Skip to content

chore: Update doc and digests for v2.5.1#748

Merged
laurentsimon merged 2 commits intoslsa-framework:mainfrom
laurentsimon:release/v2.5.1
Mar 26, 2024
Merged

chore: Update doc and digests for v2.5.1#748
laurentsimon merged 2 commits intoslsa-framework:mainfrom
laurentsimon:release/v2.5.1

Conversation

@laurentsimon
Copy link
Copy Markdown
Contributor

This sets the expected sha256 of the v2.5.1 slsa-verifier released binary.

How to LGTM this PR (I'll work on a proper doc for this in slsa-framework/slsa-github-generator#112):

  1. Download the binary and provenance from https://github.com/slsa-framework/slsa-verifier/releases/tag/v0.0.1
  2. Clone the slsa-verifier repo, compile and verify the provenance using the steps described in https://github.com/slsa-framework/slsa-verifier/blob/main/RELEASE.md#verify-provenance
$ git clone git@github.com:slsa-framework/slsa-verifier.git
$ cd slsa-verifier
$ bash verify-release.sh v2.5.1

The output hash should be the hash I'm updating to in this PR. If they match, LGTM. If they don't, someone tampered with the released binary and don't LGTM

Signed-off-by: laurentsimon <laurentsimon@google.com>
Signed-off-by: laurentsimon <laurentsimon@google.com>
@laurentsimon laurentsimon requested a review from kpk47 as a code owner March 25, 2024 15:36
@@ -1,3 +1,13 @@
### [v2.5.1](https://github.com/slsa-framework/slsa-verifier/releases/tag/v2.5.1)

6246ff80cbd3d272bf843d72d1562cafb7c59b45b5b555fbee92df90547b4256 slsa-verifier-darwin-amd64
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

those are the hashes to verify

@laurentsimon laurentsimon changed the title Update doc and digests for v2.5.1 chore: Update doc and digests for v2.5.1 Mar 25, 2024
Copy link
Copy Markdown
Contributor

@kpk47 kpk47 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I checked the digests. Everything looks good.

@laurentsimon laurentsimon merged commit f315652 into slsa-framework:main Mar 26, 2024
ramonpetgrave64 pushed a commit to ramonpetgrave64/slsa-verifier that referenced this pull request Apr 10, 2024
This sets the expected sha256 of the v2.5.1 slsa-verifier released
binary.

How to LGTM this PR (I'll work on a proper doc for this in
slsa-framework/slsa-github-generator#112):

1. Download the binary and provenance from
https://github.com/slsa-framework/slsa-verifier/releases/tag/v0.0.1
2. Clone the slsa-verifier repo, compile and verify the provenance using
the steps described in
https://github.com/slsa-framework/slsa-verifier/blob/main/RELEASE.md#verify-provenance
```
$ git clone git@github.com:slsa-framework/slsa-verifier.git
$ cd slsa-verifier
$ bash verify-release.sh v2.5.1
```

The output hash should be the hash I'm updating to in this PR. If they
match, LGTM. If they don't, someone tampered with the released binary
and don't LGTM

---------

Signed-off-by: laurentsimon <laurentsimon@google.com>
Signed-off-by: Ramon Petgrave <ramon.petgrave64@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants