packslip
Share on:
Enter Your Mastodon Instance
Copy the link below to share to Mastodon
https://terminaltrove.com/packslip/
A signed release manifest for vendor binaries.
Script Preview
Review this script before executing in your terminal.

packslip is a command-line tool used in the mise package manager for verifying published signed release manifests, artifacts and software downloads with sigstore.
Each manifest records the target platform, checksums and executable paths for a release's downloads. Maintainers then sign the software using 'packslip create' with additional flags and can verify artifacts with a pinned identity or a local sigstore key (Ed25519 key pair) which gives installers a signed record of what was published when running packslip on the artifact.
It can also generate new Ed25519 sigstore key pairs using 'packslip keygen' and can show the cryptographic information related to both the bundle and the signed key using 'packslip show'. Other features of packslip include using manifests to select a download for the host, verifying its signer and checksum, and it can unpack also archives after verification.
Software maintainers, DevOps engineers and open source developers who need to sign artifacts using sigstore or are used to using mise but need a standalone signing tool will find packslip very useful for distributing software releases securely and verifying their origin and integrity.



