<!-- https://zunder-design-preview.pages.dev/docs/deploy/verify · Markdown version of the page -->

# Verify a release

Check that a Guard release is the one our public build produced, from public source, using checksums, Sigstore signatures, SLSA provenance and a reproducible build.

:::note[Planned]
No release exists yet. The release workflow, file names and repository are the plan for Guard 1.0. The tools (`sha256sum`, `cosign`, `slsa-verifier`, `gh`) are real and their flags below are theirs.
:::

Guard holds a key that can trade your account. You should not have to trust us that the binary you run is the source you can read. Four checks, from quick to thorough.

Use this page to check a release before running it. Return to [the setup journey](https://zunder-design-preview.pages.dev/docs/deploy) for installation and paper-mode verification.

## 1. Checksum

Every release has a `SHA256SUMS` file.

```sh
sha256sum --check --ignore-missing SHA256SUMS
# zunder-guard-1.0.0-linux-arm64.tar.gz: OK
```

This catches a broken download. On its own it does not prove who made the file: someone who can replace the archive can replace the checksum file too. So check its signature next.

## 2. Sigstore signature

Releases are signed in GitHub Actions with Sigstore's keyless signing. There is no long-lived signing key to steal; the signature binds the file to the workflow, repository and tag that built it.

```sh
cosign verify-blob SHA256SUMS \
  --bundle SHA256SUMS.sigstore.json \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity "https://github.com/zunderlabs/zunder-guard/.github/workflows/release.yml@refs/tags/v1.0.0"
```

`Verified OK`, together with step 1, means: these files came out of that workflow, for that tag.

## 3. SLSA provenance

The provenance says which source commit and which build steps produced the archive.

```sh
slsa-verifier verify-artifact zunder-guard-1.0.0-linux-arm64.tar.gz \
  --provenance-path zunder-guard-1.0.0.intoto.jsonl \
  --source-uri github.com/zunderlabs/zunder-guard \
  --source-tag v1.0.0
```

GitHub's own attestations give the same answer:

```sh
gh attestation verify zunder-guard-1.0.0-linux-arm64.tar.gz --repo zunderlabs/zunder-guard
```

## 4. Build it yourself

The build is meant to be reproducible: the same source, toolchain and flags give the same bytes. The toolchain is pinned in `rust-toolchain.toml`.

```sh
git clone https://github.com/zunderlabs/zunder-guard && cd zunder-guard
git checkout v1.0.0
./scripts/reproduce.sh linux-arm64      # builds in the pinned container
sha256sum target/dist/zunder-guard-1.0.0-linux-arm64.tar.gz
```

The hash should match `SHA256SUMS`. If it does not, tell us ([Reporting a vulnerability](https://zunder-design-preview.pages.dev/docs/security/reporting)).

## Also in every release

- **SBOM:** the list of every dependency and version.
- **Licence check:** `cargo deny check` runs in CI and refuses dependencies outside a permissive allow list (MIT, Apache-2.0 and similar), and known advisories.
