Verifying downloads#

The install script and Homebrew check the binary for you. To check a binary you downloaded from the GitHub releases page yourself, verify it with the GitHub CLI.

Terminal

gh attestation verify ajmx-darwin-arm64 --repo yagipass/ajmx

This checks that GitHub Actions in yagipass/ajmx built the file. The binaries are ajmx-darwin-arm64, ajmx-linux-amd64 and ajmx-linux-arm64, and install.sh is attested too.

The install script verifies the attestation when GitHub CLI 2.93.0 or later is installed, and falls back to the SHA-256 checksum otherwise.

With the checksum#

Each binary has a .sha256 file next to it on the releases page. Download both into one directory and check the binary against it.

Terminal

shasum -a 256 -c ajmx-darwin-arm64.sha256
ajmx-darwin-arm64: OK

A checksum shows that the download is complete and unchanged, but not who built it. Prefer the attestation when you can.

Last updated: