lockrot 0.6.0
Added
self-updateverifies the release signature. Every release from 0.6.0 on publisheslockrot.phar.signext to the archive — an RSA signature (PKCS#1 v1.5 over SHA-384) by the new lockrot self-update key, in the{"sha384": "<base64>"}file format Composer uses for its own self-update — and the archive checks it withopenssl_verify()against the public key built into itself before anything is written, after the sha256 check it already made. A release signed with a key the archive does not know, a signature over other bytes, or a signature file that is not one is reported and not installed. The key is RSA 4096, separate from the GPG release key (which still signslockrot.phar.ascfor people and PHIVE); its public half islockrot-selfupdate-key.puband SECURITY.md says how it is rotated. The archive running 0.5.0 still checks the checksum only when it updates to 0.6.0; releases before 0.6.0 carry no.sig, so a 0.6.0 archive cannot--forceits way back to one.- The PHAR is built reproducibly.
build/build-phar.shon the tagged commit — with Box 4.7.0, which the script downloads and checks, and the Composer version the release workflow pins at that tag — produces the archive byte for byte, whatever the PHP version, so a release can be verified against its own source without trusting the builder. CI rebuilds every commit on a second machine, on another PHP version, and compares the bytes. The recipe is on the PHAR page.
Changed
- The mutation-testing gate now covers the whole source tree instead of the verdict engine, the signals, the analyzer and the output formats alone. No behaviour changes: the escapes it surfaced were closed with sharper tests, and a handful of statements no test could observe were removed as redundant.
- The PHAR's alias is
lockrot.phar(Box used to generate a random one per build), and itsinstalled.phpnames lockrot asdev-mainwith no commit reference. lockrot reads neither.
Verify this release
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.0/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrotOr rebuild it: check out v0.6.0, run build/build-phar.sh with Composer 2.10.3, and compare the sha256.
Full changelog: CHANGELOG.md.