Verifying Releases

Each DedupCommando release (on GitHub Releases, for amd64 and arm64) ships with artifacts you can use to verify the integrity and provenance of your download.

Artifacts (per architecture)

1. Checksum

sha256sum -c dedcom-<version>-<triple>.tar.gz.sha256   # expect: OK

2. Signature (minisign)

The project's minisign public key is:

RWS3JIpN+Qs0o91LEJ6RfrzeuJLDO3aiIcSS8YzJdayQnpKzPagqu9Z4

It is also published as minisign.pub in the repository root. Verify a release tarball against it:

# with the key string directly
minisign -Vm dedcom-<version>-<triple>.tar.gz -P RWS3JIpN+Qs0o91LEJ6RfrzeuJLDO3aiIcSS8YzJdayQnpKzPagqu9Z4

# or with the published key file
minisign -Vm dedcom-<version>-<triple>.tar.gz -p minisign.pub

Expect: Signature and comment signature verified.

3. Build provenance (SLSA attestation)

Releases are built in GitHub Actions with a signed build-provenance attestation. Verify it with the GitHub CLI:

gh attestation verify dedcom-<version>-<triple>.tar.gz --repo dedupcommando/DedupCommando

4. SBOM

The CycloneDX SBOM (*.cdx.json) lists the dependency tree and licenses, for auditing and supply-chain tooling.

APT repository

If you installed dedcom from the APT repository (apt install dedcom), apt verifies it for you. The repository's Release metadata is GPG-signed, and the signed-by option in the source list binds the repository to its published key (dedcom-archive-keyring.gpg), so apt installs a package only if it is signed with that key. This is a separate signature from the per-tarball minisign above: the APT channel is verified by the repository GPG key, the release tarballs by minisign.

Published from docs/VERIFYING-RELEASES.md at v0.9.2 · last changed 2026-06-25