Skip to content

Publish checksums.txt for GitHub release archives #141

Description

@randlee

atm-core's pinned bootstrap contract now verifies each downloaded Wyvern
archive against the SHA-256 values recorded in tools/bootstrap.toml.

Please publish a checksums.txt asset with every GitHub release, including
v0.5.0, so consumers can perform the optional release-side cross-check. The
atm-core implementation is in tools/bootstrap.py; it treats the pinned
SHA-256 as the trust anchor, and when checksums.txt is present it hard-fails
if the release listing disagrees. When the file is absent it warns and
continues after the pinned archive hash passes.

Expected v0.5.0 assets include:

wyvern-linux.tar.gz
wyvern-macos-aarch64.tar.gz
wyvern-macos-x86_64.tar.gz
wyvern-windows.zip

Publishing the manifest will make the cross-check useful without making a
missing release asset an outage for existing consumers.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions