atm-core's pinned bootstrap contract now verifies each downloaded Wyvern
archive against the SHA-256 values recorded in tools/bootstrap.toml.
Please publish a checksums.txt asset with every GitHub release, including
v0.5.0, so consumers can perform the optional release-side cross-check. The
atm-core implementation is in tools/bootstrap.py; it treats the pinned
SHA-256 as the trust anchor, and when checksums.txt is present it hard-fails
if the release listing disagrees. When the file is absent it warns and
continues after the pinned archive hash passes.
Expected v0.5.0 assets include:
wyvern-linux.tar.gz
wyvern-macos-aarch64.tar.gz
wyvern-macos-x86_64.tar.gz
wyvern-windows.zip
Publishing the manifest will make the cross-check useful without making a
missing release asset an outage for existing consumers.
atm-core's pinned bootstrap contract now verifies each downloaded Wyvern
archive against the SHA-256 values recorded in
tools/bootstrap.toml.Please publish a
checksums.txtasset with every GitHub release, includingv0.5.0, so consumers can perform the optional release-side cross-check. The
atm-core implementation is in
tools/bootstrap.py; it treats the pinnedSHA-256 as the trust anchor, and when
checksums.txtis present it hard-failsif the release listing disagrees. When the file is absent it warns and
continues after the pinned archive hash passes.
Expected v0.5.0 assets include:
Publishing the manifest will make the cross-check useful without making a
missing release asset an outage for existing consumers.