Skip to main content

Verify a release

Every release is signed keyless with Sigstore, the same way Kubernetes and Flux sign theirs. checksums.txt.sigstore.json proves that DeaconGuard's release workflow on GitHub produced checksums.txt, and checksums.txt lists the SHA-256 of every file in the release. Nobody holds a signing key that could leak.

The install script always checks the checksum, and checks the signature too when cosign is installed.

Check it yourself​

Download checksums.txt, checksums.txt.sigstore.json and the files you want from the release, then:

VERSION=0.4.0
cosign verify-blob checksums.txt --bundle checksums.txt.sigstore.json \
--certificate-identity "https://github.com/Cloudopsshell/deaconguard/.github/workflows/release.yml@refs/tags/v${VERSION}" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com

sha256sum --check --ignore-missing checksums.txt

Verified OK from cosign and OK for each file mean the files are exactly what the release workflow built for that version.