Skip to content

Indigo 0.8.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 20:21

What has and has not been run, plainly: everything here passes the host tests
(3983 checks under AddressSanitizer and UBSan) and builds and links for the 3DS
in CI against Wolfram v0.28.0. The signature check has not been run on an
emulator or a real 3DS. This is the first release whose update.json is signed,
so an Indigo that predates the check still takes releases on the SHA-256 alone.

Changed

  • Indigo now builds against Wolfram v0.28.0 (was v0.27.0). (#46)

Added

  • Updates are signed. Each release's update.json gets a detached Ed25519 signature, update.json.sig, made by the Release workflow with a key that exists only as a repository secret. Indigo checks it against the public key built in before it reads the manifest, and refuses a release that has no signature or the wrong one, so a replaced release no longer passes on its SHA-256 alone. Wolfram's wf_update_verify_signature does the check. Releases up to 0.7.0 are unsigned. None of it has run on an emulator or a console (#24).