| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search | 
| Name: vexctl | Distribution: openSUSE Tumbleweed | 
| Version: 0.4.0 | Vendor: openSUSE | 
| Release: 1.1 | Build date: Mon Sep 29 17:58:28 2025 | 
| Group: Productivity/Security | Build host: reproducible | 
| Size: 84916929 | Source RPM: vexctl-0.4.0-1.1.src.rpm | 
| Packager: http://bugs.opensuse.org | |
| Url: https://github.com/openvex/vexctl | |
| Summary: CLI tool to create, transform and attest VEX metadata | |
vexctl is a CLI tool to create, apply, and attest VEX (Vulnerability Exploitability eXchange) data. Its purpose is to help with the creation and management of VEX documents that allow "turning off" security scanner alerts of vulnerabilities known not to affect a product. VEX can be thought of as a "negative security advisory". Using VEX, software authors can communicate to their users that an otherwise vulnerable component has no security implications for their product.
Apache-2.0
* Mon Sep 29 2025 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.4.0:
    * update go, goreleaser and update/clean ci
    * Bump kubernetes-sigs/release-actions in the all group
    * Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group
  - Packaging improvements:
    * Update to BuildRequires: golang(API) >= 1.25 matching go.mod
* Mon Sep 22 2025 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.3.0+git181.33bac59:
    * Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group
    * Fix break w/cosign 2.6.0
    * Bump cosign & go-vex
    * Bump the all group across 1 directory with 2 updates
    * Fix 2.4 linter nits
    * Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group
    * Bump github.com/spf13/cobra from 1.9.1 to 1.10.1
    * Bump actions/setup-go from 5.5.0 to 6.0.0
    * Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group
    * Bump github.com/stretchr/testify from 1.10.0 to 1.11.0
    * Bump github.com/go-viper/mapstructure/v2 in the go_modules group
    * Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group
    * update release-utils and fix pkg name
    * Bump actions/checkout from 4.2.2 to 5.0.0
    * Bump github.com/secure-systems-lab/go-securesystemslib in the all group
    * Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0
    * Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0
    * Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group
    * Bump github.com/go-viper/mapstructure/v2 in the go_modules group
    * Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group
    * Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group
    * Bump the all group with 2 updates
    * migrate config to v2
    * Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0
  - Packaging improvements:
    * _service tar_scm versionrewrite-pattern v(.*?)(\+git0\.?.*?)?$
      which includes git offset only if offset exists. Useful for
      packages which frequently need package updates in the interim
      between upstream tagged releases.
* Mon Jun 16 2025 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.3.0+git133.ff97560:
    * Bump the all group across 1 directory with 2 updates
    * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group
    * Bump github.com/cloudflare/circl in the go_modules group
    * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group
    * Bump github.com/google/go-containerregistry in the all group
    * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group
    * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group
    * Bump the all group across 1 directory with 2 updates
    * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group
    * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group
    * Bump kubernetes-sigs/release-actions in the all group
    * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0
    * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group
    * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group
    * Bump github.com/golang-jwt/jwt/v4 in the go_modules group
    * Bump the all group with 2 updates
    * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group
    * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1
    * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group
    * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group
    * Bump github.com/go-jose/go-jose/v3 in the go_modules group
    * Bump github.com/go-jose/go-jose/v4 in the go_modules group
    * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group
    * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group
    * Bump the all group with 2 updates
    * use go1.24 and update golangci-lint
    * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group
    * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1
    * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group
    * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group
    * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group
    * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group
    * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group
    * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group
    * Bump the all group with 2 updates
    * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0
    * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group
    * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group
    * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group
    * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0
    * Bump go dependencies manually
    * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group
    * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group
    * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group
    * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group
    * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group
    * Bump the all group with 2 updates
    * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group
    * Bump github.com/golang-jwt/jwt/v4 in the go_modules group
    * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group
    * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group
    * Update verify.yaml
    * Update release.yaml
    * Update ci-build-test.yaml
    * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group
    * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group
    * Bump kubernetes-sigs/release-actions in the all group
    * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group
    * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group
    * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group
    * Bump the all group with 2 updates
    * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group
    * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group
    * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group
    * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group
    * upgrade to go1.23
  - Packaging improvements:
    * _service tar_scm set revision to branch main until upstream
      next has a tagged release
    * _service tar_scm when revision is a branch name e.g. master
      use versionformat @PARENT_TAG@+git@TAG_OFFSET@.%h to represent
      git commit history included beyond last tagged release. Archive
      name will be: name-X.Y.Z+gitN.shortsha.tar.gz. When upstream
      project resumes tagged releases drop the param versionformat
      and restore revision to tag name e.g. vX.Y.Z.
