What’s Changed This release resolves GHSA-fx35-mq7g-6g98 , a verification bypass using an unexpected public key in a legacy bundle. Auto-detect default digest algorithm for public keys in #5019 fix(pkcs11key): return an error instead of panicking when no key pair matches in #5022 Supporting OCI Signing with X.509 Certificate Chain in #4614 test(inspect): replace mock TSA client usage with local timestamp response generator in #5021 fix: prevent shell completions for various options not taking filenames in #5032 fix(blob): compare file checksums case-insensitively in #5036 Verification bypass v