Skip to content

Releases: dev365code/aas-submodel-validate

v0.9.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 02:22

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.9.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 08:49

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 06:33

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.8.3

Choose a tag to compare

@github-actions github-actions released this 25 Sep 03:48

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.8.2

Choose a tag to compare

@github-actions github-actions released this 25 Sep 02:32

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.8.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 23:25

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 20:25

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 18:35

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 16:10

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 18:53

See CHANGELOG.md for what changed. Requires Python 3.9 or newer.

Which file to carry

  • smtv.pyz — one file, for a machine with no package manager.
    Needs only a Python: python3 smtv.pyz --example gives a verdict
    with no file of your own, no repository and no network.
    On Windows that spelling is py smtv.pyz --example — the
    installer from python.org makes py.exe and python.exe,
    and python3 there opens the Microsoft Store instead.
  • the two .whl files — for a machine that has pip but no index.
    Put both in a directory and run
    python3 -m pip install --no-index --find-links . aas-submodel-validate
    (pip3 works too, where that is the spelling). The
    aas_core3_0-… wheel is the one dependency; without it that
    command has nothing to resolve. Under 400 KB together.
  • the .tar.gz — the source, for anyone building it themselves,
    and the only asset carrying docs/. Building it needs an
    index of its own (setuptools), so it is not the offline
    route — the two wheels above are. A finding's per line
    cites docs/divergences.md for the reading it answers for;
    that document is in here and in the repository, and not in
    the wheel or the single file. Carry it too if you may have
    to argue with a verdict offline.
  • SHA256SUMS — the checksums for everything above.

Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:

shasum -a 256 --ignore-missing -c SHA256SUMS

--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:

certutil -hashfile smtv.pyz SHA256

The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.

Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:

gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate

To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:

gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
  --bundle sha256:<digest>.jsonl \
  --custom-trusted-root trusted_root.jsonl

The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.

The tool itself reaches no network, ever.