Skip to content

Download & verify

No signed Runink River release has been published yet. The release-signing key exists and its fingerprint is pinned in KEYS and in install.sh, but no release signed with it is out. install.sh downloads only what it can verify, so until the first signed release it has nothing to offer. To try Runink River today, build the ISO yourself.

The image

Each release is one installer image for 64-bit x86 PCs:

runink-river-<date>-x86_64.iso        volume label RIVER

It contains the complete system (the kernel, the desktop, the tools) and the installer. Nothing is downloaded during an install. Releases are published on GitHub and linked from runink.org, next to SHA256SUMS, its detached signature SHA256SUMS.asc, and the evidence of the release gate (SBOMs, scans, provenance). An ISO larger than 2 GiB is also published as numbered parts (<iso>.part-00, -01, …).

Download and verify in one line

On any Linux machine, install.sh downloads the latest release, verifies the signature on SHA256SUMS against the pinned fingerprint and the image’s sha256, joins the parts if there are any, and can write the image to a USB stick:

curl -fsSL https://raw.githubusercontent.com/org-runink/river/main/install.sh | sh
AddTo
| sh -s -- --dry-runcheck the release metadata and change nothing
| sh -s -- --out DIRsave the image in DIR
| sh -s -- --write /dev/sdXwrite it to a USB stick after verifying it (Create a USB stick)

The script fails closed: no fingerprint, no signature or a wrong checksum means no image. It never runs sudo itself; when a step needs root, it prints the command for you. It sends nothing anywhere: its only requests are the release files and the public key.

If you would rather read a script before you run it, download it first:

curl -fsSLO https://raw.githubusercontent.com/org-runink/river/main/install.sh
less install.sh
sh install.sh --dry-run

Verify by hand

curl -fsSLO https://runink.org/.well-known/gpg-key.txt
gpg --import gpg-key.txt
gpg --fingerprint 95C0A7B97D547413E42660DDB06FE75626F15BF3   # must be listed, matching KEYS
gpg --verify SHA256SUMS.asc SHA256SUMS                     # must say "Good signature"
sha256sum -c --ignore-missing SHA256SUMS                   # the ISO must say "OK"

Compare the full fingerprint with the one in KEYS, never a key ID or a name. Provenance, the Sigstore signature, the signed tag and what each evidence file tells you: Verify a release.

What you need next

  • A USB stick of 8 GB or more. Everything on it is erased.
  • A PC that meets the system requirements.
  • A way to keep the recovery key the installer shows you once: pen and paper, or a second USB stick.