    * Update to BuildRequires: golang(API) >= 1.24 matching go.mod
    * %install remove extraneous comment and dest path quoting
* Tue Sep 10 2024 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.3.0:
    * Bump github.com/sigstore/sigstore from 1.8.8 to 1.8.9 in the all group
    * Bump actions/upload-artifact from 4.3.6 to 4.4.0 in the all group
    * Bump sigstore/cosign-installer from 3.5.0 to 3.6.0 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.3.0 to 2.4.0
    * Bump the all group with 2 updates
    * Bump actions/upload-artifact from 4.3.5 to 4.3.6 in the all group
    * Bump actions/upload-artifact from 4.3.4 to 4.3.5 in the all group
    * test: add a leading slash to repository_url
    * Update pkg/ctl/implementation.go
    * Fix OCI repository URL resolution
    * Bump golangci/golangci-lint-action from 6.0.1 to 6.1.0 in the all group
    * Bump github.com/docker/docker in the go_modules group
    * Bump sigs.k8s.io/release-utils from 0.8.3 to 0.8.4 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.3.0
    * Bump softprops/action-gh-release from 2.0.7 to 2.0.8 in the all group
    * update go.mod to 1.22.5
    * update golanci-lint
    * Bump github.com/google/go-containerregistry in the all group
    * Bump softprops/action-gh-release from 2.0.6 to 2.0.7 in the all group
    * Bump github.com/sigstore/sigstore from 1.8.6 to 1.8.7 in the all group
    * Improve the generated template README
    * Add support to vulnerability aliases
    * Fix Copyright in Boilerplates
    * Bump actions/setup-go from 5.0.1 to 5.0.2 in the all group
    * Bump google.golang.org/grpc in the go_modules group
    * Bump github.com/google/go-containerregistry from 0.19.2 to 0.20.0
    * Bump sigs.k8s.io/release-utils from 0.8.2 to 0.8.3 in the all group
    * Prevent from specifying subcomponents when multiple products are defined
    * fix(create): support multiple --product flags
    * Bump go to 1.22.4
    * Bump github.com/sigstore/sigstore in the all group across 1 directory
    * Bump actions/upload-artifact from 4.3.3 to 4.3.4 in the all group
    * Bump github.com/hashicorp/go-retryablehttp in the go_modules group
    * Bump softprops/action-gh-release from 2.0.5 to 2.0.6 in the all group
    * Bump ko-build/setup-ko from 0.6 to 0.7 in the all group
    * Bump the all group with 2 updates
    * Bump actions/checkout from 4.1.6 to 4.1.7 in the all group
    * Bump goreleaser/goreleaser-action from 5.1.0 to 6.0.0
    * update installation methods with homebrew
    * Bump github.com/sigstore/sigstore from 1.8.3 to 1.8.4 in the all group
    * Bump github.com/package-url/packageurl-go in the all group
    * Bump actions/checkout from 4.1.5 to 4.1.6 in the all group
    * Bump goreleaser/goreleaser-action from 5.0.0 to 5.1.0 in the all group
    * Bump golangci/golangci-lint-action from 6.0.0 to 6.0.1 in the all group
    * Bump sigs.k8s.io/release-utils from 0.8.1 to 0.8.2 in the all group
    * Bump golangci/golangci-lint-action from 5.3.0 to 6.0.0
    * Bump softprops/action-gh-release from 2.0.4 to 2.0.5 in the all group
    * Bump the all group with 2 updates
    * Bump actions/setup-go from 5.0.0 to 5.0.1 in the all group
    * Bump kubernetes-sigs/release-actions in the all group
    * Bump golangci/golangci-lint-action from 5.0.0 to 5.1.0 in the all group
    * Bump golangci/golangci-lint-action from 4.0.0 to 5.0.0
    * Bump actions/checkout from 4.1.3 to 4.1.4 in the all group
