v0.6.0
See CHANGELOG.md for what changed. Requires Python 3.9 or newer.
Which file to carry
smtv.pyz— one file, for a machine with no package manager.
Needs only a Python:python3 smtv.pyz --examplegives a verdict
with no file of your own, no repository and no network.
On Windows that spelling ispy smtv.pyz --example— the
installer from python.org makespy.exeandpython.exe,
andpython3there opens the Microsoft Store instead.- the two
.whlfiles — for a machine that has pip but no index.
Put both in a directory and run
python3 -m pip install --no-index --find-links . aas-submodel-validate
(pip3works too, where that is the spelling). The
aas_core3_0-…wheel is the one dependency; without it that
command has nothing to resolve. Under 400 KB together. - the
.tar.gz— the source, for anyone building it themselves,
and the only asset carryingdocs/. Building it needs an
index of its own (setuptools), so it is not the offline
route — the two wheels above are. A finding'sperline
citesdocs/divergences.mdfor the reading it answers for;
that document is in here and in the repository, and not in
the wheel or the single file. Carry it too if you may have
to argue with a verdict offline. SHA256SUMS— the checksums for everything above.
Was it corrupted on the way? Run this where the files
landed — that is the only place the question means anything:
shasum -a 256 --ignore-missing -c SHA256SUMS
--ignore-missing because you were probably told to carry one
file, and without it shasum calls the ones you did not bring
failures and exits 1. (sha256sum -c where that is the
spelling.) Windows has neither; compare by eye against the
line in SHA256SUMS:
certutil -hashfile smtv.pyz SHA256
The commands below are written for a Unix shell. In cmd the
line continuation is ^ and in PowerShell it is a backtick;
the simplest thing is to put each command on one line.
Who built it? A checksum cannot answer that; the signature
can. It needs GitHub, so do it on a machine that can reach it:
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate
To check it on the far side instead, bring three things rather
than one — the file, its bundle, and the trust root — because
gh fetches that root over the network unless you hand it one:
gh attestation download smtv.pyz --repo dev365code/aas-submodel-validate
gh attestation trusted-root > trusted_root.jsonl
# carry smtv.pyz, the .jsonl bundle and trusted_root.jsonl
gh attestation verify smtv.pyz --repo dev365code/aas-submodel-validate \
--bundle sha256:<digest>.jsonl \
--custom-trusted-root trusted_root.jsonl
The bundle is named for the digest. A colon is not a filename
character on Windows, so gh writes sha256-<digest>.jsonl
there -- use the name it actually wrote.
The tool itself reaches no network, ever.