Security

Verify a download

You are about to run a tool that runs other people's code, so check it first. Every release is signed by our release workflow.

With cosign

Download checksums.txt, checksums.txt.sig, and checksums.txt.pem from the release, next to your archive. With cosign installed:

cosign verify-blob checksums.txt \
  --signature checksums.txt.sig --certificate checksums.txt.pem \
  --certificate-identity-regexp '^https://github.com/greyquill/mcpsight/\.github/workflows/release\.yml@' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
shasum -a 256 --ignore-missing -c checksums.txt

Both must pass. The first proves checksums.txt came from our release workflow. The second proves your archive matches it.

With the GitHub CLI

One command checks the archive's build provenance:

gh attestation verify mcpsight_*_darwin_arm64.tar.gz --repo greyquill/mcpsight

Homebrew checks the archive's checksum for you.