Skip to content

Verifying Release Artifacts ​

Every hdf-libs GitHub Release ships the CLI archives together with three layers of supply-chain evidence, strongest first:

LayerArtifactProves
Build provenance (SLSA Build L2)GitHub attestation (fetched by gh, not a release asset)The artifact was built by this repository's release workflow from a specific commit
Signaturechecksums.txt.bundle (Sigstore bundle)checksums.txt is exactly what the release workflow produced
Integritychecksums.txtEach downloaded file is bit-identical to what was checksummed

checksums.txt lists every archive and SBOM, so the signature and the attestation transitively cover all artifacts: verify the checksum file once, then check your download against it.

Quick verification with gh ​

The GitHub CLI verifies build provenance in one command against any downloaded asset:

bash
gh attestation verify hdf_3.5.1_linux_amd64.tar.gz --repo mitre/hdf-libs

A successful verification confirms the asset was built by the .github/workflows/release.yml workflow in mitre/hdf-libs and reports the source commit. This is the recommended check for most consumers.

Signature verification with cosign ​

The release workflow signs checksums.txt with cosign keyless signing. The certificate identity is the release workflow itself, issued by GitHub's OIDC provider:

bash
cosign verify-blob \
  --bundle checksums.txt.bundle \
  --certificate-identity-regexp '^https://github.com/mitre/hdf-libs/\.github/workflows/release\.yml@refs/tags/v' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  checksums.txt

Verified OK means the checksum file is authentic. Then confirm your downloaded artifacts against it:

bash
sha256sum -c checksums.txt --ignore-missing

--ignore-missing skips entries for platforms you did not download. On macOS use shasum -a 256 -c.

Software bill of materials ​

Each archive has a matching SPDX 2.3 JSON SBOM generated by syft at build time (<archive-name>.spdx.json). The SBOM is itself listed in checksums.txt, so its integrity is covered by the signature and attestation above. Feed it to any SPDX-aware scanner, for example:

bash
grype sbom:hdf_3.5.1_linux_amd64.tar.gz.spdx.json

What each check does and does not prove ​

  • sha256sum -c alone proves integrity but not origin: an attacker who can replace an asset can replace checksums.txt too. Pair it with one of the other two layers.
  • cosign verify-blob proves the checksum file came from this repository's release workflow. It does not prove which commit was built — the attestation carries that.
  • gh attestation verify proves workflow, repository, and source commit for the specific asset, and is the only check that needs no other file from the release.

Released under the Apache 2.0 License.