Skip to content

release: publish and anonymously verify v1.1.2 installer assets #81

Description

@bradtaylorsf

Summary

Publish v1.1.2 with complete immutable installer assets and verify every public download without GitHub authentication.

Proposed Approach

  • Generate assets from the v1.1.2 tag using the release workflow.
  • Verify the manifest pins the public runtime image digest.
  • Publish only after checksums and inventory match.
  • Download anonymously and verify hashes before execution.
  • Exercise documented macOS and Windows bootstrap entry points.

Acceptance Criteria

  • v1.1.2 is a non-draft production release.
  • Required macOS, Windows/WSL2, manifest, and checksum assets are attached.
  • Checksums match locally regenerated values from tagged source.
  • Manifest pins an anonymously pullable runtime digest.
  • Every asset downloads and verifies without credentials.
  • Notes cover supported hardware, privacy, limitations, rollback, and security reporting.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestneeds-human-inputRequires human review or decisionpriority:highImportant for the complete OSS product

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions