Skip to content

lockrot 0.6.0

Choose a tag to compare

@github-actions github-actions released this 17 Sep 19:44
· 262 commits to main since this release

Added

  • self-update verifies the release signature. Every release from 0.6.0 on publishes lockrot.phar.sig next to the archive — an RSA signature (PKCS#1 v1.5 over SHA-384) by the new lockrot self-update key, in the {"sha384": "<base64>"} file format Composer uses for its own self-update — and the archive checks it with openssl_verify() against the public key built into itself before anything is written, after the sha256 check it already made. A release signed with a key the archive does not know, a signature over other bytes, or a signature file that is not one is reported and not installed. The key is RSA 4096, separate from the GPG release key (which still signs lockrot.phar.asc for people and PHIVE); its public half is lockrot-selfupdate-key.pub and SECURITY.md says how it is rotated. The archive running 0.5.0 still checks the checksum only when it updates to 0.6.0; releases before 0.6.0 carry no .sig, so a 0.6.0 archive cannot --force its way back to one.
  • The PHAR is built reproducibly. build/build-phar.sh on the tagged commit — with Box 4.7.0, which the script downloads and checks, and the Composer version the release workflow pins at that tag — produces the archive byte for byte, whatever the PHP version, so a release can be verified against its own source without trusting the builder. CI rebuilds every commit on a second machine, on another PHP version, and compares the bytes. The recipe is on the PHAR page.

Changed

  • The mutation-testing gate now covers the whole source tree instead of the verdict engine, the signals, the analyzer and the output formats alone. No behaviour changes: the escapes it surfaced were closed with sharper tests, and a handful of statements no test could observe were removed as redundant.
  • The PHAR's alias is lockrot.phar (Box used to generate a random one per build), and its installed.php names lockrot as dev-main with no commit reference. lockrot reads neither.

Verify this release

curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrot

Or rebuild it: check out v0.6.0, run build/build-phar.sh with Composer 2.10.3, and compare the sha256.

Full changelog: CHANGELOG.md.