Skip to content

Riksdagsmonitor v0.7.0

Choose a tag to compare

@github-actions github-actions released this 28 Feb 20:16
· 5833 commits to main since this release
Immutable release. Only release title and notes can be modified.

What's Changed

📚 Documentation

🧪 Testing

🌐 Internationalization

📊 Release Metrics & Evidence

Test Coverage
API Documentation
E2E Tests
Dependencies

All test reports, coverage metrics, and API documentation are generated during build and available in the Documentation Hub.

🔐 Security & Supply Chain Protection

SLSA Level 2+
OpenSSF Scorecard

This release includes:

  • SLSA Build Provenance Attestations - Cryptographically signed build provenance
  • Software Bill of Materials (SBOM) - Complete dependency inventory in SPDX format
  • SHA-256 Checksums - All artifacts include checksums for integrity verification
  • CodeQL Security Scanning - Automated vulnerability detection
  • Dependency Scanning - Continuous vulnerability monitoring with Dependabot

Verify attestations:

gh attestation verify riksdagsmonitor-0.7.0.zip -R Hack23/riksdagsmonitor

Browse attestations: View all attestations

📋 ISMS Compliance & Policies

Hack23 ISMS
Information Security Policy
Open Source Policy
Secure Development

Compliance Frameworks

ISO 27001:2022
NIST CSF 2.0
CIS Controls v8.1

Riksdagsmonitor follows Hack23 AB's comprehensive ISMS with defense-in-depth architecture and documented security controls.

📦 Release Artifacts

Artifact Description Verification
riksdagsmonitor-0.7.0.zip Production build SHA-256 checksum, SLSA attestation
riksdagsmonitor-0.7.0.zip.sha256 SHA-256 checksum Compare with sha256sum
riksdagsmonitor-0.7.0.spdx.json SBOM (SPDX format) SBOM attestation
*.intoto.jsonl SLSA attestations gh attestation verify

🚀 Deployment

🏗️ Built With

  • Node.js: 24.x
  • Vite: 7.x
  • Chart.js: 4.5.x
  • D3.js: 7.9.x
  • Vitest: 4.x
  • Cypress: 15.x

👥 Contributors

@Copilot, @pethers, GitHub Copilot, copilot-swe-agent[bot] and github-actions[bot]

Full Changelog: v0.6.4...0.7.0

📦 Release Artifacts

  • riksdagsmonitor-v0.7.0.zip - Production build
  • riksdagsmonitor-v0.7.0.zip.sha256 - Checksum for verification
  • riksdagsmonitor-v0.7.0.spdx.json - SBOM (Software Bill of Materials)
  • *.intoto.jsonl - SLSA Build Provenance Attestations

📚 Documentation

🔐 Security

All artifacts include SLSA Build Provenance attestations and SBOM for supply chain security.
Verify attestations using the GitHub CLI:

gh attestation verify riksdagsmonitor-v0.7.0.zip -R Hack23/riksdagsmonitor