    * Bump actions/upload-artifact from 4.3.2 to 4.3.3 in the all group
    * Bump actions/checkout from 4.1.2 to 4.1.3 in the all group
    * Bump golang.org/x/net from 0.22.0 to 0.23.0 in the go_modules group
    * Bump actions/upload-artifact from 4.3.1 to 4.3.2 in the all group
    * Bump sigstore/cosign-installer from 3.4.0 to 3.5.0 in the all group
    * Bump github.com/sigstore/cosign/v2 from 2.2.3 to 2.2.4
    * Bump sigs.k8s.io/release-utils from 0.8.0 to 0.8.1 in the all group
    * Add support for Golang GO-* vulnerability identifier
    * Bump sigs.k8s.io/release-utils from 0.7.7 to 0.8.0
    * Bump the all group with 1 update
    * run attest in prs to test the entire release flow
    * Bump the all group with 1 update
    * Bump the all group with 1 update
    * fix lints
    * group dependabot updates
    * upgrade to go1.22
    * Bump google.golang.org/protobuf from 1.32.0 to 1.33.0
    * Bump github.com/go-jose/go-jose/v3 from 3.0.2 to 3.0.3
    * Bump gopkg.in/go-jose/go-jose.v2 from 2.6.1 to 2.6.3
    * Bump github.com/docker/docker
    * Bump kubernetes-sigs/release-actions from 0.1.3 to 0.1.4
    * Bump github.com/google/go-containerregistry from 0.19.0 to 0.19.1
    * Update release.yaml
    * Bump softprops/action-gh-release from 2.0.3 to 2.0.4
    * Bump actions/checkout from 4.1.1 to 4.1.2
    * Bump softprops/action-gh-release from 1 to 2
    * Bump github.com/stretchr/testify from 1.8.4 to 1.9.0
    * Bump golangci/golangci-lint-action from 3.7.0 to 4.0.0
    * Bump github.com/sigstore/sigstore from 1.8.1 to 1.8.2
    * Bump github.com/sigstore/rekor from 1.3.4 to 1.3.5
    * Bump github.com/sigstore/cosign/v2 from 2.2.2 to 2.2.3
    * Bump sigstore/cosign-installer from 3.3.0 to 3.4.0
    * Bump github.com/google/go-containerregistry from 0.18.0 to 0.19.0
    * Bump github.com/sigstore/sigstore from 1.8.0 to 1.8.1
    * Bump github.com/google/go-containerregistry from 0.17.0 to 0.18.0
    * Bump kubernetes-sigs/release-actions from 0.1.2 to 0.1.3
    * Bump github.com/sigstore/sigstore from 1.7.6 to 1.8.0
    * Fix linter errors
* Fri Dec 15 2023 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.2.6:
    * Add generate test fixtures
    * Add generate subcommand
    * Add generate --init test
    * Add generate --init flag
    * Only read openvex files as templates
    * vexctl generate
    * Add Generate method
    * Add ReadTemplateData() function
    * Bump sigstore/cosign-installer from 3.2.0 to 3.3.0
    * Bump actions/setup-go from 4.1.0 to 5.0.0
    * go mod tidy
    * Attach: Add OCI annotations for keyless verification
    * Sign: Upload to tlog and capture sig data
    * Bump github.com/sigstore/cosign/v2 from 2.2.1 to 2.2.2
    * Update examples to v0.2.0
    * add: Split out of cmd validation logic
    * addOptions validation test
    * vexctl add: Fix bug when writing docs in-place
    * Bump github.com/sigstore/sigstore from 1.7.5 to 1.7.6
    * Move release actions to kubernetes-sigs
    * Bump github.com/google/go-containerregistry from 0.16.1 to 0.17.0
    * add boilerplate headers
    * add snapshot job
    * cleanup
    * add sboms and revamp the provanance with k8s-release actions tools
    * bump golangci-lint to v1.55.x
* Wed Nov 15 2023 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.2.5:
    * Bump sigs.k8s.io/release-utils from 0.7.6 to 0.7.7
    * Bump github.com/sigstore/cosign/v2 from 2.2.0 to 2.2.1
    * Bump sigstore/cosign-installer from 3.1.2 to 3.2.0
    * Bump github.com/spf13/cobra from 1.7.0 to 1.8.0
