v0.5.0
VEX Attestations
Added Vulnerability Exploitability eXchange (VEX) attestations to all images.
Kyverno Policy Templates
Pre-built Kyverno policies for signature verification.
SBOM Performance
50% faster SBOM generation for large images.
New features, improvements, and fixes to ImageSentinel.
Added Vulnerability Exploitability eXchange (VEX) attestations to all images.
Pre-built Kyverno policies for signature verification.
50% faster SBOM generation for large images.
Native GitLab CI/CD integration with auto-generated pipeline templates.
ARM64 and AMD64 hardened images available.
Fixed token refresh for long-running CI pipelines.
All images now include SLSA Level 3 build provenance attestations.
Added hardened Go minimal base images.
New `sentinel verify` command for local signature verification.
Released official GitHub Actions for image hardening.
Added hardened Java 17 and Java 21 minimal base images.
ImageSentinel private beta with Python and Node.js hardened images.
Keyless image signing with Sigstore Cosign.
CycloneDX and SPDX SBOM formats.
Follow our blog for detailed release notes and engineering insights.