- Added cosign signatures and SLSA Level 3 provenance for Argo CD container images and CLI binaries
- Fixed CVE‑2024‑45296 (ReDoS) by upgrading regexp, plus fixes for perpetual appset reconciliation and diffing on schema validation failures
- Updated documentation on cluster‑scoping changes and bumped UI dependencies (webpack, dompurify, express)
