> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Release verification

> Verify checksums, signatures, notarization, and publisher identity

Official releases are published at [github.com/turenlabs/turenos/releases](https://github.com/turenlabs/turenos/releases).

```mermaid theme={null}
flowchart LR
  Commit[Exact dev commit] --> Build[Native platform builds]
  Build --> Mac[Developer ID + notarization]
  Build --> Win[Azure Authenticode]
  Build --> Linux[Linux packages]
  Mac --> Manifest[SHA256 manifest]
  Win --> Manifest
  Linux --> Manifest
  Manifest --> GPG[Detached OpenPGP signatures]
  GPG --> Publish[Verified GitHub release]
```

## Checksums and OpenPGP

Download `RELEASE_SIGNING_KEY.asc`, `SHA256SUMS`, and `SHA256SUMS.asc` with your artifact.

```bash theme={null}
gpg --import RELEASE_SIGNING_KEY.asc
gpg --fingerprint security@turen.io
gpg --verify release-manifest.json.asc release-manifest.json
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS
gpg --verify your-artifact.asc your-artifact
```

On macOS, use `shasum -a 256 -c SHA256SUMS` when `sha256sum` is unavailable.

Expected fingerprint:

```text theme={null}
4A4B 11E5 E425 82D7 2247 9A23 FCAD F0D9 BC66 D36C
```

The same public key is shipped with every release as `RELEASE_SIGNING_KEY.asc`; compare its fingerprint here before trusting it.

`release-manifest.json` records the release version, exact Git commit, filenames, sizes, and SHA-256 hashes. Verify its detached signature before trusting it.

## macOS

```bash theme={null}
codesign --verify --deep --strict --verbose=2 /Applications/TurenOS.app
spctl --assess --type execute --verbose=4 /Applications/TurenOS.app
xcrun stapler validate /Applications/TurenOS.app
```

The authority must be `Developer ID Application: Turen Labs, Inc. (5Q9UJQ9MPK)`.

## Windows

```powershell theme={null}
$signature = Get-AuthenticodeSignature .\turenos-desktop-win-x64.exe
$signature | Format-List
```

Require `Status: Valid`, a Turen Labs signer, a Microsoft-issued Azure Trusted Signing certificate, and a timestamp certificate.

## Linux

Linux AppImage, DEB, RPM, and runtime archives use detached OpenPGP signatures plus the signed checksum manifest. DEB/RPM repository metadata is not currently an additional trust root.

<Warning>
  Do not infer authenticity from a filename or GitHub page alone. Verify the cryptographic identity and hash before executing a downloaded binary.
</Warning>
