Skip to content

docs: fix verification commands in README#52

Merged
Kirskov merged 1 commit into
mainfrom
docs/fix-verification-commands
Apr 19, 2026
Merged

docs: fix verification commands in README#52
Kirskov merged 1 commit into
mainfrom
docs/fix-verification-commands

Conversation

@Kirskov

@Kirskov Kirskov commented Apr 19, 2026

Copy link
Copy Markdown
Owner

Replace non-functional gh attestation verify (incompatible with slsa-framework/slsa-github-generator) with correct commands:

  • Quick install: use cosign verify-blob with sigstore bundle
  • Checksum: keep original filename to match checksums.txt entries
  • SLSA provenance: use slsa-verifier with multiple.intoto.jsonl

Replace non-functional `gh attestation verify` (incompatible with
slsa-framework/slsa-github-generator) with correct commands:
- Quick install: use cosign verify-blob with sigstore bundle
- Checksum: keep original filename to match checksums.txt entries
- SLSA provenance: use slsa-verifier with multiple.intoto.jsonl

Signed-off-by: Antoine GRICOURT <gricourtantoine@gmail.com>
@Kirskov
Kirskov merged commit aa7f7c5 into main Apr 19, 2026
10 checks passed
@Kirskov
Kirskov deleted the docs/fix-verification-commands branch April 19, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant