Overseas access: www.kdjingpai.com
Bookmark Us
Current Position:fig. beginning " AI Answers

How do I verify the security of the Crush installation files?

2025-08-19 309

Signature verification through the Cosign tool:

  1. Download the release file (e.g. checksums.txt) and their signature documents (.sig cap (a poem) .pem)
  2. Run the verify command:
    cosign verify-blob --certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' --cert checksums.txt.pem --signature checksums.txt.sig ./checksums.txt
  3. If the output Verified OK Indicates that the document has not been tampered with

This validation mechanism uses GitHub Actions' OIDC tokens to ensure that the certificate chain comes from a trusted build process.

Recommended

Can't find AI tools? Try here!

Just type in the keyword Accessibility Bing SearchYou can quickly find all the AI tools on this site.

Top

en_USEnglish