Mentu

Verify a release

Verify a release

Release binaries are built by GitHub Actions from the tagged source and published with a build provenance attestation. The attestation ties the asset you downloaded to the workflow, repository, and tag that produced it.

What it establishes: the binary was produced by the release.yml workflow in mentu-ai/mentu-recipes, at the tag it claims, on GitHub-hosted runners, and its SHA-256 is the one the workflow attested at build time. What it does not establish: anything about the behavior of the code. It ties the artifact to the visible source at the visible tag.

The attestation covers the two bare binaries, mentu-recipes-macos-arm64 and mentu-recipes-macos-x86_64. The installer package is not attested; it is signed and notarized instead, and checked a different way (below).

Requirements: curl, shasum, and the GitHub CLI.

1. Download the asset and the checksums

curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/mentu-recipes-macos-arm64
curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/checksums.txt

Check the bytes you got against the published checksum:

shasum -a 256 -c checksums.txt --ignore-missing
mentu-recipes-macos-arm64: OK

On Intel, substitute mentu-recipes-macos-x86_64 in the download and in every command below.

2. Verify the attestation

gh attestation verify mentu-recipes-macos-arm64 --repo mentu-ai/mentu-recipes
Loaded digest sha256:db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc for file://mentu-recipes-macos-arm64
Loaded 1 attestation from GitHub API
 
The following policy criteria will be enforced:
- Predicate type must match:................ https://slsa.dev/provenance/v1
- Source Repository Owner URI must match:... https://github.com/mentu-ai
- Source Repository URI must match:......... https://github.com/mentu-ai/mentu-recipes
- Subject Alternative Name must match regex: (?i)^https://github.com/mentu-ai/mentu-recipes/
- OIDC Issuer must match:................... https://token.actions.githubusercontent.com
 
✓ Verification succeeded!
 
The following 1 attestation matched the policy criteria
 
- Attestation #1
  - Build repo:..... mentu-ai/mentu-recipes
  - Build workflow:. .github/workflows/release.yml@refs/tags/v0.5.0
  - Signer repo:.... mentu-ai/mentu-recipes
  - Signer workflow: .github/workflows/release.yml@refs/tags/v0.5.0

That transcript is what the command prints in a terminal. When its output is not a terminal, as in a CI job or a script, it prints nothing and reports the result through its exit code alone: zero when an attestation matches the policy, non-zero when none does. That makes it usable as a gate in an install script.

Published checksums for v0.5.0

db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc  mentu-recipes-macos-arm64
04cdf178eb28db2dac9ad32acb159154ede56d75ac93251433efb5f1e461eb2e  mentu-recipes-macos-x86_64

Check a Homebrew install

The formula pins the same SHA-256 values, so Homebrew refuses any asset that does not match the attested build. To check what it installed, hash the linked binary and compare it against the list above:

shasum -a 256 "$(brew --prefix)/bin/mentu-recipes"
db71fbe9ad5be616dc5c2b36576055e22099f5e7a189c86b429dc203d90a66cc  /opt/homebrew/bin/mentu-recipes

Check the installer package

The package mentu-recipes-0.5.0-macos-arm64.pkg is signed with a Developer ID Installer certificate and notarized by Apple. Its SHA-256 is published in the release manifest at https://api.mentu.ai/v1/releases/latest and in the mentu-recipes-0.5.0-macos-arm64.json asset on the release. The Homebrew cask pins the same value, and the get.mentu.ai installer script compares the download against the manifest before running spctl and the installer.

curl -sLO https://github.com/mentu-ai/mentu-recipes/releases/download/v0.5.0/mentu-recipes-0.5.0-macos-arm64.pkg
shasum -a 256 mentu-recipes-0.5.0-macos-arm64.pkg
spctl -a -vv -t install mentu-recipes-0.5.0-macos-arm64.pkg
9f07c9238b48834ab6036fa6324408a52f6aabc5a2fba5516d1c6160c61e5972  mentu-recipes-0.5.0-macos-arm64.pkg
mentu-recipes-0.5.0-macos-arm64.pkg: accepted
source=Notarized Developer ID
origin=Developer ID Installer: Rashid Azarang (HR8X6TP7J6)

The full procedure, including the maintainer-side transcripts for the current and prior releases, is in VERIFICATION.md.

© 2026 Mentu.