Merged
Conversation
Add binary integrity verification to the Verda CLI: - Release workflow: generate raw binary checksums, sign with cosign (keyless OIDC), and upload signing artifacts to GitHub Releases - Version command: add --verify flag that computes SHA256 of the running binary and compares against published checksums from GitHub Releases - Version command: show verdacloud-sdk-go and verdagostack dependency versions in output Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Set User-Agent to "verda-cli/<version>" on both the SDK client and the shared http.Client via a custom RoundTripper, enabling server-side analytics of CLI version distribution. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Suppress G304 (file inclusion via variable) on os.Open since path comes from os.Executable, not user input - Use 0600 permissions for test temp files (G306) - Check fmt.Fprint return values in test handlers (errcheck) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Pin the manual verification instructions to the exact workflow path (release.yml@refs/*) instead of just the repo name, per Sigstore OIDC best practices. A loose identity pattern could match other workflows or forks. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Type of Change
Checklist
make test)make pre-commit)Related Issues
Additional Context