Skip to content

README: verify provenance on the release asset (nuget re-signs its copy) - #290

Merged
nathanpond merged 1 commit into
mainfrom
fix-provenance-verify-docs
Aug 27, 2026
Merged

nathanpond merged 1 commit into
mainfrom
fix-provenance-verify-docs

Conversation

@nathanpond

Copy link
Copy Markdown
Owner

Verifying provenance surfaced a real doc bug. nuget.org re-signs every package it accepts with its repository certificate, which changes the bytes — so gh attestation verify run on the installed (nuget.org) copy returns a 404: the attestation matches the CI-built artifact, which is the asset attached to the GitHub release, not the re-signed copy you install.

Fixes the Installation note accordingly:

  • Provenance → verify the release asset (gh attestation verify n8PDF.0.1.2.nupkg).
  • Repository signature → the installed copy carries nuget.org's signature (dotnet nuget verify).

Also bumps the version examples to 0.1.2. Same correction applied to the wiki Installation page.

Docs only.

🤖 Generated with Claude Code

…d nuget copy

nuget.org re-signs every package it accepts with its repository signature,
which changes the bytes — so `gh attestation verify` on the installed copy
gets a 404. The attestation matches the asset attached to the GitHub release
(the CI build). Correct the Installation note to say so: verify the release
asset for provenance, and `dotnet nuget verify` the installed copy for the
repository signature. Bump the version examples to 0.1.2.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018z5C7uNEvN24w5mSrN9sV7
@nathanpond
nathanpond merged commit 7b90e7a into main Aug 27, 2026
9 checks passed
@nathanpond
nathanpond deleted the fix-provenance-verify-docs branch August 27, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant