)]}'
{
  "commit": "b0e64237bac20b72a9e32c9afa4cf16e5073b551",
  "tree": "612558b48a8486c40e763572d092996b5ffa8bee",
  "parents": [
    "4f6f815179266d3b6fd2b806f10471d5cc5f0efc"
  ],
  "author": {
    "name": "Paul Wankadia",
    "email": "junyer@google.com",
    "time": "Mon Apr 08 22:28:14 2024 +0000"
  },
  "committer": {
    "name": "Paul Wankadia",
    "email": "junyer@google.com",
    "time": "Mon Apr 08 22:56:13 2024 +0000"
  },
  "message": "Add a GitHub Actions workflow for releases.\n\nTriggering off a pushed tag, it creates the corresponding release, then\ndownloads the source code archives and uploads them as release assets\nusing Sigstore for signature. Someday, it will be convenient to switch\nto using SLSA for signature and provenance, but that day is not today.\n\nYours truly has been wanting to automate away this dance for years. In\nlight of CVE-2024-3094, now seemed like a really good time to do that.\n\nChange-Id: I0972ae5dcae7193ef457e23553a7dbe22adbfb1c\nReviewed-on: https://code-review.googlesource.com/c/re2/+/62970\nReviewed-by: Ash Liu \u003calmquist@google.com\u003e\nReviewed-by: Paul Wankadia \u003cjunyer@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "18ee6da2f89ea80971442101e504031c317429e1",
      "new_mode": 33188,
      "new_path": ".github/workflows/release.yml"
    }
  ]
}
