Skip to content

Releases: teddytennant/wizard

v3.7.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 02:33

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.7.1/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.7.0...v3.7.1

v3.7.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 23:49

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.7.0/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.6.1...v3.7.0

v3.6.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 22:30

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.6.1/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.6.0...v3.6.1

v3.6.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 17:55

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.6.0/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.5.2...v3.6.0

v3.5.2

Choose a tag to compare

@github-actions github-actions released this 27 Sep 05:24

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.5.2/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.5.1...v3.5.2

v3.5.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 04:42

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.5.1/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.5.0...v3.5.1

v3.5.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 00:08

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.5.0/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.2.5...v3.5.0

v3.2.5

Choose a tag to compare

@github-actions github-actions released this 20 Sep 17:52

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.2.5/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.2.4...v3.2.5

v3.2.4

Choose a tag to compare

@github-actions github-actions released this 20 Sep 14:27

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.2.4/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.2.3...v3.2.4

v3.2.3

Choose a tag to compare

@github-actions github-actions released this 20 Sep 14:06

Verifying this download

Every asset below is covered by checksums.txt, which is signed
with the Wizard release key. install.sh and wizard update check
that signature and refuse anything that fails it, with no flag to
skip the check. If you download a tarball from this page by hand,
that check is yours to run:

# 1. the signature over checksums.txt, against the key in the repo
curl -fsSLO https://raw.githubusercontent.com/teddytennant/wizard/v3.2.3/wizard-release.pub
minisign -Vm checksums.txt -x checksums.txt.minisig \
  -P "$(grep -v '^untrusted comment:' wizard-release.pub)"

# 2. then the tarball you actually downloaded, against checksums.txt
sha256sum --ignore-missing -c checksums.txt

Both must pass. The first proves the checksum list is ours; the
second proves your download matches it. Checking only the second
proves nothing, because an attacker who can replace the tarball can
replace the checksum beside it.


Full Changelog: v3.2.2...v3.2.3