Skip to content

EU Parliament Monitor v0.8.53

Choose a tag to compare

@github-actions github-actions released this 01 May 21:58
· 204 commits to main since this release
Immutable release. Only release title and notes can be modified.

What's Changed

🌍 EU Parliament Integration

🏗️ Infrastructure & Performance

🔄 Code Quality & Refactoring

🔒 Security & Compliance

📝 Documentation

📦 Dependencies

  • Migrate 8 legacy news workflows onto 10-horizon-stage-helpers.md @copilot-swe-agent[bot] (#1600)
  • build(deps)(deps): bump european-parliament-mcp-server from 1.2.18 to 1.2.19 in the production-dependencies group @dependabot[bot] (#1597)
  • build(deps-dev)(deps-dev): bump the development-dependencies group with 2 updates @dependabot[bot] (#1595)
  • build(deps)(deps): bump the github-actions group with 3 updates @dependabot[bot] (#1594)
  • Look-ahead & election-cycle expansion: horizon registry, 6 new workflows, 8 templates, 2 methodologies @copilot-swe-agent[bot] (#1561)
  • build(deps-dev)(deps-dev): bump @axe-core/playwright from 4.11.2 to 4.11.3 in the development-dependencies group @dependabot[bot] (#1551)

🧪 Test Coverage Improvements

🤖 Custom Agent Updates

  • build(deps)(deps): bump european-parliament-mcp-server from 1.2.18 to 1.2.19 in the production-dependencies group @dependabot[bot] (#1597)

⚙️ Component Updates

📊 Release Metrics & Evidence

Test Coverage
API Documentation
E2E Tests

All test reports, coverage metrics, and API documentation are generated during build and available in the Documentation Hub.

🏛️ Architecture & Documentation

Document Description
Architecture C4 architecture models and system overview
Security Architecture Security design and controls
Threat Model STRIDE threat analysis
Data Model Data structures and relationships
Flowchart Process flows with security controls
State Diagram State transitions and lifecycles
Mindmap Conceptual relationships
SWOT Analysis Strategic analysis
CRA Assessment Cyber Resilience Act assessment
API Documentation TypeDoc-generated API reference

🔐 Security & Supply Chain Protection

SLSA 3
OpenSSF Scorecard
OpenSSF Best Practices

This release includes:

  • SLSA Build Provenance Attestations — Cryptographically signed build provenance
  • Software Bill of Materials (SBOM) — Complete dependency inventory in SPDX format
  • npm Provenance — Verified package publishing with attestation
  • CodeQL Security Scanning — Automated vulnerability detection
  • Dependency Scanning — Continuous vulnerability monitoring with Dependabot

Verify attestations:

gh attestation verify euparliamentmonitor-0.8.53.zip -R Hack23/euparliamentmonitor
npm audit signatures

Browse attestations: View all attestations

📋 ISMS Compliance & Policies

Hack23 ISMS
Information Security Policy
Open Source Policy
Secure Development

Compliance Frameworks

ISO 27001:2022
NIST CSF 2.0
CIS Controls v8.1

EU Parliament Monitor follows Hack23 AB's comprehensive ISMS with defense-in-depth architecture and documented security controls.

📦 Release Artifacts

Artifact Description Verification
euparliamentmonitor-0.8.53.zip Full application package SHA-256 checksum, SLSA attestation
euparliamentmonitor-0.8.53.spdx.json SBOM (SPDX format) SBOM attestation
*.intoto.jsonl SLSA attestations gh attestation verify
npm package euparliamentmonitor npm audit signatures

All artifacts are signed and attested using GitHub's SLSA Level 3 build provenance.

🚀 Deployment

🏗️ Built With

  • Node.js: 25.x
  • TypeScript: 6.0.x
  • Chart.js: 4.5.x
  • D3.js: 7.9.x
  • Vitest: 4.x
  • Playwright: 1.x
  • European Parliament MCP Server: 1.x

👥 Contributors

@Copilot, @dependabot[bot], @github-actions[bot], @pethers, copilot-swe-agent[bot], dependabot[bot] and github-actions[bot]

Full Changelog: v0.8.52...0.8.53

📦 Release Artifacts

  • euparliamentmonitor-v0.8.53.zip - Full application package
  • euparliamentmonitor-v0.8.53.spdx.json - SBOM (Software Bill of Materials)
  • *.intoto.jsonl - SLSA Build Provenance Attestations

📦 npm Package

npm install euparliamentmonitor@0.8.53

Published with npm provenance for supply chain security.

📚 Documentation

🔐 Security

All artifacts include SLSA Build Provenance attestations and SBOM for supply chain security.
Verify attestations using the GitHub CLI:

gh attestation verify euparliamentmonitor-v0.8.53.zip -R Hack23/euparliamentmonitor