Integrity

This site publishes signed releases so public files can be checked against a manifest, detached signature and public key.

Last reviewed:

Signed release

Manifest · Signature · Public key

Manifest
/integrity.json
SHA-256 hashes of public files
Signature
/integrity.json.sig
Detached PGP signature
Public key
/.well-known/pgp-key.asc
Public signing key
Archives
ZIP TAR.GZ
Signed public source release
Checksums
SHA256SUMS SHA256SUMS.sig
Signed checksum list for archive downloads
Fingerprint
A729 591B 450D 3F59 3694 98BD 8299 1F25 04AE 0263

Release archives are verified through a signed checksum list and detached archive signatures. The live public site is verified through /integrity.json.

For page-level records, use Verify. For local manifest verification commands, see Verify locally.

History

Signed snapshots are kept for reference.

View archived editions

← Privacy