Skip to content

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 25 Feb 19:58
· 71 commits to main since this release
1938eb7

tpm-ca-certificates v0.7.0

What's Changed

This release contains the tpmtb binary and OCI images built from commit 1938eb7846fa712078092d845405e7f063edffff.

Artifacts

  • tpmtb_$VERSION_$OS_$ARCH.$EXTENSION - CLI binaries for various platforms (stored in archives)
  • tpmtb_$VERSION_$OS_$ARCH.$EXTENSION.sbom.json - SBOMs for the binaries in SPDX format
  • checksums.txt - SHA-256 checksums of all artifacts
  • checksums.txt.sigstore.json - Sigstore signature bundle for checksum verification

OCI Images

docker pull ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:v0.7.0
docker pull ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:latest

Verification

Important

If you are not familiar with the concepts around software supply chain security,
(eg. build provenance attestation, keyless signature, etc.), please read the following resources first:

1. Artefacts with Cosign and GitHub CLI

For complete security verification, follow this two-step process:

Step 1: Verify Integrity with Cosign

First, verify the integrity of the checksums file using Cosign:

Tip

Make sure to use cosign >= v2.4.3 to support the Sigstore bundle format.

# Verify the checksums signature
cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp 'https://github.com/loicsikidi/tpm-ca-certificates/.github/workflows/release.yaml@refs/tags/v0.7.0' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  checksums.txt

# Verify any artifact matches the checksum
sha256sum -c checksums.txt

Step 2: Verify Provenance with GitHub CLI

Once the checksum integrity is established, verify the provenance using GitHub's attestation system:

# Verify the archive
gh attestation verify tpmtb_0.7.0_linux_amd64.tar.gz --repo loicsikidi/tpm-ca-certificates

2. OCI Provenance

gh attestation verify oci://ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:v0.7.0 --repo loicsikidi/tpm-ca-certificates

Changelog

Generated with GoReleaser 🚀