Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .clusterfuzzlite/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ set -euo pipefail
cd /src/pkg-defender

# Install the project and atheris
pip install "uv==0.5.1" --hash=sha256:4d1ec4a1bc19b523a84fc1bf2a92e9c4d982c831d3da450af71fc3057999d456 --require-hashes
printf '%s\n' 'uv==0.5.1 --hash=sha256:4d1ec4a1bc19b523a84fc1bf2a92e9c4d982c831d3da450af71fc3057999d456' > /tmp/uv-requirements.txt
pip install -r /tmp/uv-requirements.txt --require-hashes
uv pip install --system --no-deps .
uv pip install --system "atheris==2.3.0"
3 changes: 2 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -542,7 +542,8 @@ jobs:
VERSION="${{ needs.validate.outputs.version }}"
echo "Smoke testing pkg-defender==${VERSION}"
python -m venv /tmp/smoke-venv
/tmp/smoke-venv/bin/pip install "uv==0.5.1" --hash=sha256:4d1ec4a1bc19b523a84fc1bf2a92e9c4d982c831d3da450af71fc3057999d456 --require-hashes
printf '%s\n' 'uv==0.5.1 --hash=sha256:4d1ec4a1bc19b523a84fc1bf2a92e9c4d982c831d3da450af71fc3057999d456' > /tmp/uv-requirements.txt
/tmp/smoke-venv/bin/pip install -r /tmp/uv-requirements.txt --require-hashes

echo "Waiting for pkg-defender==${VERSION} to appear on PyPI..."
timeout 120 bash -c '
Expand Down
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,18 @@ and this project adheres to

## [Unreleased]

## [1.0.7] - 2026-07-23

### Fixed

- `pip install` with `--hash=<sha>` CLI flag rejected by pip ≥26.1.2 — root
cause: `--hash` is a per-requirement option valid only inside pip requirements
files, not as a CLI flag. Moved `--hash` into a temp requirements file
(`printf '%s\n' 'uv==0.5.1 --hash=...' > /tmp/uv-requirements.txt && pip
install -r /tmp/uv-requirements.txt --require-hashes`) in
`.clusterfuzzlite/build.sh` and `.github/workflows/release.yml`, preserving
SHA256 pinning and OpenSSF Scorecard Pinned-Dependencies compliance.

## [1.0.6] - 2026-07-21

### Added
Expand Down
2 changes: 1 addition & 1 deletion docs/man/pkgd.1
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
.\" Automatically generated by Pandoc 3.10
.\"
.TH "PKGD" "1" "July 20, 2026" "pkg\-defender 1.0.6" "User Commands"
.TH "PKGD" "1" "July 23, 2026" "pkg\-defender 1.0.7" "User Commands"
.SH NAME
pkgd \(em supply chain attack defense CLI
.SH SYNOPSIS
Expand Down
4 changes: 2 additions & 2 deletions docs/man/pkgd.1.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: PKGD(1)
date: "July 20, 2026"
footer: "pkg-defender 1.0.6"
date: "July 23, 2026"
footer: "pkg-defender 1.0.7"
header: "User Commands"
---

Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "hatchling.build"

[project]
name = "pkg-defender"
version = "1.0.6"
version = "1.0.7"
description = "Stop supply chain attacks before they reach your machine or CI pipeline"
requires-python = ">=3.11"
license = "Apache-2.0"
Expand Down
2 changes: 1 addition & 1 deletion src/pkg_defender/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -25,4 +25,4 @@

__version__ = _v
except ImportError:
__version__ = "1.0.6" # Tier 4: hardcoded fallback
__version__ = "1.0.7" # Tier 4: hardcoded fallback
2 changes: 1 addition & 1 deletion uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.