Skip to content

Release Signing

QHx releases are signed via Cosign.

Verification of QHx release signatures can be performed using cosign verify:

Verifying QHx release signatures
$ for x in manager proxy cli; do
cosign verify \
--certificate-identity-regexp 'https://github.com/messier-42/qhx-core/.*' \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
"oci.messier42.com/releng-test-qhx/${x}:v${VERSION}";
done