v0.7.0
tpm-ca-certificates v0.7.0
What's Changed
This release contains the tpmtb binary and OCI images built from commit 1938eb7846fa712078092d845405e7f063edffff.
Artifacts
tpmtb_$VERSION_$OS_$ARCH.$EXTENSION- CLI binaries for various platforms (stored in archives)tpmtb_$VERSION_$OS_$ARCH.$EXTENSION.sbom.json- SBOMs for the binaries in SPDX formatchecksums.txt- SHA-256 checksums of all artifactschecksums.txt.sigstore.json- Sigstore signature bundle for checksum verification
OCI Images
docker pull ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:v0.7.0
docker pull ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:latestVerification
Important
If you are not familiar with the concepts around software supply chain security,
(eg. build provenance attestation, keyless signature, etc.), please read the following resources first:
1. Artefacts with Cosign and GitHub CLI
For complete security verification, follow this two-step process:
Step 1: Verify Integrity with Cosign
First, verify the integrity of the checksums file using Cosign:
Tip
Make sure to use cosign >= v2.4.3 to support the Sigstore bundle format.
# Verify the checksums signature
cosign verify-blob \
--bundle checksums.txt.sigstore.json \
--certificate-identity-regexp 'https://github.com/loicsikidi/tpm-ca-certificates/.github/workflows/release.yaml@refs/tags/v0.7.0' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
# Verify any artifact matches the checksum
sha256sum -c checksums.txtStep 2: Verify Provenance with GitHub CLI
Once the checksum integrity is established, verify the provenance using GitHub's attestation system:
# Verify the archive
gh attestation verify tpmtb_0.7.0_linux_amd64.tar.gz --repo loicsikidi/tpm-ca-certificates2. OCI Provenance
gh attestation verify oci://ghcr.io/loicsikidi/tpm-ca-certificates/tpmtb:v0.7.0 --repo loicsikidi/tpm-ca-certificatesChangelog
- 8f4baa3: fix(api): inherit filter logic in Contains fn (#81) (@loicsikidi)
- 7cc9932: fix(api): disable verify should dl int bundle(#83)(@loicsikidi)
- 1203474: fix(cache): avoid creating empty file (#85)(@loicsikidi)
- 669c34f: feat(api): add support to MSFT in vendor list (#89)(@loicsikidi)
- 3581fb4: feat: init basic tracing #87 (#102)(@loicsikidi)
- bd864a4: perf: reduce latency on apiv1beta.GetTrustedBundle (#103)(@loicsikidi)
- 6977901: refactor: clean shitty code (#104)(@loicsikidi)
- 70116aa: perf: improve GetDefaultTUFOptions logic (#108)(@loicsikidi)
- a758a94: secu(deps): fix vuln issue in go-tuf and rekor (#112)(@loicsikidi)
- 1938eb7: ci: fix linting issues from staticheck (#117) (@loicsikidi)
- b190510: perf: add parallelization to some tests (#115) (@loicsikidi)
- 80b3352: vuln(deps): bump otel to avoid GO-2026-4394 (#116) (@loicsikidi)
Generated with GoReleaser 🚀