Verify a release
Verify a release
Release binaries are built by GitHub Actions from the tagged source and published with a build provenance attestation. The attestation ties the asset you downloaded to the workflow, repository, and tag that produced it.
What it establishes: the binary was produced by the release.yml workflow in
mentu-ai/mentu-recipes, at the tag it claims, on GitHub-hosted runners, and
its SHA-256 is the one the workflow attested at build time. What it does not
establish: anything about the behavior of the code. It ties the artifact to the
visible source at the visible tag.
The attestation covers the two bare binaries, mentu-recipes-macos-arm64 and
mentu-recipes-macos-x86_64. The installer package is not attested; it is
signed and notarized instead, and checked a different way (below).
Requirements: curl, shasum, and the GitHub CLI.
1. Download the asset and the checksums
curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/mentu-recipes-macos-arm64
curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/checksums.txtCheck the bytes you got against the published checksum:
shasum -a 256 -c checksums.txt --ignore-missingmentu-recipes-macos-arm64: OKOn Intel, substitute mentu-recipes-macos-x86_64 in the download and in every
command below.
2. Verify the attestation
gh attestation verify mentu-recipes-macos-arm64 --repo mentu-ai/mentu-recipesLoaded digest sha256:db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc for file://mentu-recipes-macos-arm64
Loaded 1 attestation from GitHub API
The following policy criteria will be enforced:
- Predicate type must match:................ https://slsa.dev/provenance/v1
- Source Repository Owner URI must match:... https://github.com/mentu-ai
- Source Repository URI must match:......... https://github.com/mentu-ai/mentu-recipes
- Subject Alternative Name must match regex: (?i)^https://github.com/mentu-ai/mentu-recipes/
- OIDC Issuer must match:................... https://token.actions.githubusercontent.com
✓ Verification succeeded!
The following 1 attestation matched the policy criteria
- Attestation #1
- Build repo:..... mentu-ai/mentu-recipes
- Build workflow:. .github/workflows/release.yml@refs/tags/v0.5.0
- Signer repo:.... mentu-ai/mentu-recipes
- Signer workflow: .github/workflows/release.yml@refs/tags/v0.5.0That transcript is what the command prints in a terminal. When its output is not a terminal, as in a CI job or a script, it prints nothing and reports the result through its exit code alone: zero when an attestation matches the policy, non-zero when none does. That makes it usable as a gate in an install script.
Published checksums for v0.5.0
db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc mentu-recipes-macos-arm64
04cdf178eb28db2dac9ad32acb159154ede56d75ac93251433efb5f1e461eb2e mentu-recipes-macos-x86_64Check a Homebrew install
The formula pins the same SHA-256 values, so Homebrew refuses any asset that does not match the attested build. To check what it installed, hash the linked binary and compare it against the list above:
shasum -a 256 "$(brew --prefix)/bin/mentu-recipes"db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc /opt/homebrew/bin/mentu-recipesCheck the installer package
The package mentu-recipes-0.5.0-macos-arm64.pkg is signed with a
Developer ID Installer certificate and notarized by Apple. Its SHA-256 is
published in the release manifest at https://api.mentu.ai/v1/releases/latest
and in the mentu-recipes-0.5.0-macos-arm64.json asset on the release.
The Homebrew cask pins the same value, and the get.mentu.ai installer script
compares the download against the manifest before running spctl and the
installer.
curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/mentu-recipes-0.5.0-macos-arm64.pkg
shasum -a 256 mentu-recipes-0.5.0-macos-arm64.pkg
spctl -a -vv -t install mentu-recipes-0.5.0-macos-arm64.pkg9f07c9238b48834ab6036fa6324408a52f6aabc5a2fba5516d1c6160c61e5972 mentu-recipes-0.5.0-macos-arm64.pkg
mentu-recipes-0.5.0-macos-arm64.pkg: accepted
source=Notarized Developer ID
origin=Developer ID Installer: Rashid Azarang (HR8X6TP7J6)The full procedure, including the maintainer-side transcripts for the current and prior releases, is in VERIFICATION.md.