    * Bump sigs.k8s.io/release-utils from 0.7.5 to 0.7.6
    * Bump github.com/sigstore/sigstore from 1.7.4 to 1.7.5
    * update version comments
    * Bump actions/checkout from 4.1.0 to 4.1.1
    * Bump github.com/sigstore/sigstore from 1.7.3 to 1.7.4
    * Attest: Add refs flag, improve help and command
    * Split intoto subj normlzatn into image and other
    * Reuse hashes from existing VEX products
    * Reuse purl hashes in product
    * Bump sigs.k8s.io/release-utils from 0.7.4 to 0.7.5
    * Update README examples to v0.2.0
    * Bump github.com/package-url/packageurl-go from 0.1.1 to 0.1.2
    * Bump actions/checkout from 4.0.0 to 4.1.0
    * Factor out document write logic
    * Add add subcommand
    * Bump goreleaser/goreleaser-action from 4.6.0 to 5.0.0
    * fix lints
    * upgrade to go1.21
    * Bump goreleaser/goreleaser-action from 4.4.0 to 4.6.0
    * Add options validation tests
    * Make out file option reusable
    * Create vex statements from st options
    * Refactor commands and options
    * Bump actions/checkout from 3.6.0 to 4.0.0
    * Bump sigstore/cosign-installer from 3.1.1 to 3.1.2
    * Bump github.com/sigstore/sigstore from 1.7.2 to 1.7.3
    * Bump github.com/sigstore/cosign/v2 from 2.1.1 to 2.2.0
    * Update show to list
    * show subcommand creation for review
    * go.mod: Pull go-vex@v0.2.5
    * Revamp tests for v0.2.2 add more fixtures
    * Update vexctl implementation to v0.2.0
    * Update vexctl create to v0.2.0
    * Rename test fixtures to versioned filenames
    * Drop depguard from golangci lint
    * Bump actions/checkout from 3.5.3 to 3.6.0
    * Bump slsa-framework/slsa-github-generator from 1.8.0 to 1.9.0
    * Update SARIF filtering examples
    * Update verify.yaml
    * Bump golangci/golangci-lint-action from 3.6.0 to 3.7.0
    * Bump goreleaser/goreleaser-action from 4.3.0 to 4.4.0
    * Bump github.com/sigstore/sigstore from 1.7.1 to 1.7.2
    * Bump actions/setup-go from 4.0.1 to 4.1.0
    * Bump slsa-framework/slsa-github-generator from 1.7.0 to 1.8.0
    * Bump github.com/google/go-containerregistry from 0.15.2 to 0.16.1
* Fri Jul 21 2023 Jeff Kowalczyk <jkowalczyk@suse.com>
  - Update to version 0.2.3:
    * Rename artifacts to vexctl
    * refactor release job
    * fix deprecated flag
    * Add ko installer to release workflow
    * Add missing ldflags script
    * go.mod: Pull go-vex v0.2.1
    * Drop deprecated vex.StatementFromID
    * Bump github.com/secure-systems-lab/go-securesystemslib
    * Fix --subcomponents flag
    * Add support for PRISMA- identifiers
    * Bump github.com/sigstore/cosign/v2 from 2.1.0 to 2.1.1
    * Bump sigstore/cosign-installer from 3.1.0 to 3.1.1
    * Bump sigstore/cosign-installer from 3.0.5 to 3.1.0
    * Bump github.com/sigstore/cosign/v2
    * Bump github.com/sigstore/sigstore from 1.7.0 to 1.7.1
    * Pull go-vex @ HEAD
    * Use vex.Open instead of vex.Load to support multi format vex
    * Add initial CSAF example files
    * Add OpenVEX examples
    * vexctl create: add --impaact-statement
    * filter: Drop debug messages, improve output
    * Add RUSTSEC, GHSA, RHSA to known identifiers
    * Bump github.com/package-url/packageurl-go from 0.1.0 to 0.1.1
    * Bump github.com/sigstore/sigstore from 1.6.5 to 1.7.0
    * Bump goreleaser/goreleaser-action from 4.2.0 to 4.3.0
    * Bump golangci/golangci-lint-action from 3.5.0 to 3.6.0
    * Bump actions/checkout from 3.5.2 to 3.5.3
