Skip to content

v4.2.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 19:06
· 3 commits to main since this release
v4.2.0
f3881ad

Verifying the Release Signature

After downloading the v4.2.0 release of Spin, either via the artifact attached to this release corresponding to your OS/architecture combination or via the installation method of your choice, you are ready to verify the release signature.

First, install cosign. This is the tool we'll use to perform signature verification. Then, from the directory containing the extracted release archive (spin, spin.sig and crt.pem), run the following command:

cosign verify-blob \
    --signature spin.sig --certificate crt.pem \
    --certificate-identity https://github.com/spinframework/spin/.github/workflows/release.yml@refs/tags/v4.2.0 \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com \
    --certificate-github-workflow-sha f3881ad20072ddaae1b377b4ca13d499eb3ccf83 \
    --certificate-github-workflow-repository spinframework/spin \
    spin

If the verification passed, you should see:

Verified OK

What's Changed

New Contributors

Full Changelog: v4.1.0...v4.2.0