gh.
What each release attests
An attestation is a signed record, kept by GitHub, of the workflow and commit that produced a file. Every release attests these files:- each command line tarball
- the app’s zip file
- a bill of materials (SBOM) for each of those, in CycloneDX format (
.cdx.json) SHA256SUMS, the checksums of the tarballs and the appappcast.xml, the update feed that tells an installed app what to update to
appcast.xml.
On macOS, the command line and the app are also signed with a Developer ID and notarised by Apple. Files for Linux are not signed.
The app carries its notarisation ticket. For the command line, macOS fetches the ticket from Apple the first time you open a copy downloaded in a browser.
Homebrew installs these same files, and refuses one changed on the release page after the release workflow ran.
Check an attestation
In the download’s folder, run this, where<file> is the file’s name:
Verification succeeded! and exits with status 0. A changed file has no attestation, and the command fails with an error starting Error: HTTP 404: Not Found.
--repo accepts an attestation from any workflow in the repository. To accept only the release workflow, add --signer-workflow:
Check the checksums
DownloadSHA256SUMS from the same release and check it first:
SHA256SUMS shows that a download arrived whole. Someone able to change the release could change a file and its checksum together, and the attestation of SHA256SUMS catches that.
Then, in the folder holding both files, run this on macOS:
--ignore-missing skips files you did not download. A file that matches prints a line like this, where <version> is the release’s version:
FAILED, and the command exits with status 1.
Check the signature on macOS
spctl asks Gatekeeper whether macOS would open a file. For the app:
--type install, because --type execute accepts only apps. In the folder the tarball unpacked into, run this:
-vvv in place of -v, an origin line names the signer. For pitboard’s files, it ends with the team identifier (D7HJ5TFYCU).
For what else pitboard protects against, see Security and privacy.