lockrot 0.6.1
Fixed
phive install somework/lockrotworks again. PHIVE takes any release asset ending in.ascor.sigfor the GPG signature of the PHAR (last one wins), and 0.6.0's self-update signature was published aslockrot.phar.sig— so PHIVE tried to verify the archive with a JSON document and failed. The asset islockrot.phar.sig.jsonfrom this release on, and was renamed on the 0.6.0 release as well.- A 0.6.0 archive cannot
self-update. It looks for the old asset name, which no later release carries: it reportsrelease v0.6.1 has no lockrot.phar.sig assetand leaves itself in place. Download this release by hand or runphive update. Every other build, 0.5.0 included, updates as before — and from 0.6.1 on,self-updateverifies the release signature with the key built into the archive.
Verify this release
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.6.1/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrotOr rebuild it: check out v0.6.1, run build/build-phar.sh with Composer 2.10.3, and compare the sha256 — see the PHAR page.
Full changelog: CHANGELOG.md.