-
Notifications
You must be signed in to change notification settings - Fork 61
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add all necessary components for gpg signed release manifests
- Loading branch information
Showing
4 changed files
with
100 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
# Verify Releases | ||
|
||
To verify the release, you can check @wbobeirne's signature against the sha256 manifest file. First import the public key: | ||
|
||
```sh | ||
curl https://raw.githubusercontent.com/joule-labs/joule-extension/master/keys/wbobeirne.asc | gpg --import | ||
``` | ||
|
||
Download the manifest and sig file and verify it: | ||
|
||
```sh | ||
gpg --verify manifest-[version].wbobeirne.sig manifest-[version].txt | ||
``` | ||
|
||
Now that we have a verified manifest, we'll verify the contents of the zip file. Download and unzip the zip file, and run `sha256sum -c` against the manifest. | ||
|
||
```sh | ||
cd joule-[version] | ||
sha256sum -c ../manifest-[version].txt --ignore-missing | ||
``` | ||
|
||
You should see a series of files and `OK` next to them if the hashes match. | ||
|
||
## Build & verify with docker | ||
|
||
You can also build your own release and manifest with `yarn build:docker`, then verify the sha256sums using the `manifest.txt` file in `docker-dist/manifest.txt` |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,52 @@ | ||
-----BEGIN PGP PUBLIC KEY BLOCK----- | ||
|
||
mQINBGDKfggBEAD0IR5BO+BOhHFRE+OKOrvkXH9qlbXC1id69A0L9XpcCqJtULvQ | ||
tAI7rV/uQQvt/ijGsJuImmq9B6LfWO2ngbz0IFwEcSwBPfbfrFqONRH5xYIsimFa | ||
N81ngeXlZjE5XleuJKtw8WsYrh1H/nyIPTIL7mOTS5jjjBfIXoE/o06Iw0KV2L7v | ||
yY16BfNZGrcEp5ar578O8E6dZRMYMOVd0UMP1ClP/zfszA0pVzJs9FuyxBQlEYFv | ||
VQR0AeSmsywH2guMq2pK6jZI8aOShmoIIYgfPgnX89KvvwZyiW3mexf2+2fqoQOS | ||
TAswXFkAEfsGEtZIgxvvNCrFBUR0BUBNX0xeeRrWfiUG+dveBiZ3HVQP3DLWldQ0 | ||
Iy8yH5CLDvz5rKELeuVt886JuvPXgVQpcQbetc103Fz3sGV9WXlRxF6L5hoaD6jU | ||
4iMxVgARSOWgDQRIw4cLA6Ya9/qGKSu4yQVjjdWiK28knYF9LexJ4MOVE3Q7vlBV | ||
sZGaOdUAO4tzNAOidBbG8EvrLiwxJm5aCeadTV6gYhH5MVUlY8Uiyk+Lew9QO3mx | ||
ZweBt6J+EnZHlOQeXywn0jrzRHfE6WmvWHVEk3LV2D0w0ndKjwjGgZlWzP76o0+M | ||
ALMty6/8//Ux0ThnYwzSufoEn6bbERNBjJtKiFsDn5scfFsI/1X+SfJhUQARAQAB | ||
tCZXaWxsaWFtIE8nQmVpcm5lIDx3Ym9iZWlybmVAZ21haWwuY29tPokCVAQTAQgA | ||
PhYhBNTM8MujyQc4lh4V8tHy40EDR8YtBQJgyn4IAhsDBQkHhh9nBQsJCAcCBhUK | ||
CQgLAgQWAgMBAh4BAheAAAoJENHy40EDR8Yt+vcQAMxsGxUVEuoJsW8wNvufeVK7 | ||
