca/cryptography/pull/10744
- Repo: pyca/cryptography
- Name: Convert module-related code to new pyo3 APIs
- #10745 facutuesca: https://github.com/pyca/cryptography/pull/10745
- Repo: pyca/cryptography
- Name: Misc oscp pyo3 migrations
- #10748 facutuesca: https://github.com/pyca/cryptography/pull/10748
- Repo: pyca/cryptography
- Name: Migrate more x509/extensions.rs APIs to new pyo3 APIs (and other migrations)
- #10749 facutuesca: https://github.com/pyca/cryptography/pull/10749
- Repo: pyca/cryptography
- Name: Fix lifetime errors in asn1.rs with gil-refs disabled
- #10778 facutuesca: https://github.com/pyca/cryptography/pull/10778
- Repo: pyca/cryptography
- Name: Fix lifetime errors in extensions.rs and sign.rs with gil-refs disabled
- #10780 facutuesca: https://github.com/pyca/cryptography/pull/10780
- Repo: pyca/cryptography
- Name: Add timezone-aware API variant for x509.InvalidityDate.invalidity_date
- #10848 facutuesca: https://github.com/pyca/cryptography/pull/10848
- Repo: pyca/cryptography
- Name: Add support for encrypting S/MIME messages
- #10889 facutuesca: https://github.com/pyca/cryptography/pull/10889
- Repo: pyca/cryptography
- Name: policy/extension: improve extension policy errors
- #11162 woodruffw: https://github.com/pyca/cryptography/pull/11162
- Repo: pyca/cryptography
- Name: verification: remove an error variant
- #11214 woodruffw: https://github.com/pyca/cryptography/pull/11214
- Repo: pyca/cryptography
- Name: Bump vectors
- #11288 woodruffw: https://github.com/pyca/cryptography/pull/11288
- Repo: pyca/cryptography
- Name: docs: Add instructions to build the docs
- #11290 facutuesca: https://github.com/pyca/cryptography/pull/11290
- Repo: pyca/cryptography
- Name: extensions: EKU must contain at least one member
- #11383 woodruffw: https://github.com/pyca/cryptography/pull/11383
- Repo: pyca/cryptography
- Name: Relax root CA AKI field checks
- #11462 woodruffw: https://github.com/pyca/cryptography/pull/11462
- Repo: pyca/cryptography
- Name: ci: add sigstore as a downstream test
- #12054 woodruffw: https://github.com/pyca/cryptography/pull/12054
- Repo: pyca/cryptography
- Name: downstream: run only sigstore-python unit tests
- #12090 woodruffw: https://github.com/pyca/cryptography/pull/12090
- Repo: pyca/cryptography
- Name: Add identifiers for Hash algorithms
- #12154 DarkaMaul: https://github.com/pyca/cryptography/pull/12154
- Repo: sfackler/rust-openssl
- Name: Add support for setting the nonce type and digest on a PKEY_CTX
- #2144 facutuesca: https://github.com/sfackler/rust-openssl/pull/2144
Languages and compilers
- Repo: airbus-cert/tree-sitter-powershell
- Name: bindings/rust: fix build.rs
- #15 woodruffw: https://github.com/airbus-cert/tree-sitter-powershell/pull/15
- Repo: compiler-explorer/compiler-explorer
- Name: Add vast-trunk compiler
- #5973 xlauko: https://github.com/compiler-explorer/compiler-explorer/pull/5973
- Repo: compiler-explorer/compiler-explorer
- Name: Add VAST as a C compiler and fix paths to resources & toolchain.
- #6147 xlauko: https://github.com/compiler-explorer/compiler-explorer/pull/6147
- Repo: compiler-explorer/infra
- Name: Add vast-trunk compiler
- #1209 xlauko: https://github.com/compiler-explorer/infra/pull/1209
- Repo: compiler-explorer/misc-builder
- Name: vast: Install newly required vcpkg in the builder.
- #93 xlauko: https://github.com/compiler-explorer/misc-builder/pull/93
- Repo: llvm/llvm-project
- Name: [MLIR] Make resolveCallable customizable in CallOpInterface
- #100361 xlauko: https://github.com/llvm/llvm-project/pull/100361
- Repo: llvm/llvm-project
- Name: [mlir][llvm] Align linkage enum order with LLVM (NFC)
- #118484 xlauko: https://github.com/llvm/llvm-project/pull/118484
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Annotating std::basic_string with all allocators
- #75845 AdvenamTacet: https://github.com/llvm/llvm-project/pull/75845
- Repo: llvm/llvm-project
- Name: [libc++] Remove usage of internal string function in sstream
- #75858 AdvenamTacet: https://github.com/llvm/llvm-project/pull/75858
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Turn on ASan annotations for short strings
- #75882 AdvenamTacet: https://github.com/llvm/llvm-project/pull/75882
- Repo: llvm/llvm-project
- Name: [ASan][libc++] String annotations optimizations fix with lambda
- #76200 AdvenamTacet: https://github.com/llvm/llvm-project/pull/76200
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Initialize __r_ variable with lambda
- #77394 AdvenamTacet: https://github.com/llvm/llvm-project/pull/77394
- Repo: llvm/llvm-project
- Name: [ASan][libc++][NFC] refactor vector annotations arguments
- #78322 AdvenamTacet: https://github.com/llvm/llvm-project/pull/78322
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Turn on ASan annotations for short strings
- #79049 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79049
- Repo: llvm/llvm-project
- Name: [ASan][JSON] Unpoison memory before its reuse
- #79065 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79065
- Repo: llvm/llvm-project
- Name: [ASan][ADT] Don’t scribble with ASan
- #79066 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79066
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Correct (explicit) annotation size
- #79292 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79292
- Repo: llvm/llvm-project
- Name: Make two texts static in ReplayInlineAdvisor
- #79489 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79489
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Turn on ASan annotations for short strings
- #79536 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79536
- Repo: llvm/llvm-project
- Name: Remove unnecessary _LIBCPP_STRING_INTERNAL_MEMORY_ACCESS
- #79574 AdvenamTacet: https://github.com/llvm/llvm-project/pull/79574
- Repo: llvm/llvm-project
- Name: [mlir] Fix debug output for passes that modify top-level operation.
- #80022 Jezurko: https://github.com/llvm/llvm-project/pull/80022
- Repo: llvm/llvm-project
- Name: [libc++] Add details about string annotations
- #80912 AdvenamTacet: https://github.com/llvm/llvm-project/pull/80912
- Repo: llvm/llvm-project
- Name: [libc++] Add details about string annotations
- #82730 AdvenamTacet: https://github.com/llvm/llvm-project/pull/82730
- Repo: llvm/llvm-project
- Name: [libc++][ASan] Fix std::basic_string trait type
- #91590 AdvenamTacet: https://github.com/llvm/llvm-project/pull/91590
- Repo: llvm/llvm-project
- Name: [compiler-rt][ASan] Add function copying annotations
- #91702 AdvenamTacet: https://github.com/llvm/llvm-project/pull/91702
- Repo: llvm/llvm-project
- Name: [compiler-rt][ASan] Remove alignment message in ASan error reporting
- #94103 AdvenamTacet: https://github.com/llvm/llvm-project/pull/94103
- Repo: llvm/llvm-project
- Name: [ASan][libc++] Turn off SSO annotations for Apple platforms
- #96269 AdvenamTacet: https://github.com/llvm/llvm-project/pull/96269
Libraries
- Repo: AFLplusplus/AFLplusplus
- Name: afl-persistent-config: Use GRUB_CMDLINE_LINUX instead of GRUB_CMDLINE_LINUX_DEFAULT
- #1998 maxammann: https://github.com/AFLplusplus/AFLplusplus/pull/1998
- Repo: AFLplusplus/LibAFL
- Name: Fix libafl_libfuzzer’s compatibility with LLVM 14
- #2136 maxammann: https://github.com/AFLplusplus/LibAFL/pull/2136
- Repo: AFLplusplus/LibAFL
- Name: Use MultiMonitor when fuzzing in non-forking mode
- #2192 maxammann: https://github.com/AFLplusplus/LibAFL/pull/2192
- Repo: AFLplusplus/LibAFL
- Name: Add documentation for InProcessForkExecutor
- #2378 maxammann: https://github.com/AFLplusplus/LibAFL/pull/2378
- Repo: curl/curl-fuzzer
- Name: Resolve i386 build warnings and errors
- #103 elopez: https://github.com/curl/curl-fuzzer/pull/103
- Repo: curl/curl-fuzzer
- Name: Add bufq fuzzing harness
- #98 elopez: https://github.com/curl/curl-fuzzer/pull/98
- Repo: di/id
- Name: prep 1.4.0
- #219 woodruffw: https://github.com/di/id/pull/219
- Repo: di/id
- Name: pyproject: include test dir in sdist
- #288 woodruffw: https://github.com/di/id/pull/288
- Repo: di/id
- Name: release: enable PEP 740 attestations
- #291 woodruffw: https://github.com/di/id/pull/291
- Repo: di/id
- Name: workflows, pyproject: 3.13, zizmor fixes
- #314 woodruffw: https://github.com/di/id/pull/314
- Repo: di/id
- Name: refactor: drop pydantic dep
- #320 woodruffw: https://github.com/di/id/pull/320
- Repo: di/id
- Name: id: prep 1.5.0
- #321 woodruffw: https://github.com/di/id/pull/321
- Repo: di/pip-api
- Name: github: add dependabot config for GHA
- #203 woodruffw: https://github.com/di/pip-api/pull/203
- Repo: di/pip-api
- Name: tox: add pip2400
- #204 woodruffw: https://github.com/di/pip-api/pull/204
- Repo: di/pip-api
- Name: pip_api: don’t pass escaped path into _parse_local_package_name
- #208 woodruffw: https://github.com/di/pip-api/pull/208
- Repo: di/pip-api
- Name: prep 0.0.32
- #209 woodruffw: https://github.com/di/pip-api/pull/209
- Repo: di/pip-api
- Name: fix release workflow, corrective release
- #210 woodruffw: https://github.com/di/pip-api/pull/210
- Repo: di/pip-api
- Name: tox: add pip==24.1b1
- #213 woodruffw: https://github.com/di/pip-api/pull/213
- Repo: di/pip-api
- Name: tox: pip241b2
- #216 woodruffw: https://github.com/di/pip-api/pull/216
- Repo: di/pip-api
- Name: tox: pip==24.1
- #218 woodruffw: https://github.com/di/pip-api/pull/218
- Repo: di/pip-api
- Name: tox: pip==24.1.1
- #220 woodruffw: https://github.com/di/pip-api/pull/220
- Repo: di/pip-api
- Name: tox: pip==24.1.2
- #222 woodruffw: https://github.com/di/pip-api/pull/222
- Repo: di/pip-api
- Name: meta: drop support for Python 3.7
- #223 woodruffw: https://github.com/di/pip-api/pull/223
- Repo: di/pip-api
- Name: prep 0.0.34
- #224 woodruffw: https://github.com/di/pip-api/pull/224
- Repo: di/pip-api
- Name: tox: pip==24.2
- #227 woodruffw: https://github.com/di/pip-api/pull/227
- Repo: di/pip-api
- Name: README: remove old version availability headers
- #229 woodruffw: https://github.com/di/pip-api/pull/229
- Repo: di/pip-api
- Name: tox, tests: drop virtualenv dependency
- #231 woodruffw: https://github.com/di/pip-api/pull/231
- Repo: di/pip-api
- Name: tox: pip==24.3
- #234 woodruffw: https://github.com/di/pip-api/pull/234
- Repo: psastras/sarif-rs
- Name: feat: collect clippy’s results children spans in related_locations
- #585 fcasal: https://github.com/psastras/sarif-rs/pull/585
- Repo: psf/cachecontrol
- Name: github: bump signing step, use dependabot
- #329 woodruffw: https://github.com/psf/cachecontrol/pull/329
- Repo: psf/cachecontrol
- Name: workflows/tests: patch macos runner version for 3.7
- #334 woodruffw: https://github.com/psf/cachecontrol/pull/334
- Repo: psf/cachecontrol
- Name: drop Python 3.7, add 3.13
- #340 woodruffw: https://github.com/psf/cachecontrol/pull/340
- Repo: psf/cachecontrol
- Name: ci: harden workflows
- #345 woodruffw: https://github.com/psf/cachecontrol/pull/345
- Repo: psf/cachecontrol
- Name: chore: prep 0.14.2
- #350 woodruffw: https://github.com/psf/cachecontrol/pull/350
- Repo: pypi/stdlib-list
- Name: docs: module inclusion policy
- #119 woodruffw: https://github.com/pypi/stdlib-list/pull/119
- Repo: pypi/stdlib-list
- Name: drop 3.7 and 3.8, prep for 3.13
- #131 woodruffw: https://github.com/pypi/stdlib-list/pull/131
- Repo: pypi/stdlib-list
- Name: bump version ranges to 3.13
- #133 woodruffw: https://github.com/pypi/stdlib-list/pull/133
- Repo: pypi/stdlib-list
- Name: CI: enable attestations, cleanup
- #134 woodruffw: https://github.com/pypi/stdlib-list/pull/134
- Repo: pypi/stdlib-list
- Name: ci: fix zizmor findings, add zizmor workflow
- #138 woodruffw: https://github.com/pypi/stdlib-list/pull/138
- Repo: sigstore/fulcio
- Name: oid-info: fix table render
