Every release ships a SHA256SUMS file and its minisign signature, SHA256SUMS.minisig. The public key lives in the repository at dist/minisign.pub.

Verify a download

Install minisign (for example apt install minisign or brew install minisign), download the release archive together with SHA256SUMS and SHA256SUMS.minisig from the release page, and save the public key next to them:

$ curl -LO https://raw.githubusercontent.com/KilimcininKorOglu/r3v3rs3/main/dist/minisign.pub

Then verify the checksums:

$ minisign -Vm SHA256SUMS -p minisign.pub
Signature and comment signature verified

minisign exits with a non-zero status when the signature does not match. When the signature is good, check the archive against the checksums:

$ sha256sum --check --ignore-missing SHA256SUMS
r3v3rs3-x86_64-unknown-linux-gnu.tar.xz: OK

Docker images carry no separate signature. Their digest, which docker pull prints, identifies the image bytes that the registry serves.