Skip to content

Document how to verify the signed images and binaries - #307

Merged
cpanato merged 1 commit into
mainfrom
docs/verify-releases
Oct 9, 2026
Merged

cpanato merged 1 commit into
mainfrom
docs/verify-releases

Conversation

@cpanato

@cpanato cpanato commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Adds a Verifying the releases section to the README with the Cosign commands to verify a container image (cosign verify) and a release binary or checksums.txt (cosign verify-blob --bundle), using the identity of the release workflow, and mentions the SLSA provenance published with each release.

I ran both commands against the v0.11.0 release (image and github-actions-exporter_0.11.0_darwin_arm64, plus its checksum) and they verify. They were tested with Cosign v3 only; the section says so.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
@cpanato
cpanato merged commit ddd479a into main Oct 9, 2026
3 checks passed
@cpanato
cpanato deleted the docs/verify-releases branch October 9, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant