CodeTruss CLI v0.2.44
·
4 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
- The person you hand a receipt to can now check it. Until this release a
receipt could only be verified by the repository that produced it:codetruss verifymeasures a receipt against the signing keys the local.codetruss.yml
pins, so the client, auditor, or acquirer the evidence was written for got
receipt signer <fp> does not match trusted key <fp>and stopped there. That
is most of the point of handing someone a receipt, and it did not work. The
gap was concrete rather than theoretical: publishing one of our own receipts
publicly required shipping a bespoke standalone verifier alongside it, because
the CLI would not check another install's receipt.codetruss verify-receipt <receipt.json|dir>is the supported path. It needs nothing but the files —
no checkout, no account, no configuration — and it reports two claims
separately, because they are two different facts and merging them would be a
lie. Integrity is that these bytes have not changed since they were
signed; it is established from the receipt alone, by checking the signature
under the key the receipt carries, reproducing the Markdown byte-for-byte from
the signed JSON, and matching the recorded digests. Provenance is that a
party you trust signed them, and it is established only against a
--public-keyyou obtained from that party some other way. A receipt vouching
for its own key proves nothing about who wrote it — forging one takes a
keypair and a minute — so a run without a supplied key can never print a
verified result or exit 0. That ceiling is the feature, not a missing half of
one. The exit codes carry the distinction into scripts: 0 for both claims, 1
for bytes that are intact but unattributed, 2 for bytes that are not what was
signed. When integrity fails, provenance is not evaluated at all and says so,
rather than printing a key match over altered bytes. Evidence a publisher
withheld — usually the patch, the only part of a receipt that quotes source —
is reported as unchecked next to the digest the signature does cover, and the
integrity line names the hole instead of reading clean.codetruss verifyis
unchanged and still requires a trusted key; its refusal now names the command
that can check a foreign receipt instead of dead-ending. Both paths run one
shared check list against one shared set of accepted Markdown renderings, so
neither can drift into checking less than it claims, and every superseded
profile wording stays reproducible, so receipts signed by older releases keep
verifying byte-for-byte.
Install
curl -fsSL https://codetruss.com/install.sh | shWindows (PowerShell):
irm https://codetruss.com/install.ps1 | iexVerify what you installed
sha256 8a405b77b2042c8daca6f2def782fa8e38a2ffcec4ebe9643631d3491af50884
gh attestation verify codetruss-cli-0.2.44.tgz --repo CodeTruss/codetruss-cliThe archive ships with a CycloneDX SBOM and SLSA build provenance. You
should not have to take our word for what is in it.