Security
Custodian release signing key
Every custodian release ships a checksums.txt signed with the key below. Check this fingerprint against the copy in the release you downloaded, then verify the checksum file's signature — that is how you know the artefacts are ours.
Published keys
This is one of three places the signing key is published — the others are thesigning/ directory of the source repository and the notes of every release. A substitution has to succeed in more than one of them to go unnoticed, so a reviewer who finds them disagreeing has learned something. Keys are never removed: a retired key stays listed so an older release can still be verified.
custodian-release-signing-key (2026)
Current- SHA-256 fingerprint
sha256:b477412e8852c1f35f0f1094cdf66527272ecc95b8faccebfc6e0a2070b67fba- Algorithm
- ECDSA P-256 (secp256r1), SHA-256
- Published
- Signing from
- Signing until
- Still current
Public key (PEM)
-----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/h28LLwbOyCexqaBLZRceOq2SeBH Br8V4encwNTCoNEh8447DucGXR+zwr5g9tPGDInJ8HCzQw04VN8oktGxEQ== -----END PUBLIC KEY-----
What this key signs
Each custodian release publishes two checksum files, and the current key signs the first of them intochecksums.txt.sig:
checksums.txt— SHA-256 of every published release artefact.checksums-unsigned.txt— SHA-256 of the same artefacts as a rebuild from source reproduces them, so a reproducible build can be compared against what was released.
Verify a release
With openssl and sha256sum alone. First save the key above to custodian-release-signing-key.pub.pem, then:
# 1. the checksum file's signature is ours
openssl dgst -sha256 \
-verify custodian-release-signing-key.pub.pem \
-signature checksums.txt.sig \
checksums.txt
# 2. the downloaded artefact matches the (signed) checksum file
sha256sum -c --ignore-missing checksums.txtYou can recompute the fingerprint above from the key file to confirm it is the one you saved:
openssl pkey -pubin -in custodian-release-signing-key.pub.pem -outform DER \
| sha256sumThe full step-by-step verification procedure — including rebuilding from the published source archive and comparing against checksums-unsigned.txt — is published withevery custodian release.