- #1662 woodruffw: https://github.com/sigstore/fulcio/pull/1662
- Repo: sigstore/protobuf-specs
- Name: gen, protos: 0.3, single cert
- #191 woodruffw: https://github.com/sigstore/protobuf-specs/pull/191
- Repo: sigstore/protobuf-specs
- Name: python: 0.3.0rc0, realign deps
- #196 woodruffw: https://github.com/sigstore/protobuf-specs/pull/196
- Repo: sigstore/protobuf-specs
- Name: CHANGELOG: record recent changes
- #197 woodruffw: https://github.com/sigstore/protobuf-specs/pull/197
- Repo: sigstore/protobuf-specs
- Name: Add RSA variants, experimental LMS and LM-OTS to algorithm registry
- #199 woodruffw: https://github.com/sigstore/protobuf-specs/pull/199
- Repo: sigstore/protobuf-specs
- Name: protos: drop EXPERIMENTAL_ prefix
- #214 woodruffw: https://github.com/sigstore/protobuf-specs/pull/214
- Repo: sigstore/protobuf-specs
- Name: fixup rust publishing
- #223 woodruffw: https://github.com/sigstore/protobuf-specs/pull/223
- Repo: sigstore/protobuf-specs
- Name: Rust 0.3.1
- #225 woodruffw: https://github.com/sigstore/protobuf-specs/pull/225
- Repo: sigstore/protobuf-specs
- Name: rust: prep 0.3.2
- #226 woodruffw: https://github.com/sigstore/protobuf-specs/pull/226
- Repo: sigstore/protobuf-specs
- Name: rust: make cargo build slightly more debuggable
- #227 woodruffw: https://github.com/sigstore/protobuf-specs/pull/227
- Repo: sigstore/protobuf-specs
- Name: rust: 0.3.3
- #233 woodruffw: https://github.com/sigstore/protobuf-specs/pull/233
- Repo: sigstore/protobuf-specs
- Name: rust: post-release cleanup
- #234 woodruffw: https://github.com/sigstore/protobuf-specs/pull/234
- Repo: sigstore/protobuf-specs
- Name: events.proto: ruby_package
- #264 woodruffw: https://github.com/sigstore/protobuf-specs/pull/264
- Repo: sigstore/protobuf-specs
- Name: trustroot: initial client config messages
- #277 woodruffw: https://github.com/sigstore/protobuf-specs/pull/277
- Repo: sigstore/protobuf-specs
- Name: python: add a py.typed marker
- #287 woodruffw: https://github.com/sigstore/protobuf-specs/pull/287
- Repo: sigstore/protobuf-specs
- Name: gen: bump patch versions
- #319 woodruffw: https://github.com/sigstore/protobuf-specs/pull/319
- Repo: sigstore/protobuf-specs
- Name: gen: bump JS patch version
- #321 woodruffw: https://github.com/sigstore/protobuf-specs/pull/321
- Repo: sigstore/protobuf-specs
- Name: rust: bump patch
- #328 woodruffw: https://github.com/sigstore/protobuf-specs/pull/328
- Repo: sigstore/protobuf-specs
- Name: sigstore_rekor: clarify inclusion_promise requirement
- #380 woodruffw: https://github.com/sigstore/protobuf-specs/pull/380
- Repo: sigstore/protobuf-specs
- Name: python: bump betterproto dep
- #404 woodruffw: https://github.com/sigstore/protobuf-specs/pull/404
- Repo: sigstore/protobuf-specs
- Name: python: prep 0.3.3
- #405 woodruffw: https://github.com/sigstore/protobuf-specs/pull/405
- Repo: sigstore/rekor
- Name: hashedrekord: fix schema $id
- #2092 woodruffw: https://github.com/sigstore/rekor/pull/2092
- Repo: sigstore/root-signing
- Name: workflows: address zizmor findings
- #1397 woodruffw: https://github.com/sigstore/root-signing/pull/1397
- Repo: sigstore/sigstore-go
- Name: ci: address zizmor’s findings
- #336 woodruffw: https://github.com/sigstore/sigstore-go/pull/336
- Repo: sigstore/sigstore-python
- Name: _cli: emit .sigstore.json by default
- #1007 woodruffw: https://github.com/sigstore/sigstore-python/pull/1007
- Repo: sigstore/sigstore-python
- Name: sigstore: uniform user-agent with sigstore version
- #1008 woodruffw: https://github.com/sigstore/sigstore-python/pull/1008
- Repo: sigstore/sigstore-python
- Name: Refactor client trust/trust root management
- #1010 woodruffw: https://github.com/sigstore/sigstore-python/pull/1010
- Repo: sigstore/sigstore-python
- Name: bump sigstore-protobuf-specs
- #1013 woodruffw: https://github.com/sigstore/sigstore-python/pull/1013
- Repo: sigstore/sigstore-python
- Name: cli: allow DSSE verification
- #1015 woodruffw: https://github.com/sigstore/sigstore-python/pull/1015
- Repo: sigstore/sigstore-python
- Name: oidc: rename expected_certificate_subject -> federated_issuer
- #1016 woodruffw: https://github.com/sigstore/sigstore-python/pull/1016
- Repo: sigstore/sigstore-python
- Name: README: improve verify github examples
- #1020 woodruffw: https://github.com/sigstore/sigstore-python/pull/1020
- Repo: sigstore/sigstore-python
- Name: sigstore: 3.0.0
- #1021 woodruffw: https://github.com/sigstore/sigstore-python/pull/1021
- Repo: sigstore/sigstore-python
- Name: release: switch to non-deprecated setting
- #1022 woodruffw: https://github.com/sigstore/sigstore-python/pull/1022
- Repo: sigstore/sigstore-python
- Name: release: remove pip cache usage
- #1025 woodruffw: https://github.com/sigstore/sigstore-python/pull/1025
- Repo: sigstore/sigstore-python
- Name: checkpoint: fix a typo
- #1036 woodruffw: https://github.com/sigstore/sigstore-python/pull/1036
- Repo: sigstore/sigstore-python
- Name: dsse: add Envelope._from_json
- #1039 woodruffw: https://github.com/sigstore/sigstore-python/pull/1039
- Repo: sigstore/sigstore-python
- Name: sigstore: type cleanup
- #1052 woodruffw: https://github.com/sigstore/sigstore-python/pull/1052
- Repo: sigstore/sigstore-python
- Name: models: add type annotation
- #1060 woodruffw: https://github.com/sigstore/sigstore-python/pull/1060
- Repo: sigstore/sigstore-python
- Name: sigstore/dsse: reject DSSEs with >1 sig
- #1062 woodruffw: https://github.com/sigstore/sigstore-python/pull/1062
- Repo: sigstore/sigstore-python
- Name: API: make _StatementBuilder public
- #1077 woodruffw: https://github.com/sigstore/sigstore-python/pull/1077
- Repo: sigstore/sigstore-python
- Name: dsse: make constituent types public
- #1078 woodruffw: https://github.com/sigstore/sigstore-python/pull/1078
- Repo: sigstore/sigstore-python
- Name: prep 3.1.0
- #1079 woodruffw: https://github.com/sigstore/sigstore-python/pull/1079
- Repo: sigstore/sigstore-python
- Name: add fix-bundle plumbing command
- #1089 woodruffw: https://github.com/sigstore/sigstore-python/pull/1089
- Repo: sigstore/sigstore-python
- Name: prep 3.2.0
- #1094 woodruffw: https://github.com/sigstore/sigstore-python/pull/1094
- Repo: sigstore/sigstore-python
- Name: workflows: various CQA fixes
- #1140 woodruffw: https://github.com/sigstore/sigstore-python/pull/1140
- Repo: sigstore/sigstore-python
- Name: cli: –offline means fully offline
- #1143 woodruffw: https://github.com/sigstore/sigstore-python/pull/1143
- Repo: sigstore/sigstore-python
- Name: workflows/release: enable PEP 740 attestations
- #1145 woodruffw: https://github.com/sigstore/sigstore-python/pull/1145
- Repo: sigstore/sigstore-python
- Name: pyproject: pin protobuf-specs
- #1149 woodruffw: https://github.com/sigstore/sigstore-python/pull/1149
- Repo: sigstore/sigstore-python
- Name: _cli: files always take precedence over digests
- #1152 woodruffw: https://github.com/sigstore/sigstore-python/pull/1152
- Repo: sigstore/sigstore-python
- Name: pyproject: fix status classifier
- #1154 woodruffw: https://github.com/sigstore/sigstore-python/pull/1154
- Repo: sigstore/sigstore-python
- Name: bump minimum Python to 3.9
- #1163 woodruffw: https://github.com/sigstore/sigstore-python/pull/1163
- Repo: sigstore/sigstore-python
- Name: prep 3.4.0
- #1168 woodruffw: https://github.com/sigstore/sigstore-python/pull/1168
- Repo: sigstore/sigstore-python
- Name: workflows/requirements: remove a lingering 3.8 reference
- #1170 woodruffw: https://github.com/sigstore/sigstore-python/pull/1170
- Repo: sigstore/sigstore-python
- Name: _cli: add plumbing update-trust-root
- #1174 woodruffw: https://github.com/sigstore/sigstore-python/pull/1174
- Repo: sigstore/sigstore-python
- Name: _cli: don’t warn on bare .sigstore if cert/sig is used
- #1179 woodruffw: https://github.com/sigstore/sigstore-python/pull/1179
- Repo: sigstore/sigstore-python
- Name: Prep 3.5.0
- #1184 woodruffw: https://github.com/sigstore/sigstore-python/pull/1184
- Repo: sigstore/sigstore-python
- Name: README: bump tag for gh-action-sigstore-python
- #1191 woodruffw: https://github.com/sigstore/sigstore-python/pull/1191
- Repo: sigstore/sigstore-python
- Name: _cli: fix warning check
- #1192 woodruffw: https://github.com/sigstore/sigstore-python/pull/1192
- Repo: sigstore/sigstore-python
- Name: sigstore: prep 3.5.1
- #1193 woodruffw: https://github.com/sigstore/sigstore-python/pull/1193
- Repo: sigstore/sigstore-python
- Name: pyproject: bump sigstore-rekor-types
- #1222 woodruffw: https://github.com/sigstore/sigstore-python/pull/1222
- Repo: sigstore/sigstore-python
- Name: CHANGELOG: record #1216
- #1224 woodruffw: https://github.com/sigstore/sigstore-python/pull/1224
- Repo: sigstore/sigstore-python
- Name: pyproject: constrain cryptography < 44
- #1229 woodruffw: https://github.com/sigstore/sigstore-python/pull/1229
- Repo: sigstore/sigstore-python
- Name: fulcio: remove ABC registration
- #1235 woodruffw: https://github.com/sigstore/sigstore-python/pull/1235
- Repo: sigstore/sigstore-python
- Name: fulcio: remove detached SCT support
- #1236 woodruffw: https://github.com/sigstore/sigstore-python/pull/1236
- Repo: sigstore/sigstore-python
- Name: conftest: tweak _has_oidc_id to only check our repo
- #1237 woodruffw: https://github.com/sigstore/sigstore-python/pull/1237
- Repo: sigstore/sigstore-python
- Name: fix: require an inclusion promise when log integration time is used
- #1247 woodruffw: https://github.com/sigstore/sigstore-python/pull/1247
- Repo: sigstore/sigstore-python
- Name: prep 3.6.0
- #1248 woodruffw: https://github.com/sigstore/sigstore-python/pull/1248
- Repo: sigstore/sigstore-python
- Name: bump rfc3161-client
- #1251 woodruffw: https://github.com/sigstore/sigstore-python/pull/1251
- Repo: sigstore/sigstore-python
- Name: sigstore: prep 3.6.1
- #1263 woodruffw: https://github.com/sigstore/sigstore-python/pull/1263
- Repo: sigstore/sigstore-python
- Name: dependabot: group GHA updates
- #855 woodruffw: https://github.com/sigstore/sigstore-python/pull/855
- Repo: sigstore/sigstore-python
- Name: API: remove SigningResult
- #862 woodruffw: https://github.com/sigstore/sigstore-python/pull/862
- Repo: sigstore/sigstore-python
- Name: Fix interrogate usage, clean up linting
- #875 woodruffw: https://github.com/sigstore/sigstore-python/pull/875
- Repo: sigstore/sigstore-python
- Name: rekor/checkpoint: handle missing ancillary data
- #891 woodruffw: https://github.com/sigstore/sigstore-python/pull/891
- Repo: sigstore/sigstore-python
- Name: Merge CLs from 2.1.x series
- #893 woodruffw: https://github.com/sigstore/sigstore-python/pull/893
- Repo: sigstore/sigstore-python
- Name: sigstore: v3 bundles
- #901 woodruffw: https://github.com/sigstore/sigstore-python/pull/901
- Repo: sigstore/sigstore-python
- Name: sigstore: prep verify APIs for DSSE
- #904 woodruffw: https://github.com/sigstore/sigstore-python/pull/904
- Repo: sigstore/sigstore-python
- Name: sigstore/sign: sign API takes bytes, not I/O
- #921 woodruffw: https://github.com/sigstore/sigstore-python/pull/921
- Repo: sigstore/sigstore-python
- Name: verifier: set store flags explicitly
- #924 woodruffw: https://github.com/sigstore/sigstore-python/pull/924
- Repo: sigstore/sigstore-python
- Name: sigstore: use our own Statement type
- #930 woodruffw: https://github.com/sigstore/sigstore-python/pull/930
- Repo: sigstore/sigstore-python
- Name: sign: fix envelope type
- #935 woodruffw: https://github.com/sigstore/sigstore-python/pull/935
- Repo: sigstore/sigstore-python
- Name: Remove VerificationMaterials (take 2)
- #937 woodruffw: https://github.com/sigstore/sigstore-python/pull/937
- Repo: sigstore/sigstore-python
- Name: pyproject: bump protobuf specs
