Releases: FransDevelopment/open-agent-trust-registry
Releases · FransDevelopment/open-agent-trust-registry
v1.1.0
Added
submitCLI command (npx @open-agent-trust/cli submit) for automated, secure Pull Request submission of registry entries and proofs directly to the global registry.
Security
- Fixed a critical JavaScript Injection Remote Code Execution (RCE) vulnerability in the GitHub Action verification pipeline.
- Hardened the auto-merge CI pipeline against Issuer Identity Hijacking (Account Takeover) by enforcing precise dual-anchor modification constraints: preventing
websiteandissuer_idchanges from being auto-merged, while seamlessly preserving self-serve key rotations and revocations.
v1.0.1
- Fix root signing key in root-keys.json
- Fix repository URLs in package.json files
- Fix compiler workflow to commit revocations.json
- Fix expiry test for revocation list