The release signing key
The public half, the allowed_signers file and the verify command. A release is signed when its SHA256SUMS.sig verifies with this key.
build host / keys
The key
The release signing key
Ed25519The public half of the key every release's SHA256SUMS is signed with; namespace igneum-release.
256 SHA256:umhm59z0pvL2OCPwi0zl1VcRCr4poHILz9zbzWEGCLk igneum-release (ED25519)
The files
Verify a release
In the directory holding a release's SHA256SUMS and SHA256SUMS.sig, with allowed_signers from this page:
ssh-keygen -Y verify -f allowed_signers -I igneum-release -n igneum-release -s SHA256SUMS.sig < SHA256SUMS
sha256sum -c SHA256SUMS
sha256sum -c SHA256SUMS
Or from a checkout: infra/release/verify.sh <component> <version>. The private half is on one machine and is never on a host, in a repository or in a message.
Igneum Labs LLC. Written 2026-10-11 13:31:11 UTC by the release host at each put; nothing here is a launch.