- #943 woodruffw: https://github.com/sigstore/sigstore-python/pull/943
- Repo: sigstore/sigstore-python
- Name: CHANGELOG: backport 2.1.3 CL
- #944 woodruffw: https://github.com/sigstore/sigstore-python/pull/944
- Repo: sigstore/sigstore-python
- Name: sigstore: use rfc8785 for SET canonicalization
- #945 woodruffw: https://github.com/sigstore/sigstore-python/pull/945
- Repo: sigstore/sigstore-python
- Name: Bump protobuf-specs, handle v3 media types
- #952 woodruffw: https://github.com/sigstore/sigstore-python/pull/952
- Repo: sigstore/sigstore-python
- Name: sigstore, test: honor PublicKeyDetails when loading Keyrings
- #953 woodruffw: https://github.com/sigstore/sigstore-python/pull/953
- Repo: sigstore/sigstore-python
- Name: sigstore: rename more logger instances
- #955 woodruffw: https://github.com/sigstore/sigstore-python/pull/955
- Repo: sigstore/sigstore-python
- Name: sigstore, test: break apart DSSE/artifact sign APIs
- #956 woodruffw: https://github.com/sigstore/sigstore-python/pull/956
- Repo: sigstore/sigstore-python
- Name: sigstore, test: drastically simplify error types
- #959 woodruffw: https://github.com/sigstore/sigstore-python/pull/959
- Repo: sigstore/sigstore-python
- Name: Initial DSSE verify APIs
- #962 woodruffw: https://github.com/sigstore/sigstore-python/pull/962
- Repo: sigstore/sigstore-python
- Name: rename sign_intoto -> sign_dsse
- #972 woodruffw: https://github.com/sigstore/sigstore-python/pull/972
- Repo: sigstore/sigstore-python
- Name: bump sigstore-rekor-types, add NOTE
- #981 woodruffw: https://github.com/sigstore/sigstore-python/pull/981
- Repo: sigstore/sigstore-python
- Name: sigstore: flatten models into sigstore.models
- #990 woodruffw: https://github.com/sigstore/sigstore-python/pull/990
- Repo: sigstore/sigstore-python
- Name: test_sign: disable more staging tests
- #997 woodruffw: https://github.com/sigstore/sigstore-python/pull/997
- Repo: sigstore/sigstore-python
- Name: sigstore: 3.0.0rc1
- #998 woodruffw: https://github.com/sigstore/sigstore-python/pull/998
Tech infrastructure
- Repo: Homebrew/homebrew-core
- Name: caracal 0.2.3
- #160933 elopez: https://github.com/Homebrew/homebrew-core/pull/160933
- Repo: Homebrew/homebrew-core
- Name: medusa 0.1.3
- #164794 elopez: https://github.com/Homebrew/homebrew-core/pull/164794
- Repo: Homebrew/homebrew-core
- Name: slither-analyzer 0.10.1
- #164797 elopez: https://github.com/Homebrew/homebrew-core/pull/164797
- Repo: Homebrew/homebrew-core
- Name: slither-analyzer 0.10.3
- #173841 elopez: https://github.com/Homebrew/homebrew-core/pull/173841
- Repo: aws/aws-nitro-enclaves-cli
- Name: command_executer – recv infinite loop
- #609 GrosQuildu: https://github.com/aws/aws-nitro-enclaves-cli/pull/609
- Repo: aws/aws-nitro-enclaves-sdk-bootstrap
- Name: Update init.c – off-by-one fix
- #27 GrosQuildu: https://github.com/aws/aws-nitro-enclaves-sdk-bootstrap/pull/27
- Repo: osquery/osquery
- Name: Changelog 5.11.0
- #8231 Smjert: https://github.com/osquery/osquery/pull/8231
- Repo: osquery/osquery
- Name: cmake: Correct typo, semvar -> semver
- #8234 Smjert: https://github.com/osquery/osquery/pull/8234
- Repo: osquery/osquery
- Name: test: Fix vscodeExtensions.test_sanity test
- #8236 Smjert: https://github.com/osquery/osquery/pull/8236
- Repo: osquery/osquery
- Name: cmake: Pass the osquery python path to googletest
- #8237 Smjert: https://github.com/osquery/osquery/pull/8237
- Repo: osquery/osquery
- Name: ci: Use all available cores and print more stats
- #8248 Smjert: https://github.com/osquery/osquery/pull/8248
- Repo: osquery/osquery
- Name: cve: Update sqlite to 3.45.0
- #8259 Smjert: https://github.com/osquery/osquery/pull/8259
- Repo: osquery/osquery
- Name: cve: Update openssl to 3.2.1
- #8262 Smjert: https://github.com/osquery/osquery/pull/8262
- Repo: osquery/osquery
- Name: cve: Update libexpat to 2.6.0
- #8281 Smjert: https://github.com/osquery/osquery/pull/8281
- Repo: osquery/osquery
- Name: cve: Remove libxml2 dependency
- #8282 Smjert: https://github.com/osquery/osquery/pull/8282
- Repo: osquery/osquery
- Name: Downgrade sqlite to 3.42 to prevent a regression with required columns
- #8295 Smjert: https://github.com/osquery/osquery/pull/8295
- Repo: osquery/osquery
- Name: CI: Fix macOS python dependencies install step
- #8308 Smjert: https://github.com/osquery/osquery/pull/8308
- Repo: osquery/osquery
- Name: docs: Correct 5.12.2 changelog
- #8348 Smjert: https://github.com/osquery/osquery/pull/8348
- Repo: osquery/osquery
- Name: CI: Update macos builder to 14 and tester to 12
- #8359 Smjert: https://github.com/osquery/osquery/pull/8359
- Repo: osquery/osquery
- Name: ci: Update Linux Docker image to Ubuntu 20.04
- #8369 Smjert: https://github.com/osquery/osquery/pull/8369
- Repo: osquery/osquery
- Name: build: Correct xz submodule url and openssl download url
- #8383 Smjert: https://github.com/osquery/osquery/pull/8383
- Repo: osquery/osquery
- Name: libs: Update rpm to 4.18.2
- #8388 Smjert: https://github.com/osquery/osquery/pull/8388
- Repo: osquery/osquery
- Name: Minor improvements to the hashing logic
- #8398 Smjert: https://github.com/osquery/osquery/pull/8398
- Repo: osquery/osquery
- Name: build: Silence deprecation warnings about non standard extensions on VS2022
- #8405 Smjert: https://github.com/osquery/osquery/pull/8405
- Repo: osquery/osquery
- Name: improvement: refactor readFile
- #8410 Smjert: https://github.com/osquery/osquery/pull/8410
- Repo: osquery/osquery
- Name: build: Cleanups and fixes for a newer clang toolchain
- #8412 Smjert: https://github.com/osquery/osquery/pull/8412
- Repo: osquery/osquery
- Name: ci: Update the upload-artifact action to v4.4.0
- #8416 Smjert: https://github.com/osquery/osquery/pull/8416
- Repo: osquery/osquery
- Name: table: Remove support for deprecated Safari Legacy Extensions
- #8426 Smjert: https://github.com/osquery/osquery/pull/8426
- Repo: osquery/osquery
- Name: Fix: safari_extensions not returning results
- #8427 Smjert: https://github.com/osquery/osquery/pull/8427
- Repo: osquery/osquery
- Name: fix: Handle strftime potential error in the time table
- #8431 Smjert: https://github.com/osquery/osquery/pull/8431
- Repo: osquery/osquery
- Name: CI: Add a specific package build folder on Windows jobs
- #8446 Smjert: https://github.com/osquery/osquery/pull/8446
- Repo: osquery/osquery
- Name: ci: Update all Github actions to a version using NodeJs 20
- #8449 Smjert: https://github.com/osquery/osquery/pull/8449
- Repo: osquery/osquery
- Name: Fix unified_log handling of timestamp formats
- #8451 Smjert: https://github.com/osquery/osquery/pull/8451
- Repo: osquery/osquery
- Name: tests: Ensure python http server is ready to serve
- #8452 Smjert: https://github.com/osquery/osquery/pull/8452
- Repo: osquery/osquery
- Name: ci: Restrict python versions differently
- #8453 Smjert: https://github.com/osquery/osquery/pull/8453
- Repo: osquery/osquery
- Name: ci: Reduce scheduled builds amount
- #8457 Smjert: https://github.com/osquery/osquery/pull/8457
- Repo: osquery/osquery
- Name: ci: Update macOS test runner from 12 to 13
- #8459 Smjert: https://github.com/osquery/osquery/pull/8459
- Repo: osquery/osquery
- Name: Fix a leak in genAarch64PlatformInfo
- #8462 Smjert: https://github.com/osquery/osquery/pull/8462
- Repo: osquery/osquery
- Name: Fix a leak in DiskArbitrationEventPublisher::getProperty
- #8463 Smjert: https://github.com/osquery/osquery/pull/8463
- Repo: osquery/osquery
- Name: ci: Update xcode version for macos-14 from 14.3.1 to 15.4
- #8467 Smjert: https://github.com/osquery/osquery/pull/8467
- Repo: osquery/osquery
- Name: docs: Update expired Slack invite
- #8488 Smjert: https://github.com/osquery/osquery/pull/8488
- Repo: python/peps
- Name: PEP 740: Index support for digital attestations
- #3618 woodruffw: https://github.com/python/peps/pull/3618
- Repo: python/peps
- Name: PEP 740: update discussions-to
- #3635 woodruffw: https://github.com/python/peps/pull/3635
- Repo: python/peps
- Name: PEP 740: initial feedback
- #3637 woodruffw: https://github.com/python/peps/pull/3637
- Repo: python/peps
- Name: PEP 740: Feedback, round 2
- #3692 woodruffw: https://github.com/python/peps/pull/3692
- Repo: python/peps
- Name: PEP 740: tweak JSON simple API prescriptions
- #3768 woodruffw: https://github.com/python/peps/pull/3768
- Repo: python/peps
- Name: PEP 740: Mark as Provisional
- #3848 woodruffw: https://github.com/python/peps/pull/3848
- Repo: python/peps
- Name: PEP 748: A Unified TLS API for Python
- #3853 woodruffw: https://github.com/python/peps/pull/3853
- Repo: python/peps
- Name: PEP 740: clarify that provenance is nullable
- #3906 woodruffw: https://github.com/python/peps/pull/3906
- Repo: python/peps
- Name: PEP 753: Uniform URLs in core metadata
- #3936 woodruffw: https://github.com/python/peps/pull/3936
- Repo: python/peps
- Name: PEP 740: data-provenance attribute value tweaks
- #3971 woodruffw: https://github.com/python/peps/pull/3971
- Repo: python/peps
- Name: PEP 753: Add suggested human-readable labels
- #3974 woodruffw: https://github.com/python/peps/pull/3974
- Repo: python/peps
- Name: PEP 740: Update api-version
- #4001 woodruffw: https://github.com/python/peps/pull/4001
- Repo: python/peps
- Name: PEP 753: Updates
- #4010 woodruffw: https://github.com/python/peps/pull/4010
- Repo: python/peps
- Name: PEP 753: updates
- #4039 woodruffw: https://github.com/python/peps/pull/4039
- Repo: python/peps
- Name: PEP 753: Mark as Accepted
- #4043 woodruffw: https://github.com/python/peps/pull/4043
- Repo: python/peps
- Name: PEP 763: Limiting deletions on PyPI
- #4080 woodruffw: https://github.com/python/peps/pull/4080
- Repo: python/peps
- Name: PEP 763: add Discussions-To
- #4089 woodruffw: https://github.com/python/peps/pull/4089
- Repo: python/peps
- Name: PEP 763: add an appendix comparing ecosystems
- #4091 woodruffw: https://github.com/python/peps/pull/4091
- Repo: python/peps
- Name: PEP 763: add Hackage and OPAM
- #4092 woodruffw: https://github.com/python/peps/pull/4092
- Repo: python/peps
- Name: PEP 753: link to PyPA spec
- #4095 woodruffw: https://github.com/python/peps/pull/4095
- Repo: python/peps
- Name: PEP 740: Mark as Final
- #4114 woodruffw: https://github.com/python/peps/pull/4114
- Repo: re-actors/checkout-python-sdist
- Name: Bump download-artifact to v4
- #3 woodruffw: https://github.com/re-actors/checkout-python-sdist/pull/3
- Repo: sigstore-conformance/extremely-dangerous-public-oidc-beacon
- Name: dependabot: keep actions updated
- #9 woodruffw: https://github.com/sigstore-conformance/extremely-dangerous-public-oidc-beacon/pull/9
- Repo: sigstore/architecture-docs
- Name: client-spec: fix links, clarify leaf checks
- #19 woodruffw: https://github.com/sigstore/architecture-docs/pull/19
- Repo: sigstore/community
- Name: sigstore/repositories: update Python repo maintainers
- #519 woodruffw: https://github.com/sigstore/community/pull/519
- Repo: sigstore/docs
- Name: python: doc tweaks
- #340 woodruffw: https://github.com/sigstore/docs/pull/340
- Repo: sigstore/gh-action-sigstore-python
- Name: CI: add dependabot config
- #101 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/101
- Repo: sigstore/gh-action-sigstore-python
- Name: Fix release-signing-artifacts behavior and docs
- #103 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/103
- Repo: sigstore/gh-action-sigstore-python
- Name: action: use shlex.split
- #104 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/104
- Repo: sigstore/gh-action-sigstore-python
- Name: action: allow ** globs
- #106 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/106
- Repo: sigstore/gh-action-sigstore-python
- Name: schedule-selftest: reduce nagging
