Releases: dev365code/aas-submodel-validate
Release list
v0.9.2
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.9.1
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.9.0
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.8.3
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.8.2
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.8.1
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.8.0
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.7.1
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.7.0
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.
v0.6.0
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.