mirror of
https://github.com/Abdess/retroarch_system.git
synced 2026-10-11 14:03:23 -05:00
SHA256SUMS.txt sat beside the artifacts it vouches for, so whoever could rewrite a release rewrote the list with it. The packs were already reproducible, which answers corruption and lets a third party rebuild an archive byte for byte; nothing answered a rewritten release. The list is now signed with an ed25519 key kept for this alone, and the public half is allowed_signers at the repository root, so verification does not go through the release page: ssh-keygen -Y verify against the committed file, then sha256sum --check. Rehearsed on all three outcomes: a good signature, a tampered pack caught by the sums, a rewritten list caught by the signature. The release steps sign and upload the signature, the README points a downloader at the procedure, and the reproducibility section says what each half proves. Rotation keeps retired lines so past releases stay verifiable. Three tests hold the trust root, the signing step and the documented principal in agreement.
2 lines
100 B
Plaintext
2 lines
100 B
Plaintext
releases@retrobios ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIkAHTwnLhKeUvYC7+i8dnQMJnpElcV/hQq0FcZoKzI9
|