PageSourceSearch

https://oras.land/assets/js/0dec3c51.51a50b55.js

js oras.land collected 2026-09-24 08:57:00 UTC 4,082 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkoras_www||=[]).push([[499],{86905(e,i,n){n.r(i),n.d(i,{assets:()=>d,contentTitle:()=>a,default:()=>h,frontMatter:()=>o,metadata:()=>s,toc:()=>c});const s=JSON.parse('{"id":"how_to_guides/verifying_binaries","title":"Validating ORAS CLI Binaries","description":"After finding your target release,","source":"@site/versioned_docs/version-1.1/how_to_guides/verifying_binaries.mdx","sourceDirName":"how_to_guides","slug":"/how_to_guides/verifying_binaries","permalink":"/docs/1.1/how_to_guides/verifying_binaries","draft":false,"unlisted":false,"editUrl":"https://github.com/oras-project/oras-www/edit/main/versioned_docs/version-1.1/how_to_guides/verifying_binaries.mdx","tags":[],"version":"1.1","sidebarPosition":10,"frontMatter":{"title":"Validating ORAS CLI Binaries","sidebar_position":10},"sidebar":"tutorialSidebar","previous":{"title":"Distributing OCI Layouts","permalink":"/docs/1.1/how_to_guides/distributing_oci_layouts"},"next":{"title":"Go Scripting","permalink":"/docs/1.1/how_to_guides/go_script"}}');var r=n(74848),t=n(28453);const o={title:"Validating ORAS CLI Binaries",sidebar_position:10},a="Validating ORAS CLI Binaries",d={},c=[{value:"Step 1:",id:"step-1",level:3},{value:"Step 2:",id:"step-2",level:3},{value:"Step 3:",id:"step-3",level:3}];function l(e){const i={a:"a",code:"code",h1:"h1",h3:"h3",header:"header",p:"p",pre:"pre",...(0,t.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(i.header,{children:(0,r.jsx)(i.h1,{id:"validating-oras-cli-binaries",children:"Validating ORAS CLI Binaries"})}),"\n",(0,r.jsxs)(i.p,{children:["After finding your ",(0,r.jsx)(i.a,{href:"https://github.com/oras-project/oras/releases",children:"target release"}),",\nyou may find the releaser's information under the ",(0,r.jsx)(i.code,{children:"notes"})," section."]}),"\n",(0,r.jsx)(i.p,{children:"The following commands can be used to verify the ORAS CLI binaries using GPG:"}),"\n",(0,r.jsx)(i.h3,{id:"step-1",children:"Step 1:"}),"\n",(0,r.jsx)(i.p,{children:"First, we import the releasers' GPG Keys which can be used for verification:"}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{children:"$ curl -sSL https://raw.githubusercontent.com/oras-project/oras/refs/heads/main/KEYS | gpg --import -\n"})}),"\n",(0,r.jsxs)(i.p,{children:["The ",(0,r.jsx)(i.a,{href:"https://github.com/oras-project/oras/blob/main/KEYS",children:"GPG keys file"})," contains the keys which have been used for ORAS releases."]}),"\n",(0,r.jsx)(i.h3,{id:"step-2",children:"Step 2:"}),"\n",(0,r.jsx)(i.p,{children:"You can run the following command to check if the key has been imported. Your output will look something like:"}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{children:"$ gpg --list-keys\npub   rsa4096 2023-02-28 [SC] [expires: 2024-02-28]\n      BE6FA8DDA48D4C230091A0A9276D8A724CE1C704\nuid           [ unknown] Billy Zha <[email protected]>\npub   rsa4096 2024-12-04 [SC] [expires: 2025-12-04]\n      73C7F42E8F0B4493115ABED64F723223E9DF0185\nuid           [ unknown] Shiwei Zhang <[email protected]>\n"})}),"\n",(0,r.jsx)(i.h3,{id:"step-3",children:"Step 3:"}),"\n",(0,r.jsx)(i.p,{children:"Verify our binaries using the command:"}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{children:'$ gpg --verify oras_1.0.0_linux_amd64.tar.gz.asc oras_1.0.0_linux_amd64.tar.gz\ngpg: Signature made Mon Mar 20 15:51:28 2023 IST\ngpg:                using RSA key BE6FA8DDA48D4C230091A0A9276D8A724CE1C704\ngpg: Good signature from "Billy Zha <[email protected]>" [unknown]\n'})})]})}function h(e={}){const{wrapper:i}={...(0,t.R)(),...e.components};return i?(0,r.jsx)(i,{...e,children:(0,r.jsx)(l,{...e})}):l(e)}},28453(e,i,n){n.d(i,{R:()=>o,x:()=>a});var s=n(96540);const r={},t=s.createContext(r);function o(e){const i=s.useContext(t);return s.useMemo((function(){return"function"==typeof e?e(i):{...i,...e}}),[i,e])}function a(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:o(e.components),s.createElement(t.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.