Releases: stacknil/scientific-computing-toolkit
Releases · stacknil/scientific-computing-toolkit
sbom-diff-and-risk v0.2.0
Highlights
- policy-aware reporting and enforcement-oriented CLI behavior
- GitHub-compatible SARIF export with code scanning validation on
main - conservative parser tightening for deterministic local mode
sbom-diff-and-riskpackage version bumped to0.2.0
Verification
- local
python -m pytestpassed before release - GitHub code scanning analysis on
mainnow reports tool version0.2.0
v0.1.0
v0.1.0
- Added deterministic diffing for CycloneDX JSON, SPDX JSON, requirements.txt, and pyproject.toml
- Added conservative risk buckets for new packages, major upgrades, unknown licenses, suspicious sources, and opt-in future stale evaluation
- Added stable JSON/Markdown reporting with golden tests
- Clarified scope: no CVE matching, no hidden enrichment, no reputation scoring by default