Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 22:54
· 42 commits to main since this release
bf995a3

Status Update: 29 September 2026

Developer preview. Do not use with real signing keys or treat the review as a safety guarantee.

The assets attached here are still v0.1.0. Later parser, acknowledgement and browser-interface fixes on main are not included in these downloads. See the current changelog and verification status before testing.

This version is superseded by v0.1.1. The original network claim was too broad: desktop Safe-service fetch contacts the network, and this version also fetched a webfont on startup. The decoder itself does not open sockets.

Only the canonical aarch64 Linux binary has the documented reproducibility comparison. Compilation uses a local registry cache; the container bootstrap still downloads dependencies. Desktop installers are unsigned. No assets or tags were replaced by this note update.

Original release notes (superseded claims corrected above)

A tool for reading a Safe transaction before you approve it. It holds no
keys, signs nothing, and never touches a network.

Start with README.md in the archive, or
docs/06-using-it-before-you-sign.md in the repository.

clearsign safe-json tx.json --chain-id 1

What is checked, and what is not. This has had one external security
review: ten findings, all fixed. The fixes have not been reviewed by
anyone outside the project. docs/03-verification-status.md lists what
is proven and what is not, including the gaps.

Reproducibility. The aarch64-unknown-linux-musl build is the one
you can check, and it is built here the same way you would rebuild it:
in the canonical container, offline, with build paths remapped out.
Rebuild it with signing-core/scripts/reproducible-cross-check.sh and
compare against signing-core/EXPECTED-HASHES.txt.

Compare the binary, not the archive. BINARY-SHA256 attached here
is the binary's hash; SHA256SUMS covers the archives, which include a
README and the licences and so hash differently.

The macOS and x86_64 builds are produced by GitHub's runners and are
not reproducible in that sense — rustc does not promise identical
output across compiler hosts, and this project would rather say so than
imply otherwise.

The application is not signed yet. macOS and Windows will warn that
it comes from an unidentified developer, because it does: signing
certificates are a paid registration this project has not taken out.
Until then the honest check is the hash, not the badge.

Not for real keys. The signing and seed commands stay behind a
development guard. Anything typed into an everyday computer should be
treated as exposed.