Verify a release
Check release checksums, Sigstore identity, provenance, and the current operating-system signing limits.
Official releases contain platform binaries, SHA-256 checksums, Cosign bundles, an SPDX SBOM, GitHub build provenance, and a small companion verifier binary (agent-comms-verify).
What the installer checks
Before replacing the user-level binary, install.sh and install.ps1:
- require an exact release tag and confirm the GitHub release has that tag;
- download the binary, checksum file, matching Cosign bundle, and the
agent-comms-verifycompanion binary for your platform; - fetch the verifier digest committed in that protected release tag and refuse to execute the verifier unless its SHA-256 digest matches;
- compare the CLI binary’s SHA-256 digest against
checksums.txt; - verify the bundle against the exact release tag’s GitHub Actions workflow identity and OIDC issuer, using
agent-comms-verify— no separately installedcosignCLI required; - preserve the prior binary and install the verified replacement.
Any missing pin, asset, or verification failure stops installation. The pin is independent of mutable release assets: release automation refuses to publish unless its deterministic verifier build matches all six platform digests committed before the tag was created. agent-comms update (self-updating an already-installed copy) remains convenient for latest-version updates because its trusted verifier is built directly into the already-installed binary.
Manual verification
Use the command printed by the installer, or run the equivalent check with the downloaded agent-comms-verify binary:
./agent-comms-verify \
--bundle agent-comms-linux-amd64.bundle \
--certificate-identity-regexp '^https://github.com/DhanushSantosh/AgentComms/.github/workflows/release.yml@refs/tags/' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
agent-comms-linux-amd64
A real, separately installed cosign remains a fully supported, independent way to run the identical check — agent-comms-verify’s flags deliberately mirror cosign verify-blob --bundle’s exactly, so the command above works unchanged with either tool:
cosign verify-blob \
--bundle agent-comms-linux-amd64.bundle \
--certificate-identity-regexp '^https://github.com/DhanushSantosh/AgentComms/.github/workflows/release.yml@refs/tags/' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
agent-comms-linux-amd64
Also compare the asset digest with checksums.txt and inspect the GitHub provenance/SBOM associated with the release.
Platform warnings
Sigstore verification is independent of Windows Authenticode and Apple notarization. Until native platform signing is published for a release, SmartScreen or Gatekeeper may still display an operating-system warning even when checksum and Sigstore verification succeed.