1 Verify a package

Download the checksum list, its signature and the release signing key next to the packages you fetched:

curl -fsSLO https://github.com/BlkLeg/CircuitBreaker/releases/download/v0.4.4/SHA256SUMS -O https://github.com/BlkLeg/CircuitBreaker/releases/download/v0.4.4/SHA256SUMS.asc -O https://github.com/BlkLeg/CircuitBreaker/releases/download/v0.4.4/circuit-breaker-release-key.asc

Import the key and check that the checksum list was signed by it:

gpg --import circuit-breaker-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS

Then check your downloads against the list:

sha256sum --ignore-missing -c SHA256SUMS

Every file also has its own detached .asc signature, linked beside it on the download page. The installer does all of this for you unless you pass --skip-checksum.

2 Verify the container image

Images are signed in CI with cosign, keyless, against this repository's GitHub Actions identity:

cosign verify ghcr.io/blkleg/circuitbreaker:0.4.4 --certificate-identity-regexp '^https://github\.com/BlkLeg/CircuitBreaker/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' --certificate-oidc-issuer https://token.actions.githubusercontent.com

3 Check the install script

https://circuitbreaker.blkleg.app/install.sh serves the install.sh published with 0.4.4, byte for byte. Every build of this site checks it against the digest GitHub recorded when the release was uploaded, and refuses to publish anything else.

curl -fsSL https://circuitbreaker.blkleg.app/install.sh | sha256sum

Expected: f8d32ec361bcfa0692e0bc8aedeb4c66a761c03e214da7e5b530d27404fab82e, the digest GitHub recorded, also in the release's SHA256SUMS.

4 Inspect what's inside

Each release publishes CycloneDX and SPDX software bills of materials. The container's SBOM is also attached to the image, so cosign download sbom ghcr.io/blkleg/circuitbreaker:0.4.4 retrieves it.

Built like infrastructure

  • Access control: Roles, TOTP multi-factor and OAuth/OIDC sign-in. Authentication & access
  • Encrypted secrets: Credentials live in an encrypted vault, never in plain config. Credential security
  • Tamper-evident audit log: Every change is recorded in a SHA-256 hash chain. Audit log
  • Least privilege: Application processes run as an unprivileged user. Deployment & security
  • Signed releases: Cosign-signed images, SBOMs and SHA256SUMS on every release. Verify a download
  • Threat model: What it defends against, and what it deliberately doesn't. Threat model

Found a vulnerability?

Please report it privately rather than in a public issue. The vulnerability disclosure policy explains how, and what happens next.