Repository navigation
brw v0.20.0
·
151 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Verifying this download
Every file attached below is listed in SHA256SUMS.txt and carries a GitHub build provenance attestation, which ties the file to this repository, this tag and the workflow run that produced it. Run this against anything you download from here:
gh attestation verify brw_0.20.0_macos_universal.pkg --repo Don-Works/brw
Substitute whichever file you downloaded. A checksum alone only proves the file matches this page; the attestation proves the file was built by this repository's release workflow from tag v0.20.0.
A CycloneDX SBOM of the Go dependency graph is attached as brw_0.20.0_sbom.cdx.json.
Installer signing
macOS (universal .pkg)
- Binaries: ad-hoc signed. The signature identifies no developer.
- Installer: unsigned. Gatekeeper reports an unidentified developer.
- Notarization: not performed.
Linux (amd64 .deb / .rpm)
- Packages: unsigned. There is no distribution GPG key, so
dpkg-sig/rpm --checksighave nothing to check. Use the checksums and the build provenance attestation instead.
Linux (arm64 .deb / .rpm)
- Packages: unsigned. There is no distribution GPG key, so
dpkg-sig/rpm --checksighave nothing to check. Use the checksums and the build provenance attestation instead.
Relocatable tarballs (.tar.gz)
- macOS binaries: ad-hoc signed, which is what lets Apple Silicon run them at all. No Developer ID is involved on this path;
scripts/install.shre-applies the same ad-hoc signature after unpacking. The.pkgabove is the signed macOS installer. - Linux binaries: unsigned, as on the
.deb/.rpmpath. - Every archive ships a matching
.sha256.install.shchecks it before unpacking and falls back toSHA256SUMS.txt, and the provenance attestation covers the archive itself.
What's Changed
- Verify browser interaction outcomes and reduce observation overhead by @revitteth in #48
Full Changelog: v0.19.0...v0.20.0