supply-chain-release · scanned

A vulnerability scan ran against this build and came back clean.

Run the scan inside the release job rather than reusing an earlier result. The one-day window exists because a scan is a claim about the advisory database at a moment: last week’s clean result is cryptographically valid, honestly stale, and says nothing about the advisories published since.

see history · edit this page