Skip to content

v0.5.3

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:57
· 9 commits to main since this release

What changed

Take this one if you run Sentry. Stopping Sentry now hands the doors back
to this product at once, at every site, with nothing to re-pair.

Changed

  • A stopped Sentry hands the doors back at every site, with nothing to
    re-pair or edit.
    Sentry 1.6.16 reports when it is running but watching
    nothing, and that is meant to put this product's own Access ingest straight
    back in charge. At a site paired on an earlier Sentry, though, that report
    was refused until somebody approved it — and approving it from the Peer link
    page deliberately does not let it take anything back, so a stopped Sentry
    kept the doors, watched by nothing, until its silence window ran out.

    This release accepts Sentry's monitoring-stopped report on its own, at start
    and at pairing, and makes it hand Access back. It is safe to accept
    unreviewed for one reason: all it can ever do is make this product watch the
    doors itself. It cannot silence anything.

    The reply to a paired product's event now says whether raising it hands the
    capability back, so Sentry's log can say what will happen when it is stopped
    instead of guessing from how old its pairing is.

Verifying this release

Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.

Linux / macOS — cosign (keyless, no key to trust in advance):

cosign verify-blob notifymatrix-linux-amd64 \
  --bundle notifymatrix-linux-amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.

Build provenance (any platform):

gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix

Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:

Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe

This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com

Full Changelog: v0.5.2...v0.5.3