- #134 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/134
- Repo: sigstore/gh-action-sigstore-python
- Name: requirements: sigstore ~3.0
- #140 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/140
- Repo: sigstore/gh-action-sigstore-python
- Name: action: flip release-signing-artifacts
- #142 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/142
- Repo: sigstore/gh-action-sigstore-python
- Name: Prep 3.0.0
- #143 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/143
- Repo: sigstore/gh-action-sigstore-python
- Name: action: use a venv to prevent PEP 668 errors
- #145 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/145
- Repo: sigstore/gh-action-sigstore-python
- Name: action: remove old output settings
- #146 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/146
- Repo: sigstore/gh-action-sigstore-python
- Name: setup, requirements: bump to Python 3.9
- #155 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/155
- Repo: sigstore/gh-action-sigstore-python
- Name: requirements: bump to sigstore ~= 3.6
- #157 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/157
- Repo: sigstore/gh-action-sigstore-python
- Name: ci: cleanup, fix zizmor findings
- #160 woodruffw: https://github.com/sigstore/gh-action-sigstore-python/pull/160
- Repo: sigstore/sigstore-conformance
- Name: README: prep 0.0.10
- #120 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/120
- Repo: sigstore/sigstore-conformance
- Name: requirements: bump sigstore-protobuf-specs
- #132 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/132
- Repo: sigstore/sigstore-conformance
- Name: README: prep 0.0.11
- #133 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/133
- Repo: sigstore/sigstore-conformance
- Name: dev-requirements: enforce sigstore ~= 2.0
- #136 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/136
- Repo: sigstore/sigstore-conformance
- Name: dev-requirements: switch to sigstore-python 3.x
- #152 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/152
- Repo: sigstore/sigstore-conformance
- Name: Conformance tests for CPython release signatures
- #156 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/156
- Repo: sigstore/sigstore-conformance
- Name: action: bump cpython-release-tracker ref
- #160 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/160
- Repo: sigstore/sigstore-conformance
- Name: cli_protocol: clarify FILE_OR_DIGEST
- #163 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/163
- Repo: sigstore/sigstore-conformance
- Name: Bump cpython artifacts
- #164 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/164
- Repo: sigstore/sigstore-conformance
- Name: README: prep 0.0.12
- #167 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/167
- Repo: sigstore/sigstore-conformance
- Name: test: don’t assume GITHUB_WORKSPACE
- #169 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/169
- Repo: sigstore/sigstore-conformance
- Name: add skip-cpython-release-tests
- #170 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/170
- Repo: sigstore/sigstore-conformance
- Name: README: prep 0.0.13
- #171 woodruffw: https://github.com/sigstore/sigstore-conformance/pull/171
Software testing tools
- Repo: google/oss-fuzz
- Name: Adding Ruby Support into OSS-Fuzz via Ruzzy
- #12034 AdvenamTacet: https://github.com/google/oss-fuzz/pull/12034
- Repo: langston-barrett/tree-crasher
- Name: feat: tree-crasher-nix
- #75 woodruffw: https://github.com/langston-barrett/tree-crasher/pull/75
- Repo: langston-barrett/tree-crasher
- Name: scripts/corpora: add ruby.sh
- #81 woodruffw: https://github.com/langston-barrett/tree-crasher/pull/81
- Repo: mkdocstrings/python
- Name: Allow ruff to be used as a formatter
- #216 DarkaMaul: https://github.com/mkdocstrings/python/pull/216
- Repo: pypa/abi3audit
- Name: _object: lower warning to debug
- #103 woodruffw: https://github.com/pypa/abi3audit/pull/103
- Repo: pypa/abi3audit
- Name: workflows/release: refactor into separate steps
- #105 woodruffw: https://github.com/pypa/abi3audit/pull/105
- Repo: pypa/abi3audit
- Name: workflows/release: split sign job, harden permissions
- #106 woodruffw: https://github.com/pypa/abi3audit/pull/106
- Repo: pypa/abi3audit
- Name: update project URLs
- #107 woodruffw: https://github.com/pypa/abi3audit/pull/107
- Repo: pypa/abi3audit
- Name: CODEOWNERS: remove
- #108 woodruffw: https://github.com/pypa/abi3audit/pull/108
- Repo: pypa/abi3audit
- Name: _audit: relax PyInit check
- #112 woodruffw: https://github.com/pypa/abi3audit/pull/112
- Repo: pypa/abi3audit
- Name: add Python 3.13 to CI, remove 3.8
- #114 woodruffw: https://github.com/pypa/abi3audit/pull/114
- Repo: pypa/abi3audit
- Name: abi3audit: set user-agent
- #122 woodruffw: https://github.com/pypa/abi3audit/pull/122
- Repo: pypa/abi3audit
- Name: lint: update ruff config, re-run format
- #84 woodruffw: https://github.com/pypa/abi3audit/pull/84
- Repo: pypa/abi3audit
- Name: CI, Makefile: cleanup
- #86 woodruffw: https://github.com/pypa/abi3audit/pull/86
- Repo: pypa/abi3audit
- Name: Support globs on Windows
- #93 woodruffw: https://github.com/pypa/abi3audit/pull/93
- Repo: pypa/abi3audit
- Name: pyproject: fix abi3info dep
- #95 woodruffw: https://github.com/pypa/abi3audit/pull/95
- Repo: pypa/abi3audit
- Name: _object: skip unknown ELF visibilities
- #96 woodruffw: https://github.com/pypa/abi3audit/pull/96
- Repo: pypa/abi3audit
- Name: _object: handle STB_GNU_UNIQUE
- #99 woodruffw: https://github.com/pypa/abi3audit/pull/99
- Repo: pypa/gh-action-pip-audit
- Name: README: prep 1.1.0
- #48 woodruffw: https://github.com/pypa/gh-action-pip-audit/pull/48
- Repo: pypa/gh-action-pip-audit
- Name: ci: zizmor fixes, add zizmor workflow
- #54 woodruffw: https://github.com/pypa/gh-action-pip-audit/pull/54
Blockchain software
- Repo: FuelLabs/fuel-vm
- Name: Add ClusterFuzzLite in CI featuring PR fuzzing, batch fuzzing and fuzz coverage reports
- #820 netrome: https://github.com/FuelLabs/fuel-vm/pull/820
- Repo: JoranHonig/tree-sitter-solidity
- Name: Add support for keyName/valueName in mappings
- #52 ret2libc: https://github.com/JoranHonig/tree-sitter-solidity/pull/52
- Repo: JoranHonig/tree-sitter-solidity
- Name: fix: align operator precedence with Solidity documentation
- #63 elopez: https://github.com/JoranHonig/tree-sitter-solidity/pull/63
- Repo: cosmos/cosmos-sdk
- Name: test: avoid evidenceFraction parameter to be very close to 1.0
- #16978 ggrieco-tob: https://github.com/cosmos/cosmos-sdk/pull/16978
- Repo: cosmos/cosmos-sdk
- Name: fix(x/bank): disallow duplicated addresses when sanitizing the genesis bank balances
- #18542 ggrieco-tob: https://github.com/cosmos/cosmos-sdk/pull/18542
- Repo: ethereum/ethereum-org-website
- Name: Fix typo in block document
- #12302 maxammann: https://github.com/ethereum/ethereum-org-website/pull/12302
- Repo: ethereum/hevm
- Name: Abstract gas v3
- #427 arcz: https://github.com/ethereum/hevm/pull/427
- Repo: ethereum/hevm
- Name: Enable foundry on Apple silicon
- #431 arcz: https://github.com/ethereum/hevm/pull/431
- Repo: ethereum/hevm
- Name: Fix trace source mapping and indexed event args
- #446 arcz: https://github.com/ethereum/hevm/pull/446
- Repo: ethereum/hevm
- Name: Limit VMResult cases when concrete
- #447 arcz: https://github.com/ethereum/hevm/pull/447
- Repo: ethereum/hevm
- Name: Prepare 0.53.0 release
- #460 arcz: https://github.com/ethereum/hevm/pull/460
- Repo: ethereum/hevm
- Name: Implement label cheatcode
- #468 arcz: https://github.com/ethereum/hevm/pull/468
- Repo: ethereum/hevm
- Name: Update GHC to 9.6
- #471 arcz: https://github.com/ethereum/hevm/pull/471
- Repo: ethereum/hevm
- Name: Mark FFI calls as unsafe
- #480 elopez: https://github.com/ethereum/hevm/pull/480
- Repo: ethereum/hevm
- Name: Optimize W256, Addr conversion to ByteString
- #481 elopez: https://github.com/ethereum/hevm/pull/481
- Repo: ethereum/hevm
- Name: ethjet: clean up dead code
- #483 elopez: https://github.com/ethereum/hevm/pull/483
- Repo: ethereum/hevm
- Name: Fix solver support on Windows
- #484 elopez: https://github.com/ethereum/hevm/pull/484
- Repo: ethereum/hevm
- Name: Drop brick remnants
- #485 elopez: https://github.com/ethereum/hevm/pull/485
- Repo: ethereum/hevm
- Name: ci: correct build matrix OSes
- #486 elopez: https://github.com/ethereum/hevm/pull/486
- Repo: ethereum/hevm
- Name: ci: update external actions
- #488 elopez: https://github.com/ethereum/hevm/pull/488
- Repo: ethereum/hevm
- Name: ethjet: convert blake2 precompile to C
- #494 elopez: https://github.com/ethereum/hevm/pull/494
- Repo: ethereum/hevm
- Name: Enable testing on Windows
- #501 elopez: https://github.com/ethereum/hevm/pull/501
- Repo: ethereum/hevm
- Name: flake: fix redistributable binary rewriting
- #512 elopez: https://github.com/ethereum/hevm/pull/512
- Repo: ethereum/hevm
- Name: Re-enable dapp tests on Windows
- #514 elopez: https://github.com/ethereum/hevm/pull/514
- Repo: ethereum/hevm
- Name: ci: windows: pin Foundry version
- #519 elopez: https://github.com/ethereum/hevm/pull/519
- Repo: ethereum/hevm
- Name: Bump nixpkgs and ethereum tests, use cabal-install from nix
- #548 arcz: https://github.com/ethereum/hevm/pull/548
- Repo: ethereum/hevm
- Name: Remove debugging leftover from showTrace
- #557 arcz: https://github.com/ethereum/hevm/pull/557
- Repo: ethereum/hevm
- Name: Implement setEnv and env{Bool,Uint,Int,Address,Bytes32,String,Bytes}
- #568 elopez: https://github.com/ethereum/hevm/pull/568
- Repo: ethereum/hevm
- Name: Fix gas accounting in cheatcodes
- #576 elopez: https://github.com/ethereum/hevm/pull/576
- Repo: ethereum/hevm
- Name: Various small cleanups
- #579 arcz: https://github.com/ethereum/hevm/pull/579
- Repo: ethereum/hevm
- Name: ci: windows: use builtin GHC clang toolchain to build dependencies
- #607 elopez: https://github.com/ethereum/hevm/pull/607
- Repo: ethereum/hevm
- Name: flake: fix nix build .#redistributable on macOS
- #614 elopez: https://github.com/ethereum/hevm/pull/614
- Repo: ethereum/hevm
- Name: Release workflow improvements
- #615 elopez: https://github.com/ethereum/hevm/pull/615
Reverse engineering tools
- Repo: Gallopsled/pwntools
- Name: Fix pwn constgrep when it matches a non-constant type (Fixes #2344)
- #2345 disconnect3d: https://github.com/Gallopsled/pwntools/pull/2345
- Repo: Gallopsled/pwntools
- Name: checksec.py: import ELF instead of *
- #2346 disconnect3d: https://github.com/Gallopsled/pwntools/pull/2346
- Repo: Gallopsled/pwntools
- Name: Fix Unicorn Engine 1GB limit that calls exit: raise OSError instead (Fixes #2343)
- #2347 disconnect3d: https://github.com/Gallopsled/pwntools/pull/2347
- Repo: NationalSecurityAgency/ghidra
- Name: Fix ASAN static initialization order fiasco
- #5382 ekilmer: https://github.com/NationalSecurityAgency/ghidra/pull/5382
- Repo: NationalSecurityAgency/ghidra
- Name: Fix C++ sleighexample
- #6276 ekilmer: https://github.com/NationalSecurityAgency/ghidra/pull/6276
- Repo: NationalSecurityAgency/ghidra
- Name: Add dwarf register mapping for sparc
- #6301 Ninja3047: https://github.com/NationalSecurityAgency/ghidra/pull/6301
- Repo: NationalSecurityAgency/ghidra
- Name: decompiler-cpp: Open sla files as ‘binary’
- #6372 ekilmer: https://github.com/NationalSecurityAgency/ghidra/pull/6372
- Repo: angr/angrop
- Name: Update README API usage rop_gadgets
- #95 ekilmer: https://github.com/angr/angrop/pull/95
- Repo: angr/angrop
- Name: find_reg_setting_gadgets allow preserve_regs
- #96 ekilmer: https://github.com/angr/angrop/pull/96
- Repo: angr/angrop
- Name: Allow setting max stacksize
- #97 Ninja3047: https://github.com/angr/angrop/pull/97
- Repo: angr/cle
- Name: Fix mips plt
- #485 Ninja3047: https://github.com/angr/cle/pull/485
