Transparency reports
For each release, the following reports are attached to the GitHub Release page:
sbom.json— CycloneDX SBOMtrivy-scan.json— Trivy vulnerability scanosv-scan.json— OSV scanthird-party-notices.txt— OSS attributions
Why coverage / test reports are not published
Section titled “Why coverage / test reports are not published”Coverage (coverage-lcov.info) and test HTML reports enumerate src/** file paths,
which would leak the closed-source structure. They remain internal.