Release signing
Runink River releases are signed with a dedicated release-signing key, published on
2026-09-27 and pinned in KEYS.
| Fingerprint | 95C0A7B97D547413E42660DDB06FE75626F15BF3 |
| Algorithm | NIST P-384 (nistp384) |
| User ID | the lead maintainer’s today; a Runink River Release Engineering user ID may be added. Identify the key by its fingerprint, never by a user ID. |
| Public key | https://runink.org/.well-known/gpg-key.txt |
| Pinned in | KEYS, KEY_FPR_PINNED in install.sh and base/keys/owner/fingerprint, changed together in one commit |
| Private key | offline, with the release maintainers; never in CI, never a repository secret |
The same key is the package-signing root of trust of the planned own base
(base/keys/owner/). It is separate from the X.509 keys of Secure Boot.
No release signed with it has been published yet.
What is signed
- Tags: every release tag,
runink-os-YYYY.MM, is a signed tag (git verify-tag runink-os-YYYY.MM). - Artifacts: each release publishes
SHA256SUMSand a detached signature over it,SHA256SUMS.asc. The ISO and the packages are covered by the checksums. Packages carry detached.sigfiles. - Supply-chain metadata (additive): SBOMs and GitHub build provenance, optionally Sigstore bundles. These add evidence; they never replace the OpenPGP signature.
How a release is made
- CI and the builders produce only unsigned artifacts plus
SHA256SUMS. - A release maintainer checks them against a local build or the CI run and signs offline
with
base/river-sign, which refuses to run in CI. - The maintainer uploads
SHA256SUMS.ascand pushes the signed tag.
A release stays a draft until the release gate has checked it and published it with its evidence (Releases). To verify a download, see Verify a release.
Honest provenance level
The current release workflow can reach SLSA Build Level 1: it attests digests after a maintainer build. Level 3 needs the ISO built on an isolated, ephemeral builder that emits its own provenance, and that is on the roadmap, as is a reproducible ISO.
Secure Boot uses a separate chain of X.509 keys: Secure Boot.
Sources: KEYS, docs/RELEASE-SIGNING.md (whose key table
predates the key’s publication).