- Repo: martinradev/gdb-pt-dump
- Name: README: mention that pt_host is a BPF program
- #30 disconnect3d: https://github.com/martinradev/gdb-pt-dump/pull/30
- Repo: martinradev/gdb-pt-dump
- Name: Update pt_gdb.py
- #37 disconnect3d: https://github.com/martinradev/gdb-pt-dump/pull/37
- Repo: purseclab/Patcherex2
- Name: Check allocation manager blocks for file_addr when using detour_pos
- #15 Ninja3047: https://github.com/purseclab/Patcherex2/pull/15
- Repo: purseclab/Patcherex2
- Name: Fix get instr normalization
- #9 Ninja3047: https://github.com/purseclab/Patcherex2/pull/9
- Repo: pwndbg/pwndbg
- Name: Fixes #1976 – vmmap read /proc/$tid/maps instead of $pid/maps
- #1982 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1982
- Repo: pwndbg/pwndbg
- Name: Optimize pwndbg.exception import time
- #1983 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1983
- Repo: pwndbg/pwndbg
- Name: Optimize pwndbg.commands.ai import time
- #1984 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1984
- Repo: pwndbg/pwndbg
- Name: ida.py: remove duplicated line
- #1985 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1985
- Repo: pwndbg/pwndbg
- Name: Create FUNDING.yml
- #1988 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1988
- Repo: pwndbg/pwndbg
- Name: exception.py: fix bug when printing exceptions
- #1994 disconnect3d: https://github.com/pwndbg/pwndbg/pull/1994
- Repo: pwndbg/pwndbg
- Name: Fix Pwndbg on Py3.12 and Fedora: add setuptools as dependency
- #2008 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2008
- Repo: pwndbg/pwndbg
- Name: cyclic: add argument to save output to file (fixes #2007)
- #2009 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2009
- Repo: pwndbg/pwndbg
- Name: Update poetry.lock
- #2010 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2010
- Repo: pwndbg/pwndbg
- Name: Fix flake.lock for Cryptography==42.0.2
- #2015 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2015
- Repo: pwndbg/pwndbg
- Name: Prepare 2024.02.14 release
- #2020 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2020
- Repo: pwndbg/pwndbg
- Name: README.md: fix cheatsheet link
- #2035 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2035
- Repo: pwndbg/pwndbg
- Name: asm command: fix default arch
- #2066 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2066
- Repo: pwndbg/pwndbg
- Name: README: update gdb build steps
- #2089 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2089
- Repo: pwndbg/pwndbg
- Name: README: update gdb build commands
- #2093 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2093
- Repo: pwndbg/pwndbg
- Name: Fix show emulate docstring
- #2133 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2133
- Repo: pwndbg/pwndbg
- Name: Assume register/memory_changed GDB events exist
- #2134 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2134
- Repo: pwndbg/pwndbg
- Name: Add more tips: $base, track-got, mmap, mprotect, hi
- #2135 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2135
- Repo: pwndbg/pwndbg
- Name: Hopefully fix UTF-8/unicode issues once and for all
- #2139 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2139
- Repo: pwndbg/pwndbg
- Name: Fix lint issue in setup.sh
- #2213 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2213
- Repo: pwndbg/pwndbg
- Name: Fix lint issue in canary.py
- #2214 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2214
- Repo: pwndbg/pwndbg
- Name: Add Ubuntu 24.04 to CI tests run
- #2215 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2215
- Repo: pwndbg/pwndbg
- Name: Fix config.disasm_annotations fetching
- #2256 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2256
- Repo: pwndbg/pwndbg
- Name: pwndbg/enhance.py: remove unused code
- #2272 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2272
- Repo: pwndbg/pwndbg
- Name: gdblib/stacks.py: fix bug with stack exploration
- #2273 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2273
- Repo: pwndbg/pwndbg
- Name: context: fix code-lines to disasm-lines and code-source-* to code-*
- #2316 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2316
- Repo: pwndbg/pwndbg
- Name: disasm/x86.py: minor refactor
- #2320 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2320
- Repo: pwndbg/pwndbg
- Name: Fix #2314: properly cache docker image build on CI/CD
- #2322 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2322
- Repo: pwndbg/pwndbg
- Name: Improve attachp: fix partial match, add –user and –all
- #2371 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2371
- Repo: pwndbg/pwndbg
- Name: attachp command: add –retry flag
- #2372 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2372
- Repo: pwndbg/pwndbg
- Name: Add tests for dt command
- #2398 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2398
- Repo: pwndbg/pwndbg
- Name: add scripts/release.sh for building release binaries
- #2399 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2399
- Repo: pwndbg/pwndbg
- Name: Disable arm64 runner on CI/CD
- #2400 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2400
- Repo: pwndbg/pwndbg
- Name: Bump version to 2024.08.29
- #2401 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2401
- Repo: pwndbg/pwndbg
- Name: add gdt command
- #2405 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2405
- Repo: pwndbg/pwndbg
- Name: Fix memory.poke and make memory.peek return bytearray
- #2483 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2483
- Repo: pwndbg/pwndbg
- Name: Fix #2490: Inform about outdated deps and updating process
- #2491 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2491
- Repo: pwndbg/pwndbg
- Name: jemalloc.py: remove unused Arena class
- #2492 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2492
- Repo: pwndbg/pwndbg
- Name: Fix canary when no canaries
- #2496 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2496
- Repo: pwndbg/pwndbg
- Name: Fix gdt command: require address argument
- #2497 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2497
- Repo: pwndbg/pwndbg
- Name: Fix ctxp command
- #2498 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2498
- Repo: pwndbg/pwndbg
- Name: Fix try_free command: make addr argument required
- #2499 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2499
- Repo: pwndbg/pwndbg
- Name: Minor refactor of aglib/regs.py:get_register
- #2583 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2583
- Repo: pwndbg/pwndbg
- Name: Fix #2549: block config. assignments
- #2585 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2585
- Repo: pwndbg/pwndbg
- Name: Improve tests.py stats handling
- #2586 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2586
- Repo: pwndbg/pwndbg
- Name: Fix/improve UX of start/sstart/entry on remote targets
- #2600 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2600
- Repo: pwndbg/pwndbg
- Name: codecov: disable PR annotations
- #2635 disconnect3d: https://github.com/pwndbg/pwndbg/pull/2635
Packaging ecosystem/supply chain
- Repo: Homebrew/.github
- Name: sync-shared-config.yml: explicit persistence of credentials
- #216 woodruffw: https://github.com/Homebrew/.github/pull/216
- Repo: Homebrew/.github
- Name: SECURITY: make conduct section, warn against weaponized PRs
- #92 woodruffw: https://github.com/Homebrew/.github/pull/92
- Repo: Homebrew/actions
- Name: setup-homebrew: add brew-gh-api-token setting
- #557 woodruffw: https://github.com/Homebrew/actions/pull/557
- Repo: Homebrew/actions
- Name: Revert “setup-homebrew: add brew-gh-api-token setting”
- #559 woodruffw: https://github.com/Homebrew/actions/pull/559
- Repo: Homebrew/actions
- Name: Revert “Revert “setup-homebrew: add brew-gh-api-token setting””
- #560 woodruffw: https://github.com/Homebrew/actions/pull/560
- Repo: Homebrew/brew-pip-audit
- Name: workflows: fix zizmor issues
- #124 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/124
- Repo: Homebrew/brew-pip-audit
- Name: workflows: ensure auto-pr always runs on the right commit
- #132 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/132
- Repo: Homebrew/brew-pip-audit
- Name: Cleanup, cache bundler gems
- #71 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/71
- Repo: Homebrew/brew-pip-audit
- Name: auto-pr: fix broken runner python
- #72 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/72
- Repo: Homebrew/brew-pip-audit
- Name: generate-prs: be more verbose while updating
- #80 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/80
- Repo: Homebrew/brew-pip-audit
- Name: auto-pr: double the timeout
- #81 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/81
- Repo: Homebrew/brew-pip-audit
- Name: generate-prs: skip pytorch
- #99 woodruffw: https://github.com/Homebrew/brew-pip-audit/pull/99
- Repo: Homebrew/brew
- Name: attestation: add initial attestation helpers, integrate into brew install
- #17049 woodruffw: https://github.com/Homebrew/brew/pull/17049
- Repo: Homebrew/brew
- Name: ensure_executable!: add opt_bin path to search
- #17106 woodruffw: https://github.com/Homebrew/brew/pull/17106
- Repo: Homebrew/brew
- Name: attestations: improve authentication techniques
- #17220 woodruffw: https://github.com/Homebrew/brew/pull/17220
- Repo: Homebrew/brew
- Name: attestation: redact secret in environment
- #17302 woodruffw: https://github.com/Homebrew/brew/pull/17302
- Repo: Homebrew/brew
- Name: attestation: drop workflow check on core attestation
- #17331 woodruffw: https://github.com/Homebrew/brew/pull/17331
- Repo: Homebrew/brew
- Name: attestation: handle :all bottles
- #17438 woodruffw: https://github.com/Homebrew/brew/pull/17438
- Repo: Homebrew/brew
- Name: formula_installer: fix gh bootstrap cycle
- #17546 woodruffw: https://github.com/Homebrew/brew/pull/17546
- Repo: Homebrew/brew
- Name: attestations: widen the beta
- #17692 woodruffw: https://github.com/Homebrew/brew/pull/17692
- Repo: Homebrew/brew
- Name: curl_spec: remove no-op Marshal use
- #17699 woodruffw: https://github.com/Homebrew/brew/pull/17699
- Repo: Homebrew/brew
- Name: attestation: don’t dupe stderr
- #17704 woodruffw: https://github.com/Homebrew/brew/pull/17704
- Repo: Homebrew/brew
- Name: formula_installer: skip attestations on local_bottle_path
- #17706 woodruffw: https://github.com/Homebrew/brew/pull/17706
- Repo: Homebrew/brew
- Name: pypi: allow universal wheels as resources
- #17724 woodruffw: https://github.com/Homebrew/brew/pull/17724
- Repo: Homebrew/brew
- Name: workflows/tests: enable attestations
- #17736 woodruffw: https://github.com/Homebrew/brew/pull/17736
- Repo: Homebrew/brew
- Name: utils/pypi: add missing import
- #17753 woodruffw: https://github.com/Homebrew/brew/pull/17753
- Repo: Homebrew/brew
- Name: attestation: fix comment
- #17805 woodruffw: https://github.com/Homebrew/brew/pull/17805
- Repo: Homebrew/brew
- Name: attestation: handle mirrored bottles correctly
- #17878 woodruffw: https://github.com/Homebrew/brew/pull/17878
- Repo: Homebrew/brew
- Name: resource_auditor: normalize PyPI names to kebab case before auditing
- #17896 woodruffw: https://github.com/Homebrew/brew/pull/17896
- Repo: Homebrew/brew
- Name: language/python: support pure-Python wheel installs
- #17897 woodruffw: https://github.com/Homebrew/brew/pull/17897
- Repo: Homebrew/brew
- Name: attestation: remove gh version detection
- #17899 woodruffw: https://github.com/Homebrew/brew/pull/17899
- Repo: Homebrew/brew
- Name: sandbox: disallow backslashes in path filter names
- #17919 woodruffw: https://github.com/Homebrew/brew/pull/17919
- Repo: Homebrew/brew
- Name: Homebrew-and-Python: more PEP 668 guidance
- #17922 woodruffw: https://github.com/Homebrew/brew/pull/17922
- Repo: Homebrew/brew
- Name: attestation: specialize error when gh is old
