github carvel-dev/imgpkg v0.48.3

6 hours ago

Installation and signature verification

Installation

By downloading binary from the release

For instance, if you are using Linux on an AMD64 architecture:

# Download the binary
curl -LO https://github.com/carvel-dev/imgpkg/releases/download/v0.48.3/imgpkg-linux-amd64

# Move the binary in to your PATH
mv imgpkg-linux-amd64 /usr/local/bin/imgpkg

# Make the binary executable
chmod +x /usr/local/bin/imgpkg

Via Homebrew (macOS or Linux)

$ brew tap carvel-dev/carvel
$ brew install imgpkg
$ imgpkg version

Verify checksums file signature

Install cosign on your system https://docs.sigstore.dev/system_config/installation/

The checksums file provided within the artifacts attached to this release is signed using Cosign with GitHub OIDC. To validate the signature of this file, run the following commands:

# Download the checksums file, certificate and signature
curl -LO https://github.com/carvel-dev/imgpkg/releases/download/v0.48.3/checksums.txt
curl -LO https://github.com/carvel-dev/imgpkg/releases/download/v0.48.3/checksums.txt.pem
curl -LO https://github.com/carvel-dev/imgpkg/releases/download/v0.48.3/checksums.txt.sig

# Verify the checksums file
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp=https://github.com/carvel-dev \
  --certificate-oidc-issuer=https://token.actions.githubusercontent.com

Verify binary integrity

To verify the integrity of the downloaded binary, you can utilize the checksums file after having validated its signature.

# Verify the binary using the checksums file
sha256sum -c checksums.txt --ignore-missing

What's Changed

  • build(deps): Bump github.com/mattn/go-isatty from 0.0.20 to 0.0.24 by @dependabot[bot] in #793
  • build(deps): Bump golang.org/x/sys from 0.46.0 to 0.48.0 by @dependabot[bot] in #797
  • build(deps): Bump github.com/maxbrunsfeld/counterfeiter/v6 from 6.12.2 to 6.13.0 by @dependabot[bot] in #796
  • build(deps): Bump github.com/cheggaaa/pb/v3 from 3.1.7 to 3.2.1 by @dependabot[bot] in #800
  • fix: case-insensitive active-keychains env var, and message-text corrections by @G-Gobi in #799

New Contributors

Full Changelog: v0.48.2...v0.48.3

📂 Files Checksum

17165d62316364a23eaf7f1f7fb44b0a976b53c18da986746c9deb2474c733e6  ./imgpkg-darwin-amd64
26eb329bfb2d64033ced4a1c7cc8dadb5bf7176cdd57b29328a8c7047c4196e8  ./imgpkg-darwin-arm64
655609325d9497096546342a4683688fc2a87a2952542b5da8105838285ec079  ./imgpkg-linux-arm64
d177073901136b1e07741c9c7e6afdbdf8b4bcf32017c1e5bc8d184c8383ec69  ./imgpkg-linux-amd64
cc7633b88d0fe29c67aaed2cea32717d31944dd529c911a0bbe7f944ec106bba  ./imgpkg-windows-amd64.exe

Don't miss a new imgpkg release

NewReleases is sending notifications on new releases.