Verify before you install
Every artifact here is signed with GitHub build provenance — a Sigstore attestation binding the
file's digest to this repository, this workflow, and the commit that built it. There is no
maintainer key to fetch and no trust-on-first-use step.
gh attestation verify BTCPayServer.Plugins.Flint.btcpay --repo sethforprivacy/flintOffline, against the attestation.jsonl bundle attached below rather than GitHub's API:
gh attestation verify BTCPayServer.Plugins.Flint.btcpay \
--bundle attestation.jsonl --repo sethforprivacy/flintSHA256SUMS is attested too, so it can be trusted once verified. One quirk: BTCPay's PluginPacker
writes it with a single space between hash and filename. GNU sha256sum -c accepts that; macOS's
shasum -a 256 -c rejects the whole file, so on macOS compare shasum -a 256 <file> by eye.
Installing
Server settings → Plugins, find Flint in the plugin store (official listing), and install it. BTCPay restarts itself to finish.
Alternatively, Server settings → Plugins → Upload plugin, and select BTCPayServer.Plugins.Flint.btcpay. BTCPay restarts itself to finish. Both routes require BTCPay Server 2.4.1 or newer, on a non-Alpine host.
Read the CHANGELOG for what is in this release and how far it has actually been proven, and the trust model, before you put money through it.
What's Changed
- Warn non-admin tenants that the server operator holds their Spark seed by @sethforprivacy in #45
- Release 1.0.1 by @sethforprivacy in #46
Full Changelog: v1.0.0...v1.0.1