Skip to content

Verify a download

Releases are signed in CI by the release workflow with Sigstore keyless signing. There is no long-lived private key. Every signature is tied to this identity, where X.Y.Z is the release:

https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z

issued by https://token.actions.githubusercontent.com. Anything signed by another identity did not come from a SegAudit release.

Run this on the connected machine where you downloaded the bundle, with Cosign installed. It needs no internet: trusted_root.json from the same release holds the Sigstore trust root.

Terminal window
sha256sum -c segaudit-X.Y.Z-linux-amd64.tar.gz.sha256
cosign verify-blob \
--trusted-root trusted_root.json \
--bundle segaudit-X.Y.Z-linux-amd64.tar.gz.sigstore.json \
--certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
segaudit-X.Y.Z-linux-amd64.tar.gz

On macOS use shasum -a 256 -c instead of sha256sum -c. segaudit-update runs the same checks on the jump host, the signature check only when Cosign is installed there.

To accept any release rather than one version, swap --certificate-identity for:

Terminal window
--certificate-identity-regexp '^https://github\.com/lukeponio/segaudit/\.github/workflows/release\.yml@refs/tags/v[0-9]+\.[0-9]+\.[0-9]+$'

Each installer has its own .sha256 and .sigstore.json, signed by the same identity. With trusted_root.json from the same release:

Terminal window
sha256sum -c SegAudit-Setup-X.Y.Z-windows-x64.exe.sha256
cosign verify-blob \
--trusted-root trusted_root.json \
--bundle SegAudit-Setup-X.Y.Z-windows-x64.exe.sigstore.json \
--certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
SegAudit-Setup-X.Y.Z-windows-x64.exe

Swap in the .dmg, .deb or .rpm name for the other installers. On Windows without sha256sum, compare the file’s hash from Get-FileHash SegAudit-Setup-X.Y.Z-windows-x64.exe with the one in the .sha256 file. The Sigstore signature is not an operating-system code signature, so Windows SmartScreen and macOS Gatekeeper may still warn the first time; install says what to click.

On a connected host that pulls the image instead:

Terminal window
cosign verify \
--certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
ghcr.io/lukeponio/segaudit:X.Y.Z

The release notes give the image digest. After loading, compare it:

Terminal window
docker image inspect ghcr.io/lukeponio/segaudit:X.Y.Z --format '{{.Id}} {{.RepoDigests}}'

Each release includes an SPDX JSON software bill of materials per CPU type, published beside the bundles and attached to each CPU type’s image as a signed attestation:

Terminal window
cosign verify-attestation --type spdxjson \
--certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
ghcr.io/lukeponio/segaudit:X.Y.Z-amd64

Releases fail to build if the vulnerability scan finds a High or Critical issue.