- #17926 woodruffw: https://github.com/Homebrew/brew/pull/17926
- Repo: Homebrew/brew
- Name: Revert “attestation: specialize error when gh is old”
- #18030 woodruffw: https://github.com/Homebrew/brew/pull/18030
- Repo: Homebrew/brew
- Name: attestation: specialize error on incompatible gh
- #18543 woodruffw: https://github.com/Homebrew/brew/pull/18543
- Repo: Homebrew/brew
- Name: actionlint: suppress zizmor’s exit code
- #18753 woodruffw: https://github.com/Homebrew/brew/pull/18753
- Repo: Homebrew/brew
- Name: attestation: handle multiple subjects
- #18883 woodruffw: https://github.com/Homebrew/brew/pull/18883
- Repo: Homebrew/homebrew-core
- Name: python@3.12: tweak EXTERNALLY-MANAGED guidance
- #165681 woodruffw: https://github.com/Homebrew/homebrew-core/pull/165681
- Repo: Homebrew/homebrew-core
- Name: publish-commit-bottles: use public action
- #171085 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171085
- Repo: Homebrew/homebrew-core
- Name: publish-commit-bottles: remove PR positional arg
- #171201 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171201
- Repo: Homebrew/homebrew-core
- Name: dispatch-build-bottle: add provenance step
- #171819 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171819
- Repo: Homebrew/homebrew-core
- Name: dispatch-rebottle: add provenance
- #171986 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171986
- Repo: Homebrew/homebrew-core
- Name: dispatch-rebottle: consistently plumb inputs
- #171990 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171990
- Repo: Homebrew/homebrew-core
- Name: dispatch-build-bottle: route inputs through env
- #171996 woodruffw: https://github.com/Homebrew/homebrew-core/pull/171996
- Repo: Homebrew/homebrew-core
- Name: create-replacement-pr: add provenance
- #172005 woodruffw: https://github.com/Homebrew/homebrew-core/pull/172005
- Repo: Homebrew/homebrew-core
- Name: workflows/tests: set HOMEBREW_VERIFY_ATTESTATIONS
- #177326 woodruffw: https://github.com/Homebrew/homebrew-core/pull/177326
- Repo: Homebrew/homebrew-core
- Name: pypi_formula_mappings: alot excludes notmuch2
- #177329 woodruffw: https://github.com/Homebrew/homebrew-core/pull/177329
- Repo: Homebrew/homebrew-core
- Name: libtirpc 1.3.4
- #177335 woodruffw: https://github.com/Homebrew/homebrew-core/pull/177335
- Repo: Homebrew/homebrew-core
- Name: Revert “workflows/tests: set HOMEBREW_VERIFY_ATTESTATIONS”
- #177383 woodruffw: https://github.com/Homebrew/homebrew-core/pull/177383
- Repo: Homebrew/homebrew-core
- Name: medusa 0.1.4
- #177811 elopez: https://github.com/Homebrew/homebrew-core/pull/177811
- Repo: Homebrew/homebrew-core
- Name: lorem: add missing Python dependency
- #178828 woodruffw: https://github.com/Homebrew/homebrew-core/pull/178828
- Repo: Homebrew/homebrew-core
- Name: pass: update digest
- #181795 woodruffw: https://github.com/Homebrew/homebrew-core/pull/181795
- Repo: Homebrew/homebrew-core
- Name: zizmor: drop openssl@3 linux dep
- #201399 woodruffw: https://github.com/Homebrew/homebrew-core/pull/201399
- Repo: Homebrew/ruby-macho
- Name: macho: 4.0.1
- #593 woodruffw: https://github.com/Homebrew/ruby-macho/pull/593
- Repo: Homebrew/ruby-macho
- Name: tests: set CODECOV_TOKEN
- #597 woodruffw: https://github.com/Homebrew/ruby-macho/pull/597
- Repo: Homebrew/ruby-macho
- Name: workflows: pin setup-ruby action
- #598 woodruffw: https://github.com/Homebrew/ruby-macho/pull/598
- Repo: Homebrew/ruby-macho
- Name: macho: 4.1.0
- #626 woodruffw: https://github.com/Homebrew/ruby-macho/pull/626
- Repo: Homebrew/ruby-macho
- Name: workflows: add a release workflow
- #627 woodruffw: https://github.com/Homebrew/ruby-macho/pull/627
- Repo: Homebrew/ruby-macho
- Name: headers: add some new constants
- #655 woodruffw: https://github.com/Homebrew/ruby-macho/pull/655
- Repo: actions/starter-workflows
- Name: ci/python-publish: bump, use trusted publishing
- #2345 woodruffw: https://github.com/actions/starter-workflows/pull/2345
- Repo: commercetools/merchant-center-application-kit
- Name: workflows: fix some exploitable template injections
- #3670 woodruffw: https://github.com/commercetools/merchant-center-application-kit/pull/3670
- Repo: microsoft/vcpkg
- Name: [nanobind] New port
- #35488 ekilmer: https://github.com/microsoft/vcpkg/pull/35488
- Repo: psf/policies
- Name: docs, mkdocs: fix domain, title caps
- #15 woodruffw: https://github.com/psf/policies/pull/15
- Repo: pypa/advisory-database
- Name: idna: fix PYSEC-2024-60
- #186 woodruffw: https://github.com/pypa/advisory-database/pull/186
- Repo: pypa/advisory-database
- Name: PYSEC-2024-60: fix fixed field
- #187 woodruffw: https://github.com/pypa/advisory-database/pull/187
- Repo: pypa/gh-action-pypi-publish
- Name: oidc-exchange: update OIDC minting endpoint
- #206 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/206
- Repo: pypa/gh-action-pypi-publish
- Name: twine-upload: fix tense on password nudge
- #234 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/234
- Repo: pypa/gh-action-pypi-publish
- Name: Expose PEP 740 attestations functionality
- #236 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/236
- Repo: pypa/gh-action-pypi-publish
- Name: Link the PyPI status dashboard in OIDC error messages
- #243 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/243
- Repo: pypa/gh-action-pypi-publish
- Name: requirements: re-compile requirements with latest twine
- #245 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/245
- Repo: pypa/gh-action-pypi-publish
- Name: Add nudge message with magic link to create new Trusted Publisher
- #250 facutuesca: https://github.com/pypa/gh-action-pypi-publish/pull/250
- Repo: pypa/gh-action-pypi-publish
- Name: Remove redundant Path.absolute() call
- #258 facutuesca: https://github.com/pypa/gh-action-pypi-publish/pull/258
- Repo: pypa/gh-action-pypi-publish
- Name: Bump pypi-attestations to v0.0.12 in the runtime lock file
- #262 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/262
- Repo: pypa/gh-action-pypi-publish
- Name: Fix magic link summary
- #270 facutuesca: https://github.com/pypa/gh-action-pypi-publish/pull/270
- Repo: pypa/gh-action-pypi-publish
- Name: requirements: bump sigstore, pypi-attestations
- #276 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/276
- Repo: pypa/gh-action-pypi-publish
- Name: action: enable attestations by default
- #277 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/277
- Repo: pypa/gh-action-pypi-publish
- Name: attestations: collect *.zip sdists as well
- #295 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/295
- Repo: pypa/gh-action-pypi-publish
- Name: requirements: bump pypi-attestations to 0.0.15
- #297 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/297
- Repo: pypa/gh-action-pypi-publish
- Name: oidc-exchange: add workflow_ref to debug msg
- #305 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/305
- Repo: pypa/gh-action-pypi-publish
- Name: requirements: bump twine to ~= 6.0
- #309 woodruffw: https://github.com/pypa/gh-action-pypi-publish/pull/309
- Repo: pypa/packaging.python.org
- Name: publish-to-test-pypi: bump action versions
- #1539 woodruffw: https://github.com/pypa/packaging.python.org/pull/1539
- Repo: pypa/packaging.python.org
- Name: guides, specifications: update for PEP 753
- #1611 woodruffw: https://github.com/pypa/packaging.python.org/pull/1611
- Repo: pypa/packaging.python.org
- Name: version-specifiers: add a custom anchor for Pre-releases section
- #1625 woodruffw: https://github.com/pypa/packaging.python.org/pull/1625
- Repo: pypa/packaging.python.org
- Name: specifications: create living copy of PEP 740
- #1646 woodruffw: https://github.com/pypa/packaging.python.org/pull/1646
- Repo: pypa/packaging.python.org
- Name: tool-recommendations: update Trusted Publisher providers
- #1668 woodruffw: https://github.com/pypa/packaging.python.org/pull/1668
- Repo: pypa/pip-audit
- Name: _cli: remove a misleading warning
- #719 woodruffw: https://github.com/pypa/pip-audit/pull/719
- Repo: pypa/pip-audit
- Name: prep 2.7.0
- #722 woodruffw: https://github.com/pypa/pip-audit/pull/722
- Repo: pypa/pip-audit
- Name: _virtual_env: handle PermissionError
- #737 woodruffw: https://github.com/pypa/pip-audit/pull/737
- Repo: pypa/pip-audit
- Name: prep 2.7.1
- #738 woodruffw: https://github.com/pypa/pip-audit/pull/738
- Repo: pypa/pip-audit
- Name: Replace issue templates with issue forms
- #741 woodruffw: https://github.com/pypa/pip-audit/pull/741
- Repo: pypa/pip-audit
- Name: _virtual_env: allow pip to shell out to keyring
- #743 woodruffw: https://github.com/pypa/pip-audit/pull/743
- Repo: pypa/pip-audit
- Name: prep 2.7.2
- #744 woodruffw: https://github.com/pypa/pip-audit/pull/744
- Repo: pypa/pip-audit
- Name: README: fixup troubleshooting docs based on #742
- #759 woodruffw: https://github.com/pypa/pip-audit/pull/759
- Repo: pypa/pip-audit
- Name: CHANGELOG: record #756
- #762 woodruffw: https://github.com/pypa/pip-audit/pull/762
- Repo: pypa/pip-audit
- Name: prep 2.7.3
- #771 woodruffw: https://github.com/pypa/pip-audit/pull/771
- Repo: pypa/pip-audit
- Name: workflows/release: cleanup
- #789 woodruffw: https://github.com/pypa/pip-audit/pull/789
- Repo: pypa/pip-audit
- Name: drop 3.8, add 3.13
- #846 woodruffw: https://github.com/pypa/pip-audit/pull/846
- Repo: pypa/pip-audit
- Name: workflows: address zizmor findings, add zizmor workflow
- #851 woodruffw: https://github.com/pypa/pip-audit/pull/851
- Repo: pypa/pip-audit
- Name: ci: zizmor: use uvx
- #864 woodruffw: https://github.com/pypa/pip-audit/pull/864
- Repo: pypa/sampleproject
- Name: pyproject: prep 4.0.0
- #219 woodruffw: https://github.com/pypa/sampleproject/pull/219
- Repo: pypa/twine
- Name: twine: use API tokens by default on PyPI
- #1040 woodruffw: https://github.com/pypa/twine/pull/1040
- Repo: pypa/twine
- Name: twine/upload: attestations scaffolding
- #1095 woodruffw: https://github.com/pypa/twine/pull/1095
- Repo: pypa/twine
- Name: test_integration: allow PEP 625 sdist name
- #1096 woodruffw: https://github.com/pypa/twine/pull/1096
- Repo: pypa/twine
- Name: upload: add attestations to PackageFile
- #1098 woodruffw: https://github.com/pypa/twine/pull/1098
- Repo: pypa/twine
- Name: upload: prevent –attestations on non-PyPI indices
- #1099 woodruffw: https://github.com/pypa/twine/pull/1099
- Repo: pypa/twine
- Name: upload: turn attestation error into a warning
- #1101 woodruffw: https://github.com/pypa/twine/pull/1101
- Repo: pypa/twine
- Name: Update changelog for 5.1.0
- #1107 woodruffw: https://github.com/pypa/twine/pull/1107
- Repo: pypa/twine
- Name: docs, twine: improve messaging around #1040
- #1137 woodruffw: https://github.com/pypa/twine/pull/1137
- Repo: pypa/twine
- Name: Fix #908
- #1168 DarkaMaul: https://github.com/pypa/twine/pull/1168
- Repo: pypa/twine
- Name: check: ignore attestations, like signatures
- #1172 woodruffw: https://github.com/pypa/twine/pull/1172
- Repo: pypa/twine
- Name: chore: mark 3.13 as explicitly supported
- #1184 woodruffw: https://github.com/pypa/twine/pull/1184
- Repo: pypa/twine
- Name: check: fix handling of non-shell-expanded globs
- #1188 woodruffw: https://github.com/pypa/twine/pull/1188
- Repo: pypa/twine
- Name: Update changelog for 6.0.1
- #1189 woodruffw: https://github.com/pypa/twine/pull/1189
- Repo: pypi/warehouse
- Name: warehouse/help: fixup API token guidance
- #15130 woodruffw: https://github.com/pypi/warehouse/pull/15130
- Repo: pypi/warehouse
- Name: Refactor OIDC mint token endpoint (cont. #14063)
- #15148 woodruffw: https://github.com/pypi/warehouse/pull/15148
- Repo: pypi/warehouse
- Name: docs: add per-publisher content tabs
- #15173 woodruffw: https://github.com/pypi/warehouse/pull/15173
- Repo: pypi/warehouse
