Sign release checksums with Ed25519 (#63)
CI / Lint (ruff) (pull_request) Successful in 6s
CI / Tests (py3.10 / ubuntu-latest) (pull_request) Successful in 12s
CI / Tests (py3.12 / windows-latest) (pull_request) Successful in 23s
CI / Tests (py3.12 / ubuntu-latest) (pull_request) Successful in 11s
CI / Tests (py3.13 / ubuntu-latest) (pull_request) Successful in 13s
CI / Lint (ruff) (pull_request) Successful in 6s
CI / Tests (py3.10 / ubuntu-latest) (pull_request) Successful in 12s
CI / Tests (py3.12 / windows-latest) (pull_request) Successful in 23s
CI / Tests (py3.12 / ubuntu-latest) (pull_request) Successful in 11s
CI / Tests (py3.13 / ubuntu-latest) (pull_request) Successful in 13s
Publish SHA256SUMS for every release archive and sign it with a detached Ed25519 signature (SHA256SUMS.sig), since paid code signing (macOS Developer ID, Windows Authenticode) and Sigstore keyless (needs a Fulcio-trusted OIDC issuer; self-hosted Gitea isn't one) are both out of budget/scope. - scripts/sign_checksums.py: dependency-light (cryptography only) helper to hash a directory of files into a sha256sum(1)-compatible SHA256SUMS manifest, sign it (domain-separated: b"bcc-release-v1|" + raw manifest bytes), and verify a signature. CLI has generate/ sign/verify subcommands; verify doubles as the check path. - tests/test_checksums.py: 15 unit + CLI-subprocess tests covering hashing, manifest formatting, sign/verify roundtrip, tamper detection, wrong-key rejection, domain-separation, and the no-key-provided failure path (must error, never write an empty/ bogus .sig). - .github/workflows/release.yml: Publish Release job now checks out the repo, flattens build artifacts, generates SHA256SUMS, and signs it from the RELEASE_SIGNING_KEY secret (base64 raw Ed25519 seed) if present. If the secret is absent, the release still publishes with a loud ::warning:: and no .sig — it never fails the release or publishes a bogus signature. - README.md: new 'Verifying your download' section with the (still placeholder) public key, sha256sum -c / Get-FileHash commands, and an explicit statement that this does not remove Gatekeeper/ SmartScreen warnings. - requirements-dev.txt / ci.yml: add cryptography as a dev/test dependency for the new script and its tests. Touches no files from bcc_core.py / tests/test_core.py / pyproject.toml / bcc.spec to avoid colliding with concurrent work on those files.
This commit is contained in:
@@ -19,6 +19,65 @@ Pre-built self-contained binaries are attached to every [GitHub Release](../../r
|
||||
|
||||
> **macOS Gatekeeper note:** the app is not notarized. On first launch, right-click → **Open**, or run `xattr -cr /Applications/BetterClaudeConfig.app` in a terminal.
|
||||
|
||||
## Verifying your download
|
||||
|
||||
BCC isn't code-signed — there's no budget for a paid certificate (macOS
|
||||
Developer ID, Windows Authenticode). Instead, every release publishes a
|
||||
`SHA256SUMS` file listing the checksum of each archive, detached-signed with
|
||||
Ed25519 as `SHA256SUMS.sig`. Both are attached to the release alongside the
|
||||
binaries.
|
||||
|
||||
**What this proves:** the file you downloaded is byte-for-byte what we
|
||||
published, and the manifest itself was signed by our release key.
|
||||
|
||||
**What this does NOT do:** it does not make the binary "safe," and it does
|
||||
**not** remove the macOS Gatekeeper or Windows SmartScreen warning — those
|
||||
are only suppressed by a paid OS-vendor certificate, which this project
|
||||
doesn't have. Verifying checksums is about detecting tampering in transit or
|
||||
on a mirror, not about vouching for the software.
|
||||
|
||||
**Release signing public key** (Ed25519, base64, raw 32 bytes):
|
||||
|
||||
```
|
||||
<PLACEHOLDER — AJ: paste the public key from the Catalog Console (#62) here>
|
||||
```
|
||||
|
||||
### macOS / Linux
|
||||
|
||||
```bash
|
||||
# From inside the folder you downloaded the release files into:
|
||||
sha256sum -c SHA256SUMS
|
||||
```
|
||||
|
||||
If your `sha256sum` complains about missing files, download `SHA256SUMS`
|
||||
into the same directory as the archive you downloaded — it lists every
|
||||
platform's archive, and only the one(s) present will be checked.
|
||||
|
||||
To also verify the manifest's signature (optional, requires Python +
|
||||
`pip install cryptography` and a checkout of this repo):
|
||||
|
||||
```bash
|
||||
python3 scripts/sign_checksums.py verify \
|
||||
--sums SHA256SUMS --sig SHA256SUMS.sig \
|
||||
--pubkey-b64 "<the public key above>"
|
||||
```
|
||||
|
||||
### Windows (PowerShell)
|
||||
|
||||
```powershell
|
||||
Get-FileHash .\BetterClaudeConfig-Windows.zip -Algorithm SHA256
|
||||
```
|
||||
|
||||
Compare the printed hash (case-insensitively) against the matching line in
|
||||
`SHA256SUMS`.
|
||||
|
||||
### If a release has no `SHA256SUMS.sig`
|
||||
|
||||
The signing key is a repo secret that has to be configured manually; if a
|
||||
release is missing the `.sig` file, the checksums themselves are still
|
||||
valid and safe to check against — the release workflow only skips signing,
|
||||
never checksum generation.
|
||||
|
||||
## Run from source
|
||||
|
||||
```bash
|
||||
@@ -92,6 +151,7 @@ file is also listed, marked *legacy*, so you can copy them over.
|
||||
- `test_core.py` — unit suite for the core (`python test_core.py`).
|
||||
- `bcc.spec` — PyInstaller build spec (cross-platform).
|
||||
- `scripts/build_icons.py` — regenerates `icons/app.icns` and `icons/app.ico` from source PNGs.
|
||||
- `scripts/sign_checksums.py` — generates and Ed25519-signs the release `SHA256SUMS` manifest (see [Verifying your download](#verifying-your-download)).
|
||||
|
||||
## Building from source
|
||||
|
||||
|
||||
Reference in New Issue
Block a user