Skip to content

lockrot 0.6.1

Choose a tag to compare

@github-actions github-actions released this 17 Sep 20:15
· 261 commits to main since this release

Fixed

  • phive install somework/lockrot works again. PHIVE takes any release asset ending in .asc or .sig for the GPG signature of the PHAR (last one wins), and 0.6.0's self-update signature was published as lockrot.phar.sig — so PHIVE tried to verify the archive with a JSON document and failed. The asset is lockrot.phar.sig.json from this release on, and was renamed on the 0.6.0 release as well.
  • A 0.6.0 archive cannot self-update. It looks for the old asset name, which no later release carries: it reports release v0.6.1 has no lockrot.phar.sig asset and leaves itself in place. Download this release by hand or run phive update. Every other build, 0.5.0 included, updates as before — and from 0.6.1 on, self-update verifies the release signature with the key built into the archive.

Verify this release

curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrot

Or rebuild it: check out v0.6.1, run build/build-phar.sh with Composer 2.10.3, and compare the sha256 — see the PHAR page.

Full changelog: CHANGELOG.md.