- Name: docs/user: update OIDC minting endpoint
- #15180 woodruffw: https://github.com/pypi/warehouse/pull/15180
- Repo: pypi/warehouse
- Name: oidc: add a NOTE about duped route
- #15183 woodruffw: https://github.com/pypi/warehouse/pull/15183
- Repo: pypi/warehouse
- Name: Miscellaneous OIDC fixes (from #15207)
- #15225 woodruffw: https://github.com/pypi/warehouse/pull/15225
- Repo: pypi/warehouse
- Name: docs, tests, warehouse: update PPUG links
- #15265 woodruffw: https://github.com/pypi/warehouse/pull/15265
- Repo: pypi/warehouse
- Name: Fix dev docs instructions on how to build docs
- #15273 facutuesca: https://github.com/pypi/warehouse/pull/15273
- Repo: pypi/warehouse
- Name: Initial implementation of GitLab OIDC trusted publisher
- #15275 facutuesca: https://github.com/pypi/warehouse/pull/15275
- Repo: pypi/warehouse
- Name: Add GitLab Trusted Publishing docs
- #15283 facutuesca: https://github.com/pypi/warehouse/pull/15283
- Repo: pypi/warehouse
- Name: oidc/forms: improve project exists error
- #15366 woodruffw: https://github.com/pypi/warehouse/pull/15366
- Repo: pypi/warehouse
- Name: Add daily task to purge expired OIDC macaroons
- #15463 facutuesca: https://github.com/pypi/warehouse/pull/15463
- Repo: pypi/warehouse
- Name: oidc/github: make repo comparison insensitive
- #15501 woodruffw: https://github.com/pypi/warehouse/pull/15501
- Repo: pypi/warehouse
- Name: oidc/gitlab: make project path comparison case insensitive
- #15512 facutuesca: https://github.com/pypi/warehouse/pull/15512
- Repo: pypi/warehouse
- Name: Return Macaroon alongside User in MacaroonSecurityPolicy.identity
- #15581 facutuesca: https://github.com/pypi/warehouse/pull/15581
- Repo: pypi/warehouse
- Name: Re-add UserTokenContext, with instance checks
- #15590 woodruffw: https://github.com/pypi/warehouse/pull/15590
- Repo: pypi/warehouse
- Name: Warn users when API token is used in Trusted Publishing project (take 2)
- #15641 facutuesca: https://github.com/pypi/warehouse/pull/15641
- Repo: pypi/warehouse
- Name: Add test to check email subject templates do NOT contain newlines
- #15651 facutuesca: https://github.com/pypi/warehouse/pull/15651
- Repo: pypi/warehouse
- Name: Combine User and UserTokenContext for user-backed identities in requests
- #15757 facutuesca: https://github.com/pypi/warehouse/pull/15757
- Repo: pypi/warehouse
- Name: Add ondelete and onupdate attributes to macaroon warning table
- #15832 facutuesca: https://github.com/pypi/warehouse/pull/15832
- Repo: pypi/warehouse
- Name: Fix GitLab Trusted Publisher not accepting valid namespaces
- #15839 facutuesca: https://github.com/pypi/warehouse/pull/15839
- Repo: pypi/warehouse
- Name: docs: self-managed GitLab instances are not supported (for Trusted Publishing)
- #15840 facutuesca: https://github.com/pypi/warehouse/pull/15840
- Repo: pypi/warehouse
- Name: Fix GitLab Trusted Publishers UI and docs
- #15921 facutuesca: https://github.com/pypi/warehouse/pull/15921
- Repo: pypi/warehouse
- Name: Remove deprecated version property from docker-compose.yml
- #15949 facutuesca: https://github.com/pypi/warehouse/pull/15949
- Repo: pypi/warehouse
- Name: Add support for uploading attestations in legacy API
- #15952 facutuesca: https://github.com/pypi/warehouse/pull/15952
- Repo: pypi/warehouse
- Name: Add comments explaining GitHub’s job_workflow_ref claim behavior
- #15967 facutuesca: https://github.com/pypi/warehouse/pull/15967
- Repo: pypi/warehouse
- Name: Clarify that GitHub is not the sole Identity Provider
- #16130 DarkaMaul: https://github.com/pypi/warehouse/pull/16130
- Repo: pypi/warehouse
- Name: docs, warehouse: improve “pending” publisher docs, messages
- #16158 woodruffw: https://github.com/pypi/warehouse/pull/16158
- Repo: pypi/warehouse
- Name: oidc/services: fix mischaracterized error
- #16197 woodruffw: https://github.com/pypi/warehouse/pull/16197
- Repo: pypi/warehouse
- Name: Verify release URLs using Trusted Publisher information
- #16205 facutuesca: https://github.com/pypi/warehouse/pull/16205
- Repo: pypi/warehouse
- Name: Parallelize the unit tests
- #16206 woodruffw: https://github.com/pypi/warehouse/pull/16206
- Repo: pypi/warehouse
- Name: routes: update ToU route + test
- #16210 woodruffw: https://github.com/pypi/warehouse/pull/16210
- Repo: pypi/warehouse
- Name: requirements: add pytest-sugar
- #16245 woodruffw: https://github.com/pypi/warehouse/pull/16245
- Repo: pypi/warehouse
- Name: Trusted publishing: prevent OIDC credential re-use
- #16254 DarkaMaul: https://github.com/pypi/warehouse/pull/16254
- Repo: pypi/warehouse
- Name: help, settings: replace setup.py with pyproject.toml
- #16258 woodruffw: https://github.com/pypi/warehouse/pull/16258
- Repo: pypi/warehouse
- Name: docs/dev/application: document some more directories
- #16259 woodruffw: https://github.com/pypi/warehouse/pull/16259
- Repo: pypi/warehouse
- Name: Improve GitLab projects name verification
- #16262 DarkaMaul: https://github.com/pypi/warehouse/pull/16262
- Repo: pypi/warehouse
- Name: forklift/legacy: add a scope to fallthrough error
- #16283 woodruffw: https://github.com/pypi/warehouse/pull/16283
- Repo: pypi/warehouse
- Name: misc: fix some sentry captures
- #16284 woodruffw: https://github.com/pypi/warehouse/pull/16284
- Repo: pypi/warehouse
- Name: Update pypi-attestations to 0.0.9
- #16291 facutuesca: https://github.com/pypi/warehouse/pull/16291
- Repo: pypi/warehouse
- Name: Store attestations for PEP740
- #16302 DarkaMaul: https://github.com/pypi/warehouse/pull/16302
- Repo: pypi/warehouse
- Name: Dockerfile: put some XDG dirs under /tmp
- #16304 woodruffw: https://github.com/pypi/warehouse/pull/16304
- Repo: pypi/warehouse
- Name: Dockerfile, tests: fix typo, add backstop
- #16309 woodruffw: https://github.com/pypi/warehouse/pull/16309
- Repo: pypi/warehouse
- Name: tests/functional: assert R_OK/W_OK for XDG dirs
- #16322 woodruffw: https://github.com/pypi/warehouse/pull/16322
- Repo: pypi/warehouse
- Name: Makefile: optimize subset test runs
- #16323 woodruffw: https://github.com/pypi/warehouse/pull/16323
- Repo: pypi/warehouse
- Name: Add metrics for GH Trusted Publishers with reusable workflows
- #16364 facutuesca: https://github.com/pypi/warehouse/pull/16364
- Repo: pypi/warehouse
- Name: constants: remove MAX_SIGSIZE
- #16373 woodruffw: https://github.com/pypi/warehouse/pull/16373
- Repo: pypi/warehouse
- Name: Initial PEP 740 documentation
- #16398 woodruffw: https://github.com/pypi/warehouse/pull/16398
- Repo: pypi/warehouse
- Name: Support pre-filling Trusted Publisher form via URL params
- #16399 facutuesca: https://github.com/pypi/warehouse/pull/16399
- Repo: pypi/warehouse
- Name: oidc/services: use PyJWK directly
- #16430 woodruffw: https://github.com/pypi/warehouse/pull/16430
- Repo: pypi/warehouse
- Name: Bump mypy and mypy-zope
- #16458 DarkaMaul: https://github.com/pypi/warehouse/pull/16458
- Repo: pypi/warehouse
- Name: GitHub, GitLab: improve claim matching during lookup
- #16462 woodruffw: https://github.com/pypi/warehouse/pull/16462
- Repo: pypi/warehouse
- Name: Move verified Release URLs to the Verified section
- #16472 facutuesca: https://github.com/pypi/warehouse/pull/16472
- Repo: pypi/warehouse
- Name: Move URLs to top of verified section
- #16473 facutuesca: https://github.com/pypi/warehouse/pull/16473
- Repo: pypi/warehouse
- Name: Make ReleaseURL model consistent with DB
- #16484 facutuesca: https://github.com/pypi/warehouse/pull/16484
- Repo: pypi/warehouse
- Name: Verify URLs that link to the project page on PyPI
- #16485 facutuesca: https://github.com/pypi/warehouse/pull/16485
- Repo: pypi/warehouse
- Name: Add publisher_url to the github_reusable_workflow metric.
- #16497 DarkaMaul: https://github.com/pypi/warehouse/pull/16497
- Repo: pypi/warehouse
- Name: Verify github.io URLs with Trusted Publishing
- #16499 facutuesca: https://github.com/pypi/warehouse/pull/16499
- Repo: pypi/warehouse
- Name: Update services recognized in detail.html
- #16512 DarkaMaul: https://github.com/pypi/warehouse/pull/16512
- Repo: pypi/warehouse
- Name: Documentation on Project-Urls
- #16513 DarkaMaul: https://github.com/pypi/warehouse/pull/16513
- Repo: pypi/warehouse
- Name: Add tests for the Google Trusted Publisher form
- #16514 facutuesca: https://github.com/pypi/warehouse/pull/16514
- Repo: pypi/warehouse
- Name: Improve Pending Trusted Publishers UX when project already exists
- #16515 facutuesca: https://github.com/pypi/warehouse/pull/16515
- Repo: pypi/warehouse
- Name: Improve test collect time
- #16523 DarkaMaul: https://github.com/pypi/warehouse/pull/16523
- Repo: pypi/warehouse
- Name: Makefile: optimize sub-test run
- #16524 DarkaMaul: https://github.com/pypi/warehouse/pull/16524
- Repo: pypi/warehouse
- Name: Verify URLs ending with .git for GitHub and GitLab
- #16525 facutuesca: https://github.com/pypi/warehouse/pull/16525
- Repo: pypi/warehouse
- Name: Add missing translation for Trusted Publishing error
- #16526 facutuesca: https://github.com/pypi/warehouse/pull/16526
- Repo: pypi/warehouse
- Name: Fix warning in tests for URL verification
- #16528 facutuesca: https://github.com/pypi/warehouse/pull/16528
- Repo: pypi/warehouse
- Name: Fix missing unverified URLs
- #16531 facutuesca: https://github.com/pypi/warehouse/pull/16531
- Repo: pypi/warehouse
- Name: Fix error when trying to verify Google TP URLs
- #16538 facutuesca: https://github.com/pypi/warehouse/pull/16538
- Repo: pypi/warehouse
- Name: docs: Add more details on how URLs are verified
- #16539 facutuesca: https://github.com/pypi/warehouse/pull/16539
- Repo: pypi/warehouse
- Name: register IntegrityService correctly
- #16543 woodruffw: https://github.com/pypi/warehouse/pull/16543
- Repo: pypi/warehouse
- Name: Reapply “Store attestations for PEP740 (#16302)” (#16545)
- #16546 woodruffw: https://github.com/pypi/warehouse/pull/16546
- Repo: pypi/warehouse
- Name: Verify Home-Page and Download-URL metadata URLs
- #16568 facutuesca: https://github.com/pypi/warehouse/pull/16568
- Repo: pypi/warehouse
- Name: docs: Clarify URL verification time validity
- #16576 facutuesca: https://github.com/pypi/warehouse/pull/16576
- Repo: pypi/warehouse
- Name: docs: link to docs in Verified Details section
- #16578 facutuesca: https://github.com/pypi/warehouse/pull/16578
- Repo: pypi/warehouse
- Name: Update icons reference in doc metadata docs
- #16584 DarkaMaul: https://github.com/pypi/warehouse/pull/16584
- Repo: pypi/warehouse
- Name: Add verification date to Verified Details section
- #16585 facutuesca: https://github.com/pypi/warehouse/pull/16585
- Repo: pypi/warehouse
- Name: Move URL verification logic into its own file
- #16592 facutuesca: https://github.com/pypi/warehouse/pull/16592
- Repo: pypi/warehouse
- Name: Documentation on how to implement a new service
- #16595 DarkaMaul: https://github.com/pypi/warehouse/pull/16595
- Repo: pypi/warehouse
- Name: Update tests to use sysmon
- #16621 DarkaMaul: https://github.com/pypi/warehouse/pull/16621
- Repo: pypi/warehouse
- Name: services: don’t send a Path where a str is expected
- #16622 woodruffw: https://github.com/pypi/warehouse/pull/16622
- Repo: pypi/warehouse
- Name: Revert PEP 740 persistence
- #16623 woodruffw: https://github.com/pypi/warehouse/pull/16623
- Repo: pypi/warehouse
- Name: warehouse: PEP 740 models
- #16625 woodruffw: https://github.com/pypi/warehouse/pull/16625
- Repo: pypi/warehouse
- Name: Verify emails in release metadata using PyPI user information
- #16631 facutuesca: https://github.com/pypi/warehouse/pull/16631
- Repo: pypi/warehouse
- Name: Remove dep on types-boto3
- #16633 DarkaMaul: https://github.com/pypi/warehouse/pull/16633
- Repo: pypi/warehouse
- Name: Add a new flag to disable PEP 740 support.
