fix(dockerfile): purge npm cache in same layer as installs to prevent secret leakage
#30 -Commit
94333e4d32
pushed by
jz
ci(scan): add Grype scanning alongside Trivy; fix --vuln-type flag
#28 -Commit
71494a59b3
pushed by
jz
fix(docker): patch picomatch 4.0.3 → 4.0.4 (CVE-2026-33671)
#27 -Commit
12d75b0dc2
pushed by
jz
feat(ci): generate SBOMs in scan job and attach attestations on push
#17 -Commit
e6b46087b3
pushed by
jz
feat(ci): add Trivy container security scanning before push
#16 -Commit
530def213b
pushed by
jz
chore(docker): pin Claude Code install to stable release channel
#10 -Commit
b76d1e5e2a
pushed by
jz
chore(hooks): fix executable bit on build.sh and hooks/pre-commit
#7 -Commit
8b4f08e68c
pushed by
jz
ci: add Forgejo action to build and push Docker images to registry
#1 -Commit
1dbbbc840d
pushed by
jz