MAQPNADocs

maqpna verify binary

Verify a binary against its Sigstore bundle and checksums

Operate-o json | yaml

Synopsis#

maqpna verify binary FILE [--bundle FILE.sigstore.json] [--checksums checksums.txt]

Description#

From the help of maqpna verify:

Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.

Flags#

FlagTypeDescriptionDefault
--bundlestringsigstore bundle (default FILE.sigstore.json)none
--checksumsstringchecksums.txt of the release (SHA-256 check)none
--identitystringexact signer identitynone
--identity-regexpstringsigner identity regexp (default: the MAQPNA maqpna-signed-release.yml)none
--issuerstringOIDC issuernone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna verify binary ./maqpna --checksums checksums.txt

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna verify binary --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.