You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If you choose this option, refer to [Verifying Release Signatures](#verifying-release-signatures) to verify the authenticity and integrity of the downloaded binary.
62
63
63
64
#### Option 2 - Build the project yourself.
64
65
@@ -259,6 +260,47 @@ using SAS Viya Orders CLI:
259
260
}
260
261
```
261
262
263
+
## Verifying Release Signatures
264
+
265
+
SAS Viya Orders CLI releases are cryptographically signed with [GPG](https://www.gnupg.org/). To verify the authenticity of a downloaded binary:
Download both the binary and its corresponding `.asc` signature file from https://github.com/sassoftware/viya4-orders-cli/releases/latest, then verify:
gpg: Good signature from "SAS Institute, Inc. (Release Signing) <[email protected]>"
300
+
```
301
+
302
+
**Note:** You may see a warning about the key not being "certified with a trusted signature." This is normal and does not affect the verification. The warning simply means you haven't explicitly marked the key as trusted in your keyring.
303
+
262
304
## Contributing
263
305
264
306
We welcome your contributions! Please read [CONTRIBUTING.md](CONTRIBUTING.md)
0 commit comments