Step SDS v0.2.2-rc14 (${RELEASE_DATE})
Pre-release
Pre-release
Signatures and Checksums
step-sds
uses sigstore/cosign for signing and verifying release artifacts.
Below is an example using cosign
to verify a release artifact:
cosign verify-blob \
--certificate ~/Downloads/step-sds_darwin_0.2.2-rc14_amd64.tar.gz.pem \
--signature ~/Downloads/step-sds_darwin_0.2.2-rc14_amd64.tar.gz.sig \
~/Downloads/step-sds_darwin_0.2.2-rc14_amd64.tar.gz
The checksums.txt
file (in the 'Assets' section below) contains a checksum for every artifact in the release.
Changelog
- 62bae90 [action] cosign by container image name (not by tag)
Thanks!
Those were the changes on v0.2.2-rc14!
Come join us on Discord to ask questions, chat about PKI, or get a sneak peak at the freshest PKI memes.