Integrity

Signed.Verifiable.Reproducible.

The live manifest, signing key and release fingerprint for the current edition — the cryptographic authority for the site as it stands now, where Releases keeps the edition history. For independent verification, verify locally.

Read the instructions to verify the publication locally with command-line tools Check the current page against the published integrity data

Signature · Fingerprint · Manifest

Signature & signing key

Detached signature
/integrity.json.sig Download the detached PGP signature for the integrity manifest
Public key
/.well-known/pgp-key.asc Download the public PGP key used to sign releases

Release fingerprint

A729 591B 450D 3F59 3694 98BD 8299 1F25 04AE 0263

Manifest & checksums

Manifest
/integrity.json Download the signed integrity manifest (JSON listing every public file and its SHA-256)
Archive checksums
/SHA256SUMS Download the SHA-256 checksums for the signed release archives

Source archives

ZIP Download the source archive as a ZIP file TAR.GZ Download the source archive as a TAR.GZ file