Verify a download
Releases are signed in CI by the release workflow with Sigstore keyless signing. There is no long-lived private key. Every signature is tied to this identity, where X.Y.Z is the release:
https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Zissued by https://token.actions.githubusercontent.com. Anything signed by another identity did not come from a SegAudit release.
Verify a bundle
Section titled “Verify a bundle”Run this on the connected machine where you downloaded the bundle, with Cosign installed. It needs no internet: trusted_root.json from the same release holds the Sigstore trust root.
sha256sum -c segaudit-X.Y.Z-linux-amd64.tar.gz.sha256
cosign verify-blob \ --trusted-root trusted_root.json \ --bundle segaudit-X.Y.Z-linux-amd64.tar.gz.sigstore.json \ --certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ segaudit-X.Y.Z-linux-amd64.tar.gzOn macOS use shasum -a 256 -c instead of sha256sum -c. segaudit-update runs the same checks on the jump host, the signature check only when Cosign is installed there.
To accept any release rather than one version, swap --certificate-identity for:
--certificate-identity-regexp '^https://github\.com/lukeponio/segaudit/\.github/workflows/release\.yml@refs/tags/v[0-9]+\.[0-9]+\.[0-9]+$'Verify a desktop installer
Section titled “Verify a desktop installer”Each installer has its own .sha256 and .sigstore.json, signed by the same identity. With trusted_root.json from the same release:
sha256sum -c SegAudit-Setup-X.Y.Z-windows-x64.exe.sha256
cosign verify-blob \ --trusted-root trusted_root.json \ --bundle SegAudit-Setup-X.Y.Z-windows-x64.exe.sigstore.json \ --certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ SegAudit-Setup-X.Y.Z-windows-x64.exeSwap in the .dmg, .deb or .rpm name for the other installers. On Windows without sha256sum, compare the file’s hash from Get-FileHash SegAudit-Setup-X.Y.Z-windows-x64.exe with the one in the .sha256 file. The Sigstore signature is not an operating-system code signature, so Windows SmartScreen and macOS Gatekeeper may still warn the first time; install says what to click.
Verify the container image
Section titled “Verify the container image”On a connected host that pulls the image instead:
cosign verify \ --certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ ghcr.io/lukeponio/segaudit:X.Y.ZThe release notes give the image digest. After loading, compare it:
docker image inspect ghcr.io/lukeponio/segaudit:X.Y.Z --format '{{.Id}} {{.RepoDigests}}'Review the SBOM
Section titled “Review the SBOM”Each release includes an SPDX JSON software bill of materials per CPU type, published beside the bundles and attached to each CPU type’s image as a signed attestation:
cosign verify-attestation --type spdxjson \ --certificate-identity https://github.com/lukeponio/segaudit/.github/workflows/release.yml@refs/tags/vX.Y.Z \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ ghcr.io/lukeponio/segaudit:X.Y.Z-amd64Releases fail to build if the vulnerability scan finds a High or Critical issue.