2wbdOpjqQfpkfVSZZDiY4mNECOm3BZVdu1rOuhxK1IwNhqRSXe+pa7rde8wk6DpO | ||
8pYTz+qL21ngTEgtwBNX3JV07V4TjtQJ+GcQ1FEw5fCi2uK46RPSaC1pzOk6Tjyc | ||
P7E5BUvzGl21AcEHStURkUaLFPYN2kSCiZQk66LQQenuYGQuzej1KheVVlhYAqGk | ||
IXhH+4cMbggNZXAJBV4t/yUF4fLkeaGBhKRNyqpkvWBAs/njyTvVsTk9J7bCvvMf | ||
ElZpxZAGBO/Jw3FrsOSsoJehQkv0+OBQNNK+lbmziw67ICXCCV01yAWTMO45wvvN | ||
fabli33Ja0wXz1WAunWWNl1GkGyNiJf0bcT4N3JoF3uxyil0TvgFPrqFW0uR4Ek2 | ||
2GbFKc9yHVCe6U3mXALnKdpDsSzof80JhSDXTPut2qFNRaEQXAF4NUQ9rUMSCGAf | ||
bpqdMrUiRlIzrTkJ8Nk+s/Mro3KTbTwYlvPv0j+G1GVN8yzRvMGzPQdpKikyiT9M | ||
EsxX27u4q62NB0cFuVXHPDwvClQtUhsUJ3UeW7JRwsaEfC5JlsP85x+5B0nfMK5e | ||
NYg1w+BE+sGqfapeKoF5Fzq4KxrZtmrcm8fMVa5SUu9+V41I1yGqJlF+CicXtxX4 | ||
aA6yPKqpWN3im1OBuWSMuQINBGDKfggBEADI3guxFanGOkbdJ5ueeRQQ5mhCCHay | ||
DBvq01FjbLnNpdE0tbGq/xHGXJLTOdeNwpioPf+fK8GAy3DUKFkExJvR1eR3MPOR | ||
rYHEK7PK4IHhq/U6XyI09KsOZ4SwcnIyLQ/VqJGaLA6uu/K7CC73/UWcgGY+teVL | ||
T1l225w7IRnFOWJhPugzioUEW0c/loCJeaHKVdQFqc1vAGBiQ6PlWzQdRJ1PoJ9S | ||
0WJMSIr/Y4cBweHA1bEzKiuQbsAontaqMUwPaWBv96ZrX8epqxtjUFEofxrcbXXV | ||
e6Hd7xAVZhzaUtODvEZeMmMOqtHZsvXgNfIti8xwgLBdjeb/JWoxiqy21qeeZuco | ||
HUs8e66Gh04VKuQaOv6kbv7D/Miwv+xtM++gXealQFhbtS5iGdLYZHF+vaUKmMFO | ||
SAdfMuv9LfWIV0yNlWIOD2aatlagBB8gST+/B5b6+tm9BLiAkWvXUc/ThtRvWm1P | ||
78PwPqkNGW0RDr3bFOVm83skc4fxRsAbWIYS029m9h9EkAlNdKqxmMSHcdUN/mTG | ||
OQA77xiLgZFRnFp3wDatsYgkmTwiIcK2FRl+PUrfsoMlmNb2NE54NVpPtfoKk+N/ | ||
lGthXZZTlc4A8e987Y3LlVON8w2oBdtrhpbf/2mDMMx9Ayqk19T2sdsKOBYNgGjl | ||
0LAwSz9htsRHPQARAQABiQI8BBgBCAAmFiEE1Mzwy6PJBziWHhXy0fLjQQNHxi0F | ||
AmDKfggCGwwFCQeGH2cACgkQ0fLjQQNHxi1/bQ//ShBoTDlz7o8HRRTBUks3d0eT | ||
E9hVtGuybnw8zfUjMF8un76d3Etk5R6oJRiLVJKEiYYLVxuJXCujjLgEGH4YxcKC | ||
zTmFi9CavQQAeqWP0pAG73Wq50OopLO9aAJ8XCLUPmMRPnrWXvlOg3aYK0ErIi4r | ||
EBa84RSv57crhdBUS7CmPDMASryRA+MeOcTxVHFdon/wWDHun+qJ+p5Qd8wFCmTU | ||
2L8fDChmuZloZaCQhqai5YdsxrC9ljBo9pGyCJq/XbNt44FkvSsiEtCkOsx2H1Dq | ||
cqlgjWvDw//yoxZzoe8+1QWjYDQSjcYYBqrJBbZmiDHRhkrDeIMJZZAKIHHRdCtw | ||
oDxQxVTdFt6NzmKyQ7qTpDFJ7/JPGmkrlx8xNgW+JZMecoeEDhZDKDvDig+q17bJ | ||
MJhYBzFn7rzBEBbsix9J6csiJn2NTW7isU4OkXi0a+LdxJM/KWIbhy498a2HoOPC | ||
crXR+kxwZ9t7QCfPr2ZzOFixF7y5LwbqDNq+oZFuI7gYe/YtbhT2I6WGetmn4yB0 | ||
9tQnX7n5XfdEFQUBA3xq7PK1/w2GQTzFWcx/0vBw2l29/KW3zOvwsYNW7eWvM/M+ | ||
T7FPp9RdG4qV+OaMXMaWL6XVHIj+hLGnBjxnpGm6eSzUdz37sOzKkPu40SVne+qI | ||
X0bW0MQSJnLwwDDixUg= | ||
=Yo5s | ||
-----END PGP PUBLIC KEY BLOCK----- |