ZenNotes CLI 0.6.2
From this release on, every ZenNotes CLI release carries a signed manifest, and ZenNotes desktop uses it to keep the zn it manages up to date. CLI fixes no longer wait for a desktop release.
Signed release manifest
Each release now includes two more files:
terminal-release.json: the version, the desktop integration protocol, the source commit, and the SHA-256 of each macOS and Linux archive. It uses the same format as the CLI pin inside ZenNotes desktop.terminal-release.json.sig: an Ed25519 signature over those exact bytes, by keyzn-release-1. The public key is inpackaging/release-signing/zn-release-1.pub.
The release workflow builds the manifest from the release archives, signs it, and checks it against the committed public key before uploading, so a release can't ship a manifest the desktop would reject. To check a release by hand:
go run ./scripts/releasemanifest verify -manifest terminal-release.json -sig terminal-release.json.sig -public-key-file packaging/release-signing/zn-release-1.pubDesktop-managed installations
ZenNotes desktop 2.60.0 and later check the latest release once a day for a zn installed from Settings > CLI. They install it only when the signature, the archive checksum and the new binary's integration check all pass, and they keep the previous version on disk. On those installations zn update now points at Settings > CLI > Check for updates instead of telling you to update the desktop app. zn update --check still reports the latest release.
Upgrade
zn updateStandalone macOS and Linux installations update in place and keep zn.previous as a backup. Homebrew users run brew update && brew upgrade zn. With Go:
go install github.com/ZenNotes/tui/cmd/zn@v0.6.2Or download an archive below. Desktops from ZenNotes 2.60.0 on pick this release up by themselves within a day; earlier desktop releases keep the CLI they bundle.
Verification
The release workflow ran the Go tests, built the archives with GoReleaser, then built, signed and checked this release's manifest against the committed public key before uploading it (run 36882848479). Checked again after publishing:
- The signature verifies with the committed public key and with the key built into ZenNotes desktop.
- The manifest names 0.6.2, protocol 1 and commit
140a38f, and all four macOS and Linux archives match it,checksums.txtand their downloaded bytes. zn --versionreports v0.6.2 and the integration check answers protocol 1, version 0.6.2. On a desktop-managed path,zn updatepoints at Settings > CLI > Check for updates.- A ZenNotes desktop development build that bundles 0.6.0, with no test overrides, found this release on GitHub, verified it with its built-in key and updated itself to 0.6.2.
- The Homebrew formula in
zennotes/tappoints at 0.6.2;brew stylereports no offenses.