Download & verify
KEYS and in install.sh, but no release signed
with it is out. install.sh downloads only what it can verify, so until the first signed
release it has nothing to offer. To try Runink River today,
build the ISO yourself.The image
Each release is one installer image for 64-bit x86 PCs:
runink-river-<date>-x86_64.iso volume label RIVERIt contains the complete system (the kernel, the desktop, the tools) and the installer.
Nothing is downloaded during an install. Releases are published on
GitHub and linked from
runink.org, next to SHA256SUMS, its detached signature
SHA256SUMS.asc, and the evidence of the release gate (SBOMs, scans, provenance). An ISO
larger than 2 GiB is also published as numbered parts (<iso>.part-00, -01, …).
Download and verify in one line
On any Linux machine, install.sh downloads the latest release, verifies the
signature on SHA256SUMS against the pinned fingerprint and the image’s sha256, joins the
parts if there are any, and can write the image to a USB stick:
curl -fsSL https://raw.githubusercontent.com/org-runink/river/main/install.sh | sh| Add | To |
|---|---|
| sh -s -- --dry-run | check the release metadata and change nothing |
| sh -s -- --out DIR | save the image in DIR |
| sh -s -- --write /dev/sdX | write it to a USB stick after verifying it (Create a USB stick) |
The script fails closed: no fingerprint, no signature or a wrong checksum means no
image. It never runs sudo itself; when a step needs root, it prints the command for you.
It sends nothing anywhere: its only requests are the release files and the public key.
If you would rather read a script before you run it, download it first:
curl -fsSLO https://raw.githubusercontent.com/org-runink/river/main/install.sh
less install.sh
sh install.sh --dry-runVerify by hand
curl -fsSLO https://runink.org/.well-known/gpg-key.txt
gpg --import gpg-key.txt
gpg --fingerprint 95C0A7B97D547413E42660DDB06FE75626F15BF3 # must be listed, matching KEYS
gpg --verify SHA256SUMS.asc SHA256SUMS # must say "Good signature"
sha256sum -c --ignore-missing SHA256SUMS # the ISO must say "OK"Compare the full fingerprint with the one in KEYS, never a key ID or a
name. Provenance, the Sigstore signature, the signed tag and what each evidence file tells
you: Verify a release.
What you need next
- A USB stick of 8 GB or more. Everything on it is erased.
- A PC that meets the system requirements.
- A way to keep the recovery key the installer shows you once: pen and paper, or a second USB stick.