Security
Verify a download
You are about to run a tool that runs other people's code, so check it first. Every release is signed by our release workflow.
With cosign
Download checksums.txt, checksums.txt.sig, and checksums.txt.pem from the release, next to your archive. With cosign installed:
cosign verify-blob checksums.txt \ --signature checksums.txt.sig --certificate checksums.txt.pem \ --certificate-identity-regexp '^https://github.com/greyquill/mcpsight/\.github/workflows/release\.yml@' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com shasum -a 256 --ignore-missing -c checksums.txt
Both must pass. The first proves checksums.txt came from our release workflow. The second proves your archive matches it.
With the GitHub CLI
One command checks the archive's build provenance:
gh attestation verify mcpsight_*_darwin_arm64.tar.gz --repo greyquill/mcpsight
Homebrew checks the archive's checksum for you.