    * Bump slsa-framework/slsa-github-generator from 1.6.0 to 1.7.0
    * Bump github.com/sirupsen/logrus from 1.9.2 to 1.9.3
    * Bump golangci/golangci-lint-action from 3.4.0 to 3.5.0
    * Bump github.com/sigstore/sigstore from 1.6.4 to 1.6.5
    * Bump github.com/stretchr/testify from 1.8.3 to 1.8.4
    * Bump github.com/stretchr/testify from 1.8.2 to 1.8.3
    * Bump sigstore/cosign-installer from 3.0.4 to 3.0.5
    * Bump github.com/google/go-containerregistry from 0.15.1 to 0.15.2
    * Bump github.com/sirupsen/logrus from 1.9.0 to 1.9.2
    * Bump sigstore/cosign-installer from 3.0.3 to 3.0.4
    * Bump sigs.k8s.io/release-utils from 0.7.3 to 0.7.4
    * Bump actions/setup-go from 4.0.0 to 4.0.1
    * fix lints
    * bump to go 1.20 and update some dependencies
    * Bump slsa-framework/slsa-github-generator from 1.5.0 to 1.6.0
    * Bump github.com/sigstore/sigstore from 1.6.3 to 1.6.4
    * Bump github.com/in-toto/in-toto-golang from 0.8.0 to 0.9.0
    * Bump github.com/sigstore/cosign/v2 from 2.0.1 to 2.0.2
    * Bump github.com/in-toto/in-toto-golang from 0.7.1 to 0.8.0
    * Bump github.com/sigstore/sigstore from 1.6.2 to 1.6.3
    * Bump sigstore/cosign-installer from 3.0.2 to 3.0.3
    * Bump actions/checkout from 3.5.1 to 3.5.2
    * Bump actions/checkout from 3.5.0 to 3.5.1
    * Bump github.com/sigstore/sigstore from 1.6.1 to 1.6.2
    * Bump sigstore/cosign-installer from 3.0.1 to 3.0.2
    * Bump github.com/sigstore/cosign/v2
    * Bump github.com/sigstore/sigstore from 1.6.0 to 1.6.1
    * Bump github.com/in-toto/in-toto-golang from 0.7.0 to 0.7.1
    * Bump github.com/spf13/cobra from 1.6.1 to 1.7.0
    * Bump actions/checkout from 3.4.0 to 3.5.0
    * Bump actions/setup-go from 3.5.0 to 4.0.0
    * Bump github.com/google/go-containerregistry
    * Bump actions/checkout from 3.3.0 to 3.4.0
    * set cosign yes env var
    * Bump sigstore/cosign-installer from 2.8.1 to 3.0.1
    * update dependencies and cosign to v2
    * Bump github.com/stretchr/testify from 1.8.1 to 1.8.2
    * Bump slsa-framework/slsa-github-generator from 1.4.0 to 1.5.0
    * Bump github.com/sigstore/sigstore from 1.5.1 to 1.5.2
    * Bump github.com/in-toto/in-toto-golang
    * Bump github.com/openvex/go-vex
    * Fix broken parameters
    * Fix examples based on actual command output
    * Update maintainers to match community
    * Add boilerplate to newfile
    * Add unit test to references verifier
    * Ensure attested refs are in doc
    * --attach implies --sign
    * Update attest subcm help
    * Drop attestation targets from CLI
    * Add test for ListDocumentProducts
    * Rework attestation code
    * go mod: pull purl module
    * Add images test document
    * Add test for NormalizeImageRefs
    * Bump goreleaser/goreleaser-action from 4.1.0 to 4.2.0
    * Fix exmple and testdata
    * Bump github.com/google/go-containerregistry from 0.12.1 to 0.13.0
    * Bump golangci/golangci-lint-action from 3.3.1 to 3.4.0
    * fix: missing metadata on document merge
    * small fixes
    * add provenance and refactor release job
    * build vexctl image using ko
    * Add initial MAINTAINERS.md
    * update license headers
    * More improvements to README
    * Update README
    * Bump github.com/sigstore/sigstore from 1.5.0 to 1.5.1
/usr/bin/vexctl /usr/share/doc/packages/vexctl /usr/share/doc/packages/vexctl/README.md /usr/share/licenses/vexctl /usr/share/licenses/vexctl/LICENSE
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Oct 24 23:22:36 2025