From 82aa0065a2fa84b7a7498bf4fc1033eea374e6f0 Mon Sep 17 00:00:00 2001 From: npond Date: Thu, 27 Aug 2026 11:04:46 -0400 Subject: [PATCH] README: verify provenance against the release asset, not the re-signed nuget copy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit nuget.org re-signs every package it accepts with its repository signature, which changes the bytes — so `gh attestation verify` on the installed copy gets a 404. The attestation matches the asset attached to the GitHub release (the CI build). Correct the Installation note to say so: verify the release asset for provenance, and `dotnet nuget verify` the installed copy for the repository signature. Bump the version examples to 0.1.2. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_018z5C7uNEvN24w5mSrN9sV7 --- README.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 995ef31..a4bfd2b 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ Converter.ConvertFile("report.docx", "report.pdf"); ## Installation -`n8PDF` is on [NuGet](https://www.nuget.org/packages/n8PDF) — latest **0.1.1** ([release notes](https://github.com/nathanpond/n8PDF/releases)): +`n8PDF` is on [NuGet](https://www.nuget.org/packages/n8PDF) — latest **0.1.2** ([release notes](https://github.com/nathanpond/n8PDF/releases)): ```bash dotnet add package n8PDF @@ -19,18 +19,21 @@ dotnet add package n8PDF or, in a project file: ```xml - + ``` It targets **.NET 10** (`net10.0`) and ships with its symbols and XML documentation. It is pre-1.0 — usable and hardened, but the API is not frozen until `v1.0.0`. Every release is published through NuGet **trusted publishing** (an OIDC exchange from CI, with no -stored key) and carries a signed [SLSA build-provenance](https://slsa.dev) attestation, so you can -prove a package came from this repository's CI and was not tampered with in the pipeline: +stored key). The copy you install carries nuget.org's own repository signature — `dotnet nuget verify` +shows it — and each [GitHub release](https://github.com/nathanpond/n8PDF/releases) attaches the same +package with a signed [SLSA build-provenance](https://slsa.dev) attestation binding it to the commit +and workflow that built it. nuget.org re-signs its copy, which changes its bytes, so verify the +**release asset** against this repository rather than the installed one: ```bash -gh attestation verify n8PDF.0.1.1.nupkg --repo nathanpond/n8PDF +gh attestation verify n8PDF.0.1.2.nupkg --repo nathanpond/n8PDF # the file from the GitHub release ``` ## The API