trust, checked
Verify by hand
Every release ships SHA256SUMS.txt and a minisign signature.
The signing public key lives at
/clawee-release.pub — it is also baked into the
installer, which is the trust anchor that verifies each download automatically. To check
a download yourself:
minisign -V -P "$(cat clawee-release.pub | tail -n1)" -m SHA256SUMS.txt -x SHA256SUMS.txt.minisig f=<file> # the file you downloaded want=$(awk -v f="$f" '{ n = $2; sub(/^\*/, "", n); if (n == f) { print $1; exit } }' SHA256SUMS.txt) got=$(shasum -a 256 "$f" | awk '{print $1}') # sha256sum "$f" on Linux if [ -z "$want" ]; then echo "NO ENTRY for $f in SHA256SUMS.txt — do not install" elif [ "$want" = "$got" ]; then echo "OK $f" else echo "MISMATCH for $f — do not install"; fi
A failed signature check means the bytes are untrusted — do not install them.
Both files are published beside every zip; the downloads page links them per release.