Changelog
Fixed
- 879ece7c24bc92b25e1fb0a4da33049ed8b8332a: fix(ssrf): pin resolved IP in dial to prevent DNS rebinding (#791) (@vnykmshr)
Verifying the artifacts
First, download the [`checksums.txt` file](https://github.com/charmbracelet/soft-serve/releases/download/v0.11.5/checksums.txt) and the [`checksums.txt.sigstore.json` file](https://github.com/charmbracelet/soft-serve/releases/download/v0.11.5/checksums.txt.sigstore.json) files, for example, with `wget`: :::bash wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.11.5/checksums.txt' wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.11.5/checksums.txt.sigstore.json' Then, verify it using [`cosign`](https://github.com/sigstore/cosign): :::bash cosign verify-blob \ --certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' \ --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \ --bundle 'checksums.txt.sigstore.json' \ ./checksums.txt If the output is `Verified OK`, you can safely use it to verify the checksums of other artifacts you downloaded from the release using `sha256sum`: :::bash sha256sum --ignore-missing -c checksums.txt Done! You artifacts are now verified!Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.
