NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3377 most downloaded on npm
code-signing for npm packages
Last release 1 months ago
21 Aug 2026
Release timing varies
gaps range from 2 weeks to 9 months
Nearly every release is documented
notes for 13 of 14 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
15 releases · first in 2023
One column per quarter.
Signed-off-by: Appu appu@google.com
release/typescript/v0.5.1
release/typescript/v0.5.1
Introduce v0.2 TrustedRoot, un-deprecate log ID. Checkpoint key ID and Operator for TrustedRoot are only set for v0.2 TrustedRoot.
Added Rekor v2 generated clients
Deprecated LMS/LMS-OTS as supported signing algorithms
Added deprecated, but still in use, algorithms for ECDSA P384 and P512 using SHA256
Announced deprecation of JSONSchema outputs from this project
Allowed specifying artifact digest for verification
Added TransparencyLogInstance.checkpoint_key_id as an optional key identifier for logs that generate checkpoints
Added client configuration message for signing
Deterministic ECDSA is deprecated
VerificationMaterials.contents now has an additional certificate variant,
which is preferred in 0.3 bundles with the Sigstore PGI (#191)PublicKeyDetails message
(#194, #212)
CloudEvents proto for Rekor pub/sub messages
There were no changes in this release.
There were no removals in this release.
TransparencyLogEntry.inclusion_proof is now marked as required (was previously optional), while TransparencyLogEntry.inclusion_promise is now marked a
TransparencyLogEntry.inclusion_proof is now marked as required (was previously optional),
while TransparencyLogEntry.inclusion_promise is now marked as optional (was previously
required) (#84)
More Rekor messages and message fields have been marked as required (#79)
Ruby bindings: class names have been updated and now live in the Sigstore:: namespace
(#87)
Docs: Clarify that TransparencyLogEntry.canonicalized_body is optional
(#74)
Docs: Clarify that key IDs are digests over SPKI encodings (#73)
Docs: Clarify that bundled certificate chains must not contain root or intermediate certificates that should be trused out-of-band (#77)
Docs: Clarify TimeRange validity periods
(#78)
There were no removals in this release.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →