This release patches a security issue related to LFS locks of different users.
Thank you @Tomer-PL for reporting and fixing this one 🙂
Changelog
Fixed
- 62e2d5c: fix(ssh): ui: respect anon-access setting for the ui (@aymanbagabas)
- 2447a96: fix(tests): ignore stderr output in SSRF webhook test (@aymanbagabas)
Other stuff
- 000ab51: Merge commit from fork (@Tomer-PL)
- ba7d415: ci: sync golangci-lint config (#767) (@github-actions[bot])
Verifying the artifacts
First, download the checksums.txt file and the checksums.txt.sigstore.json file files, for example, with wget:
wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.11.2/checksums.txt'
wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.11.2/checksums.txt.sigstore.json'Then, verify it using cosign:
cosign verify-blob \
--certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--bundle 'checksums.txt.sigstore.json' \
./checksums.txtIf the output is Verified OK, you can safely use it to verify the checksums of other artifacts you downloaded from the release using sha256sum:
sha256sum --ignore-missing -c checksums.txtDone! You artifacts are now verified!
Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.