Verifying Release Artifacts
Every hdf-libs GitHub Release ships the CLI archives together with three layers of supply-chain evidence, strongest first:
| Layer | Artifact | Proves |
|---|---|---|
| Build provenance (SLSA Build L2) | GitHub attestation (fetched by gh, not a release asset) | The artifact was built by this repository's release workflow from a specific commit |
| Signature | checksums.txt.bundle (Sigstore bundle) | checksums.txt is exactly what the release workflow produced |
| Integrity | checksums.txt | Each downloaded file is bit-identical to what was checksummed |
checksums.txt lists every archive and SBOM, so the signature and the attestation transitively cover all artifacts: verify the checksum file once, then check your download against it.
Quick verification with gh
The GitHub CLI verifies build provenance in one command against any downloaded asset:
gh attestation verify hdf_3.5.1_linux_amd64.tar.gz --repo mitre/hdf-libsA successful verification confirms the asset was built by the .github/workflows/release.yml workflow in mitre/hdf-libs and reports the source commit. This is the recommended check for most consumers.
Signature verification with cosign
The release workflow signs checksums.txt with cosign keyless signing. The certificate identity is the release workflow itself, issued by GitHub's OIDC provider:
cosign verify-blob \
--bundle checksums.txt.bundle \
--certificate-identity-regexp '^https://github.com/mitre/hdf-libs/\.github/workflows/release\.yml@refs/tags/v' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txtVerified OK means the checksum file is authentic. Then confirm your downloaded artifacts against it:
sha256sum -c checksums.txt --ignore-missing--ignore-missing skips entries for platforms you did not download. On macOS use shasum -a 256 -c.
Software bill of materials
Each archive has a matching SPDX 2.3 JSON SBOM generated by syft at build time (<archive-name>.spdx.json). The SBOM is itself listed in checksums.txt, so its integrity is covered by the signature and attestation above. Feed it to any SPDX-aware scanner, for example:
grype sbom:hdf_3.5.1_linux_amd64.tar.gz.spdx.jsonWhat each check does and does not prove
sha256sum -calone proves integrity but not origin: an attacker who can replace an asset can replacechecksums.txttoo. Pair it with one of the other two layers.cosign verify-blobproves the checksum file came from this repository's release workflow. It does not prove which commit was built — the attestation carries that.gh attestation verifyproves workflow, repository, and source commit for the specific asset, and is the only check that needs no other file from the release.