Skip to content

ghr 0.7.0

Latest

Choose a tag to compare

@github-actions github-actions released this 27 Jul 22:30
742def1

A toolkit for GitHub releases.

Highlights

  • GitHub artifact attestations: ghr download and ghr install now verify GitHub-native build provenance, checking the attestation's Sigstore trust chain, Rekor inclusion proof, and workflow identity, then reporting the source repository and workflow. (#166, #168, #169, #170)
  • Signatures no longer expire: Authenticode certificates are now validated at the time of signing rather than against the wall clock. Previously a correctly signed binary became unverifiable once the timestamp authority's own certificate expired — ghr download git-lfs/git-lfs/git-lfs-windows-v3.7.1.exe failed with CertificateExpired. The trust root set is no longer clock-filtered either. (#175, fixes #172)
  • Correct signer attribution: Authenticode and Sigstore chain verification reported the last certificate walked instead of the leaf, so a GitHub-signed binary was credited to Microsoft ID Verified Code Signing PCA 2021. (#174)
  • Hardened DER parsing: Every DER structure parsed from untrusted input — X.509 certificates, PKCS#7 SignedData, RFC 3161 tokens — is now fully bounds-checked, so a truncated or hostile encoding is reported as an ordinary verification failure rather than crashing. (#171, fixes #167)
  • Full changelog: v0.6.9...v0.7.0

Install:

pipx install ghr-bin==0.7.0
uv tool install ghr-bin==0.7.0
winget install ghr --version 0.7.0
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | GHR_VERSION=v0.7.0 sh
$env:GHR_VERSION = 'v0.7.0'; iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr@v0.7.0 RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0