<!-- https://zunderlabs.com/docs/deploy/verify · Markdown version of the page -->

# Verify a release

Check that a Guard release is the one our public build produced, from public source, using checksums, Sigstore signatures, SLSA provenance and a reproducible build.

:::note[Planned]
No release exists yet. The release workflow, file names and repository are the plan for Guard 1.0. The tools (`sha256sum`, `cosign`, `slsa-verifier`, `gh`) are real and their flags below are theirs.
:::

Guard holds a key that can trade your account. You should not have to trust us that the binary you run is the source you can read. Four checks, from quick to thorough.

## 1. Checksum

Every release has a `SHA256SUMS` file.

```sh
sha256sum --check --ignore-missing SHA256SUMS
# zunder-guard-1.0.0-linux-arm64.tar.gz: OK
```

This catches a broken download. On its own it does not prove who made the file: someone who can replace the archive can replace the checksum file too. So check its signature next.

## 2. Sigstore signature

Releases are signed in GitHub Actions with Sigstore's keyless signing. There is no long-lived signing key to steal; the signature binds the file to the workflow, repository and tag that built it.

```sh
cosign verify-blob SHA256SUMS \
  --bundle SHA256SUMS.sigstore.json \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity "https://github.com/zunderlabs/zunder-guard/.github/workflows/release.yml@refs/tags/v1.0.0"
```

`Verified OK`, together with step 1, means: these files came out of that workflow, for that tag.

## 3. SLSA provenance

The provenance says which source commit and which build steps produced the archive.

```sh
slsa-verifier verify-artifact zunder-guard-1.0.0-linux-arm64.tar.gz \
  --provenance-path zunder-guard-1.0.0.intoto.jsonl \
  --source-uri github.com/zunderlabs/zunder-guard \
  --source-tag v1.0.0
```

GitHub's own attestations give the same answer:

```sh
gh attestation verify zunder-guard-1.0.0-linux-arm64.tar.gz --repo zunderlabs/zunder-guard
```

## 4. Build it yourself

The build is meant to be reproducible: the same source, toolchain and flags give the same bytes. The toolchain is pinned in `rust-toolchain.toml`.

```sh
git clone https://github.com/zunderlabs/zunder-guard && cd zunder-guard
git checkout v1.0.0
./scripts/reproduce.sh linux-arm64      # builds in the pinned container
sha256sum target/dist/zunder-guard-1.0.0-linux-arm64.tar.gz
```

The hash should match `SHA256SUMS`. If it does not, tell us ([Reporting a vulnerability](https://zunderlabs.com/docs/security/reporting)).

## Also in every release

- **SBOM:** the list of every dependency and version.
- **Licence check:** `cargo deny check` runs in CI and refuses dependencies outside a permissive allow list (MIT, Apache-2.0 and similar), and known advisories.
