Verifying the Release Signature
After downloading the v4.2.1 release of Spin, either via the artifact attached to this release corresponding to your OS/architecture combination or via the installation method of your choice, you are ready to verify the release signature.
First, install cosign. This is the tool we'll use to perform signature verification. Then, from the directory containing the extracted release archive (spin, spin.sig and crt.pem), run the following command:
cosign verify-blob \
--signature spin.sig --certificate crt.pem \
--certificate-identity https://github.com/spinframework/spin/.github/workflows/release.yml@refs/tags/v4.2.1 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-github-workflow-sha fa7dc37ea28efcdd1b924ebe1eba88a1d069764d \
--certificate-github-workflow-repository spinframework/spin \
spin
If the verification passed, you should see:
Verified OK
What's Changed
- Bump for v4.2 release by @fibonacci1729 in #3729
- [Backport v4.2] Work around for
set-path-with-queryfailing on empty string by @itowlson in #3732 - Bump version for patch release by @fibonacci1729 in #3733
Full Changelog: v4.2.0...v4.2.1