- #16645 DarkaMaul: https://github.com/pypi/warehouse/pull/16645
- Repo: pypi/warehouse
- Name: use sentry_sdk.new_scope
- #16682 woodruffw: https://github.com/pypi/warehouse/pull/16682
- Repo: pypi/warehouse
- Name: requirements: bump sigstore, pypi-attestations
- #16683 woodruffw: https://github.com/pypi/warehouse/pull/16683
- Repo: pypi/warehouse
- Name: PEP 740: add IntegrityService and interface
- #16684 woodruffw: https://github.com/pypi/warehouse/pull/16684
- Repo: pypi/warehouse
- Name: oidc: add missing claims check in publisher lookup
- #16698 facutuesca: https://github.com/pypi/warehouse/pull/16698
- Repo: pypi/warehouse
- Name: packaging: add initial hints to storage services
- #16709 woodruffw: https://github.com/pypi/warehouse/pull/16709
- Repo: pypi/warehouse
- Name: requirements: bump pypi-attestations to 0.0.12
- #16757 woodruffw: https://github.com/pypi/warehouse/pull/16757
- Repo: pypi/warehouse
- Name: test_simple: fix accidentally skipped test
- #16777 woodruffw: https://github.com/pypi/warehouse/pull/16777
- Repo: pypi/warehouse
- Name: Provenance retrieval route
- #16778 woodruffw: https://github.com/pypi/warehouse/pull/16778
- Repo: pypi/warehouse
- Name: conftest: put transaction manager in its own fixture
- #16796 woodruffw: https://github.com/pypi/warehouse/pull/16796
- Repo: pypi/warehouse
- Name: PEP 740: add provenance to simple API
- #16801 woodruffw: https://github.com/pypi/warehouse/pull/16801
- Repo: pypi/warehouse
- Name: docs/dev: add destructive migration docs
- #16831 woodruffw: https://github.com/pypi/warehouse/pull/16831
- Repo: pypi/warehouse
- Name: Check OIDC issuer claim when verifying uploaded PEP740 attestations
- #16860 facutuesca: https://github.com/pypi/warehouse/pull/16860
- Repo: pypi/warehouse
- Name: Ignore case when verifying GitLab/GitHub URLs
- #16899 DarkaMaul: https://github.com/pypi/warehouse/pull/16899
- Repo: pypi/warehouse
- Name: Verify GitLab URLs
- #16918 DarkaMaul: https://github.com/pypi/warehouse/pull/16918
- Repo: pypi/warehouse
- Name: test/oidc: rename TestPublisher, mark as abstract
- #16921 woodruffw: https://github.com/pypi/warehouse/pull/16921
- Repo: pypi/warehouse
- Name: attestations: provenance added metric
- #16934 woodruffw: https://github.com/pypi/warehouse/pull/16934
- Repo: pypi/warehouse
- Name: oidc: move reusable_worfklow_used field to the correct event
- #16935 woodruffw: https://github.com/pypi/warehouse/pull/16935
- Repo: pypi/warehouse
- Name: detail: fix spacing
- #16947 woodruffw: https://github.com/pypi/warehouse/pull/16947
- Repo: pypi/warehouse
- Name: requirements: bump pypi-attestations
- #17044 woodruffw: https://github.com/pypi/warehouse/pull/17044
- Repo: pypi/warehouse
- Name: dev/db: add some provenance fixtures to the dev DB
- #17051 woodruffw: https://github.com/pypi/warehouse/pull/17051
- Repo: pypi/warehouse
- Name: File details view, including attestations
- #17052 woodruffw: https://github.com/pypi/warehouse/pull/17052
- Repo: pypi/warehouse
- Name: legacy: ensure invalid attestation error is never empty
- #17065 woodruffw: https://github.com/pypi/warehouse/pull/17065
- Repo: pypi/warehouse
- Name: legacy: split attestation handling phases
- #17067 woodruffw: https://github.com/pypi/warehouse/pull/17067
- Repo: pypi/warehouse
- Name: file-details: small tweaks
- #17072 woodruffw: https://github.com/pypi/warehouse/pull/17072
- Repo: pypi/warehouse
- Name: blog: give Alexis credit
- #17081 woodruffw: https://github.com/pypi/warehouse/pull/17081
- Repo: pypi/warehouse
- Name: docs: add security model/considerations for attestations
- #17082 woodruffw: https://github.com/pypi/warehouse/pull/17082
- Repo: pypi/warehouse
- Name: user-docs: add section on trustworthiness
- #17091 woodruffw: https://github.com/pypi/warehouse/pull/17091
- Repo: pypi/warehouse
- Name: attestations: remove double states, simplify tests
- #17108 woodruffw: https://github.com/pypi/warehouse/pull/17108
- Repo: pypi/warehouse
- Name: attestations: allow upload of SLSA provenances
- #17121 facutuesca: https://github.com/pypi/warehouse/pull/17121
- Repo: pypi/warehouse
- Name: docs: migrate index/upload API docs to user docs
- #17123 woodruffw: https://github.com/pypi/warehouse/pull/17123
- Repo: pypi/warehouse
- Name: Add support PEP-740 attestations for GitLab CI/CD
- #17125 facutuesca: https://github.com/pypi/warehouse/pull/17125
- Repo: pypi/warehouse
- Name: Add documentation for PEP-740 attestations using GitLab CI/CD
- #17133 facutuesca: https://github.com/pypi/warehouse/pull/17133
- Repo: pypi/warehouse
- Name: Allow multiple attestations per distribution
- #17134 facutuesca: https://github.com/pypi/warehouse/pull/17134
- Repo: pypi/warehouse
- Name: user-docs: mention OIDC discovery
- #17137 woodruffw: https://github.com/pypi/warehouse/pull/17137
- Repo: pypi/warehouse
- Name: Improve file-details with certificate claims
- #17145 DarkaMaul: https://github.com/pypi/warehouse/pull/17145
- Repo: pypi/warehouse
- Name: Fix URL verification for GitHub/GitLab
- #17154 DarkaMaul: https://github.com/pypi/warehouse/pull/17154
- Repo: pypi/warehouse
- Name: docs: move stats API to user docs
- #17161 woodruffw: https://github.com/pypi/warehouse/pull/17161
- Repo: pypi/warehouse
- Name: docs: move BigQuery to user docs
- #17162 woodruffw: https://github.com/pypi/warehouse/pull/17162
- Repo: pypi/warehouse
- Name: docs: add Prerequisites section to attestations
- #17164 woodruffw: https://github.com/pypi/warehouse/pull/17164
- Repo: pypi/warehouse
- Name: docs: migrate RSS Feed docs to user docs
- #17171 woodruffw: https://github.com/pypi/warehouse/pull/17171
- Repo: pypi/warehouse
- Name: docs: move integration guide to user-docs
- #17173 woodruffw: https://github.com/pypi/warehouse/pull/17173
- Repo: pypi/warehouse
- Name: docs: migrate JSON API docs to user-docs
- #17178 woodruffw: https://github.com/pypi/warehouse/pull/17178
- Repo: pypi/warehouse
- Name: docs: update API links everywhere
- #17211 woodruffw: https://github.com/pypi/warehouse/pull/17211
- Repo: pypi/warehouse
- Name: docs: remove user-api-docs flash
- #17212 woodruffw: https://github.com/pypi/warehouse/pull/17212
- Repo: pypi/warehouse
- Name: docs: redirect all old API docs to new equivalents
- #17213 woodruffw: https://github.com/pypi/warehouse/pull/17213
- Repo: pypi/warehouse
- Name: Don’t install deploy dependencies for tests
- #17232 DarkaMaul: https://github.com/pypi/warehouse/pull/17232
- Repo: pypi/warehouse
- Name: docs: use Trusted Publishing uniformly as a term of art
- #17267 woodruffw: https://github.com/pypi/warehouse/pull/17267
- Repo: pypi/warehouse
- Name: requirements: drop direct pycurl dep
- #17280 woodruffw: https://github.com/pypi/warehouse/pull/17280
- Repo: rubygems/guides
- Name: trusted-publishing: add environment:
- #356 woodruffw: https://github.com/rubygems/guides/pull/356
- Repo: sigstore/docs
- Name: docs: Fix blockchain question in FAQ
- #295 facutuesca: https://github.com/sigstore/docs/pull/295
- Repo: sigstore/fulcio
- Name: docs: Fix extensions for digest values requiring a type prefix
- #1661 facutuesca: https://github.com/sigstore/fulcio/pull/1661
- Repo: sigstore/rekor
- Name: Add support for ed25519ph user keys in hashedrekord
- #1945 ret2libc: https://github.com/sigstore/rekor/pull/1945
- Repo: sigstore/rekor
- Name: Added support for sha384/sha512 hash algorithms in hashedrekords
- #1959 ret2libc: https://github.com/sigstore/rekor/pull/1959
- Repo: sigstore/sigstore-conformance
- Name: Support verifying digests in addition to artifacts
- #158 facutuesca: https://github.com/sigstore/sigstore-conformance/pull/158
- Repo: sigstore/sigstore-python
- Name: sigstore: add py.typed marker for type checking
- #1003 facutuesca: https://github.com/sigstore/sigstore-python/pull/1003
- Repo: sigstore/sigstore-python
- Name: sigstore: add new verification policies for missing extensions
- #1004 facutuesca: https://github.com/sigstore/sigstore-python/pull/1004
- Repo: sigstore/sigstore-python
- Name: sigstore: 3.0.0rc2
- #1005 facutuesca: https://github.com/sigstore/sigstore-python/pull/1005
- Repo: sigstore/sigstore-python
- Name: Add Python 3.12 classifier to pyproject.toml
- #1109 facutuesca: https://github.com/sigstore/sigstore-python/pull/1109
- Repo: sigstore/sigstore-python
- Name: Add minimum version to interrogate dependency
- #1110 facutuesca: https://github.com/sigstore/sigstore-python/pull/1110
- Repo: sigstore/sigstore-python
- Name: Add sigstore attest CLI subcommand to sign using DSSE envelopes
- #1115 facutuesca: https://github.com/sigstore/sigstore-python/pull/1115
- Repo: sigstore/sigstore-python
- Name: Print in-toto statement when verifying DSSE
- #1116 facutuesca: https://github.com/sigstore/sigstore-python/pull/1116
- Repo: sigstore/sigstore-python
- Name: Attestation CLI command improvements
- #1121 facutuesca: https://github.com/sigstore/sigstore-python/pull/1121
- Repo: sigstore/sigstore-python
- Name: Add CLI integration tests for attest subcommand
- #1124 facutuesca: https://github.com/sigstore/sigstore-python/pull/1124
- Repo: sigstore/sigstore-python
- Name: Add support for verifying digests to CLI verify commands
- #1125 facutuesca: https://github.com/sigstore/sigstore-python/pull/1125
- Repo: sigstore/sigstore-python
- Name: prep 3.3.0
- #1129 facutuesca: https://github.com/sigstore/sigstore-python/pull/1129
- Repo: sigstore/sigstore-python
- Name: Add CLI integration tests for sign subcommand
- #1134 facutuesca: https://github.com/sigstore/sigstore-python/pull/1134
- Repo: sigstore/sigstore-python
- Name: Deduplicate test fixtures
- #1137 facutuesca: https://github.com/sigstore/sigstore-python/pull/1137
- Repo: sigstore/sigstore-python
- Name: Add models for TimestampVerificationData
- #1186 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1186
- Repo: sigstore/sigstore-python
- Name: Fix warning for CLI verification of legacy bundles
- #1198 facutuesca: https://github.com/sigstore/sigstore-python/pull/1198
- Repo: sigstore/sigstore-python
- Name: Add CertificateAuthority
- #1200 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1200
- Repo: sigstore/sigstore-python
- Name: Timestamp Authority Verification
- #1206 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1206
- Repo: sigstore/sigstore-python
- Name: Add signature on Envelope
- #1211 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1211
- Repo: sigstore/sigstore-python
- Name: Sign Bundle with a Timestamp Authority
- #1216 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1216
- Repo: sigstore/sigstore-python
- Name: Use official GH action to generate build provenances
- #1219 facutuesca: https://github.com/sigstore/sigstore-python/pull/1219
- Repo: sigstore/sigstore-python
- Name: Update Sigstore Timestamp using dependabot
- #1225 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1225
- Repo: sigstore/sigstore-python
- Name: Dm/tsa doc
- #1255 DarkaMaul: https://github.com/sigstore/sigstore-python/pull/1255
- Repo: sigstore/sigstore-python
- Name: sigstore: extract LogEntry conversions to their own functions
- #992 facutuesca: https://github.com/sigstore/sigstore-python/pull/992
- Repo: sigstore/sigstore
- Name: Convert ED25519phSignerVerifier to the Pure version
- #1616 ret2libc: https://github.com/sigstore/sigstore/pull/1616
- Repo: sigstore/timestamp-authority
- Name: Fixes #846
- #847 DarkaMaul: https://github.com/sigstore/timestamp-authority/pull/847
Others
- Repo: AlDanial/cloc
- Name: Adding FunC language
- #872 cdahlheimer: https://github.com/AlDanial/cloc/pull/872
- Repo: emad-elsaid/xlog
- Name: link_preview.go: fix Twitter regexp
- #67 disconnect3d: https://github.com/emad-elsaid/xlog/pull/67