Repository navigation
0.8.18
Release Notes
Security — cross-role signature-verify fix. Upgrade recommended.
- Fixed a cross-role false-
Verifiedin signature checking (C1). The%G?verify cache was keyed
by commit SHA alone, but a commit's signature status is evaluated against a one-key allowed-signers
file that is specific to each role's pinned key. So a good-signature verdict proven for role A's pin
could be reused for role B on a commit that touched both — meaning a hub writer with their own valid
pinned key could bundle a message (or card edit) attributed to another role into a single signed
commit and have it shown as Verified under that role. The cache now keys on(sha, role, pinned)
— the full input to the check — so each(commit, role-pin)is verified independently. Found by a
post-multi-harness security review; regression test included. No config or workflow change.
Install confer-cli 0.8.18
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codeshrew/confer/releases/download/v0.8.18/confer-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install codeshrew/tap/conferDownload confer-cli 0.8.18
| File | Platform | Checksum |
|---|---|---|
| confer-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| confer-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| confer-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| confer-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |