Official releases are published at github.com/turenlabs/turenos/releases.
Checksums and OpenPGP
Download RELEASE_SIGNING_KEY.asc, SHA256SUMS, and SHA256SUMS.asc with your artifact.
On macOS, use shasum -a 256 -c SHA256SUMS when sha256sum is unavailable.
Expected fingerprint:
The same public key is shipped with every release as RELEASE_SIGNING_KEY.asc; compare its fingerprint here before trusting it.
release-manifest.json records the release version, exact Git commit, filenames, sizes, and SHA-256 hashes. Verify its detached signature before trusting it.
macOS
The authority must be Developer ID Application: Turen Labs, Inc. (5Q9UJQ9MPK).
Windows
Require Status: Valid, a Turen Labs signer, a Microsoft-issued Azure Trusted Signing certificate, and a timestamp certificate.
Linux
Linux AppImage, DEB, RPM, and runtime archives use detached OpenPGP signatures plus the signed checksum manifest. DEB/RPM repository metadata is not currently an additional trust root.
Do not infer authenticity from a filename or GitHub page alone. Verify the cryptographic identity and hash before executing a downloaded binary.