Changelog
- 2dc640229d26bd5a26cebbf663d443a96a82eb74 fix: take version from the release tag and sign releases with cosign (#2)
Verifying this download
Check the archive against the checksums file, then confirm that file came
from StackGuardian's release pipeline rather than from whoever served it
to you:
cosign verify-blob sg-cli_2.2.1_checksums.txt \
--certificate sg-cli_2.2.1_checksums.txt.pem \
--signature sg-cli_2.2.1_checksums.txt.sig \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https://github.com/StackGuardian/sg-cli-v2/\.github/workflows/release\.yml@refs/tags/'The signing is keyless, so the certificate names the workflow and tag that
built the release rather than a key someone has to keep.