Verify a release
Check that a Guard release is the one our public build produced, from public source, using checksums, Sigstore signatures, SLSA provenance and a reproducible build.
Guard holds a key that can trade your account. You should not have to trust us that the binary you run is the source you can read. Four checks, from quick to thorough.
1. Checksum
Section titled “1. Checksum”Every release has a SHA256SUMS file.
sha256sum --check --ignore-missing SHA256SUMS# zunder-guard-1.0.0-linux-arm64.tar.gz: OKThis catches a broken download. On its own it does not prove who made the file: someone who can replace the archive can replace the checksum file too. So check its signature next.
2. Sigstore signature
Section titled “2. Sigstore signature”Releases are signed in GitHub Actions with Sigstore’s keyless signing. There is no long-lived signing key to steal; the signature binds the file to the workflow, repository and tag that built it.
cosign verify-blob SHA256SUMS \ --bundle SHA256SUMS.sigstore.json \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ --certificate-identity "https://github.com/zunderlabs/zunder-guard/.github/workflows/release.yml@refs/tags/v1.0.0"Verified OK, together with step 1, means: these files came out of that workflow, for that tag.
3. SLSA provenance
Section titled “3. SLSA provenance”The provenance says which source commit and which build steps produced the archive.
slsa-verifier verify-artifact zunder-guard-1.0.0-linux-arm64.tar.gz \ --provenance-path zunder-guard-1.0.0.intoto.jsonl \ --source-uri github.com/zunderlabs/zunder-guard \ --source-tag v1.0.0GitHub’s own attestations give the same answer:
gh attestation verify zunder-guard-1.0.0-linux-arm64.tar.gz --repo zunderlabs/zunder-guard4. Build it yourself
Section titled “4. Build it yourself”The build is meant to be reproducible: the same source, toolchain and flags give the same bytes. The toolchain is pinned in rust-toolchain.toml.
git clone https://github.com/zunderlabs/zunder-guard && cd zunder-guardgit checkout v1.0.0./scripts/reproduce.sh linux-arm64 # builds in the pinned containersha256sum target/dist/zunder-guard-1.0.0-linux-arm64.tar.gzThe hash should match SHA256SUMS. If it does not, tell us (Reporting a vulnerability).
Also in every release
Section titled “Also in every release”- SBOM: the list of every dependency and version.
- Licence check:
cargo deny checkruns in CI and refuses dependencies outside a permissive allow list (MIT, Apache-2.0 and similar), and known advisories.
This page as plain Markdown, for people and LLMs: /docs/deploy/verify.md