v0.46.0
·
10 commits
to develop
since this release
Installation and signature verification
Installation
By downloading binary from the release
For instance, if you are using Linux on an AMD64 architecture:
# Download the binary
curl -LO https://github.com/carvel-dev/vendir/releases/download/v0.46.0/vendir-linux-amd64
# Move the binary in to your PATH
mv vendir-linux-amd64 /usr/local/bin/vendir
# Make the binary executable
chmod +x /usr/local/bin/vendirVia Homebrew (macOS or Linux)
$ brew tap carvel-dev/carvel
$ brew install vendir
$ vendir version Verify checksums file signature
Install cosign on your system https://docs.sigstore.dev/system_config/installation/
The checksums file provided within the artifacts attached to this release is signed using Cosign with GitHub OIDC. To validate the signature of this file, run the following commands:
# Download the checksums file, certificate and signature
curl -LO https://github.com/carvel-dev/vendir/releases/download/v0.46.0/checksums.txt
curl -LO https://github.com/carvel-dev/vendir/releases/download/v0.46.0/checksums.txt.pem
curl -LO https://github.com/carvel-dev/vendir/releases/download/v0.46.0/checksums.txt.sig
# Verify the checksums file
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp=https://github.com/carvel-dev \
--certificate-oidc-issuer=https://token.actions.githubusercontent.comVerify binary integrity
To verify the integrity of the downloaded binary, you can utilize the checksums file after having validated its signature.
# Verify the binary using the checksums file
sha256sum -c checksums.txt --ignore-missingWhat's Changed
- Adds Bearer token authentication support to vendir sync (http) @husira #435
- adds support for symlink tar entry to extract as symlink @DocX #438
- Other dependency bump by @sameerforge @joaopapereira @CodesbyUnnati
Full Changelog: v0.45.4...v0.46.0
📂 Files Checksum
5b417c837b0134fabf2c4a322db054eacb8cfbe8d0e8cbbb86afc7e4f0d625fd ./vendir-darwin-amd64
781c0a9eafb86ddd88d078d29766f6afe5ec7b6b9a28efcb38c7a2424eb745f7 ./vendir-windows-amd64.exe
878f3c77cae21b9b63d0ea6c11454c0008d41652d2eb3d1844fdcf69cca6ae9e ./vendir-linux-amd64
e136160aa642231c6eb1df25cbe3e57e5f3848ac0a7e7de57bbc3249fdbd800f ./vendir-darwin-arm64
f80a27f1247ad4353b6054ca9d7e13e2511bf70c0e28d85bc314d2177ec2b0d2 ./vendir-linux-arm64