Files
libretro/allowed_signers
Abdessamad Derraz 1a96853aee feat: sign the release checksum list
SHA256SUMS.txt sat beside the artifacts it vouches for, so whoever could
rewrite a release rewrote the list with it. The packs were already
reproducible, which answers corruption and lets a third party rebuild an
archive byte for byte; nothing answered a rewritten release.

The list is now signed with an ed25519 key kept for this alone, and the
public half is allowed_signers at the repository root, so verification
does not go through the release page: ssh-keygen -Y verify against the
committed file, then sha256sum --check. Rehearsed on all three outcomes:
a good signature, a tampered pack caught by the sums, a rewritten list
caught by the signature.

The release steps sign and upload the signature, the README points a
downloader at the procedure, and the reproducibility section says what
each half proves. Rotation keeps retired lines so past releases stay
verifiable. Three tests hold the trust root, the signing step and the
documented principal in agreement.
2026-09-04 14:01:05 +02:00

2 lines
100 B
Plaintext

releases@retrobios ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIkAHTwnLhKeUvYC7+i8dnQMJnpElcV/hQq0FcZoKzI9