Changelog
Verify
Important
It is strongly recommended to verify the integrity and security of the release assets before executing them. This helps mitigate potential risks associated with running unverified files.
First, verify the file using checksums.
sha256sum --check --ignore-missing unch_v1.0.1-checksums.txtThen, ensure the authenticity of the release asset with Cosign:
cosign verify-blob --key release-unch_v1.0.1.pub --signature unch_v1.0.1-OS_ARCH.sig unch_v1.0.1-OS_ARCH