Skip to content

1.0.0-beta3

Pre-release
Pre-release

Choose a tag to compare

@sgammon sgammon released this 26 Nov 05:05
· 11 commits to main since this release
1.0.0-beta3
bb185f0

Summary

Release #3 of the Buildless CLI, which extends the new Local Agent functionality to Linux and adds a new Pkgst proxy. Please see the CLI documentation for more info.

Warning

This version has known issues. Instead, please use 1.0.0-beta5 or later.

Verification

Use the following parameters to verify this release using Sigstore.

Parameter Value Description
certificate-oidc-issuer https://accounts.google.com Verifies the releaser's account
certificate-identity sam@elide.ventures Issuer for this release (a Google account)

New features

  • Local Agent: Early support for Linux
  • Pkgst Proxy: Local proxy for Pkgst traffic
  • Secure Releases: Support for binary-embedded SBOM, provenance, and Sigstore signing

Installation

One-liner (install and verify):

  • macOS:
echo "Installing Buildless..." \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.darwin-arm64.tgz \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.darwin-arm64.tgz.sha256 \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.darwin-arm64.sigstore.json \
  && tar -xzvf buildless.darwin-arm64.tgz \
  && cat buildless.darwin-arm64.tgz.sha256 | gsha256sum --check --status \
  &&  cosign verify-blob \
    --certificate-oidc-issuer https://accounts.google.com \
    --certificate-identity sam@elide.ventures \
    --bundle ./buildless.darwin-arm64.sigstore.json \
    buildless \
  && mkdir ~/bin \
  && cp -fv buildless ~/bin \
  && export PATH="$PATH:~/bin" \
  && rm -f buildless "buildless.darwin-arm64.*" \
  && buildless --version \
  || $(echo "Failed to verify Buildless binary; deleting." && rm -fv buildless)

# Prints: "Verified OK", with `buildless` binary extracted and installed to `~/bin`
  • Linux:
echo "Installing Buildless..." \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.linux-amd64.tgz \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.linux-amd64.tgz.sha256 \
  && wget -q https://github.com/buildless/cli/releases/download/1.0.0-beta3/buildless.linux-amd64.sigstore.json \
  && tar -xzvf buildless.linux-amd64.tgz \
  && cat buildless.linux-amd64.tgz.sha256 | gsha256sum --check --status \
  &&  cosign verify-blob \
    --certificate-oidc-issuer https://accounts.google.com \
    --certificate-identity sam@elide.ventures \
    --bundle ./buildless.linux-arm64.sigstore.json \
    buildless \
  && mkdir ~/bin \
  && cp -fv buildless ~/bin \
  && export PATH="$PATH:~/bin" \
  && rm -fv buildless "buildless.linux-amd64.*" \
  || $(echo "Failed to verify Buildless binary; deleting." && rm -fv buildless)

# Prints: "Verified OK", with `buildless` binary extracted and installed to `~/bin`

Verifying a release

To verify this release, download the binary for your platform and architecture, and the accompanying sha256 and sigstore.json files. For example, on macOS ARM64 (M1-M3), you would download all of:

  • buildless.darwin-arm64.tgz
  • buildless.darwin-arm64.tgz.sha256
  • buildless.darwin-arm64.sigstore.json

Extract the binary:

tar -xzvf buildless.darwin-arm64.tgz

To verify the SHA256 hash:

cat buildless.darwin-arm64.tgz.sha256 | gsha256sum --check --status

This command returns 0 (success) if the checksum matches.

To verify the Sigstore signature:

cosign verify-blob \
  --certificate-oidc-issuer https://accounts.google.com \
  --certificate-identity sam@elide.ventures \
  --bundle ./buildless.darwin-arm64.sigstore.json \
  buildless

# Prints: "Verified OK"

See the table at the top of this release for explanations of each parameter.

All verification steps:

tar -xzvf buildless.darwin-arm64.tgz \
  && cat buildless.darwin-arm64.tgz.sha256 | gsha256sum --check --status \
  &&  cosign verify-blob \
  --certificate-oidc-issuer https://accounts.google.com \
  --certificate-identity sam@elide.ventures \
  --bundle ./buildless.darwin-arm64.sigstore.json \
  buildless || $(echo "Failed to verify Buildless binary; deleting." && rm -fv buildless)

# Prints: "Verified OK", with `buildless` binary extracted

Platform support

Currently available for:

  • macOS M1, M2, M3 (darwin-arm64)
  • Linux X86-64 (linux-amd64)