Binary supply chain

How to check the checksum and signature of a codafort release, and what each install channel verifies before installing.

Every release publishes SHA256SUMS, minisign-signed from v0.1.0 on, and every channel checks the hash before installing. The signature is checked by the install script when minisign is installed (table below).

What every release publishes

At github.com/codafort/releases, per product and version (the tag carries the product: codafort-v0.1.0, codacrash-v0.1.0…):

FileContents
<product>-<version>-<platform>.tar.gz / .zipthe binary, LICENSE (EULA) and THIRD-PARTY-NOTICES.md; for codafort, also skills/ (the Agent Skills)
SHA256SUMSthe hash of every file in the release
SHA256SUMS.minisigthe minisign signature of the hash file
codafort.pubthe minisign public key, in every codafort release and at codafort.dev/codafort.pub, where the installers fetch it
codafort-<version>-sbom.cdx.jsonthe CycloneDX SBOM of the codafort release (the binary and the dashboard it embeds)
codaprobe.rb · codatrace.rbHomebrew formulas for those two products, as release assets (the tap only carries codafort)

codafort platforms: macOS arm64 and x64, Linux x64 and arm64, Windows x64. codacrash: macOS arm64 and x64, Linux x64, Windows x64 and x86. codaprobe: macOS arm64 and x64, Linux x64, Windows x64. codatrace: macOS and Linux x64; on other platforms, the JVM agent ships as source in the package and codatrace install jvm prints the cc line to compile it. The Linux binaries need glibc 2.28 or newer (Ubuntu 20.04+, Debian 11+, RHEL/Rocky 8+, Amazon Linux 2023); Alpine/musl is not supported.

Verify by hand

# 1. checksum (only the files you downloaded)
sha256sum -c --ignore-missing SHA256SUMS   # macOS: shasum -a 256 -c --ignore-missing SHA256SUMS
# 2. signature of the checksum file
minisign -Vm SHA256SUMS -p codafort.pub

On Windows, step 1 is (Get-FileHash .\codafort-<version>-win32-x64.zip -Algorithm SHA256).Hash, compared with the line in SHA256SUMS.

If step 2 passes, every hash in SHA256SUMS is what codafort published. If step 1 passes, the file you downloaded is what the hash describes.

The channels and what each verifies

Pre-launch: codafort is not available to install yet. Join the waitlist →

ChannelCommandVerification
Script (macOS · Linux)`curl --proto '=https' --tlsv1.2 -fsSL https://codafort.dev/install.sh \sh`SHA-256 always: without SHA256SUMS or without sha256sum/shasum, it does not install; minisign when minisign is installed (otherwise warns and continues). Installs into ~/.local/bin; CODAFORT_VERSION pins the version, CODAFORT_INSTALL changes the directory, CODAFORT_NO_MODIFY_PATH=1 suppresses the PATH hint
PowerShell (Windows)`irm https://codafort.dev/install.ps1 \iex`SHA-256 always; minisign when minisign is on PATH. Installs into %LOCALAPPDATA%\Programs\codafort and adds it to the user PATH (CODAFORT_NO_MODIFY_PATH=1 skips that); the same CODAFORT_VERSION and CODAFORT_INSTALL
npmnpm i -g codafort · npx codafortthe codafort meta-package resolves @codafort/cli-<platform> via optionalDependencies; the native binary ships inside the package, and nothing is downloaded later
Homebrewbrew install codafort/tap/codafortthe formula carries each tarball's sha256
ManualDownloadyou verify as above

npm only distributes codafort. The codatrace agents (Python, Node, JVM) ship in the same package as the collector, so agent and collector are always on the same version.

SBOM

codafort's own SBOM is at /sbom.json (CycloneDX 1.5), produced by the product itself. It covers the dependencies of the binary and the web dashboard. It does not cover the codatrace agents, which have no lockfile of their own and use the standard library of your application's runtime. Every codafort release also carries the release's own SBOM (codafort-<version>-sbom.cdx.json), covered by SHA256SUMS and therefore by the signature.

Treat the installers as a release

/install.sh is POSIX sh, no bashisms; /install.ps1 runs on Windows PowerShell 5.1 and PowerShell 7. To read them before running: curl -fsSL https://codafort.dev/install.sh | less · irm https://codafort.dev/install.ps1. Neither asks for admin rights. The sh one never changes PATH (it only suggests); the PowerShell one changes only the user PATH, and says so. Both stop without installing if the checksum does not match, and a download cut short during curl | sh executes nothing.

Licence

Every binary is distributed under the Orchestro Tecnologia EULA (LICENSE in the package): licensed, not sold. Security (detection and fix) is free forever; see codafort.com/terms.