v0.7.2
Changelog
Bug fixes
- 9c7172e04d719d6045c057a3e9fb5db05474295d: Fix
vhs servemode (#448) (@t-chab) - 03cb81b5c310430d44de494db1094bf6555d7363: Update
logdependency (@caarlos0)
Other work
- 99506788042c267f0053e05aa8dfa4c5d2dc305b: Fix app crash when there is repeated
SLEEPat the end of the "lines" slice (#446) (@alaingilbert) - 2a1d3038af93dabf5e45bb0259653d684267bc91: Refactor Lexer, Parser, Token into packages (#427) (@maaslalani)
Verifying the artifacts
First, download the checksums.txt file, for example, with wget:
wget 'https://github.com/charmbracelet/vhs/releases/download/v0.7.2/checksums.txt'
Then, verify it using cosign:
cosign verify-blob \
--certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--cert 'https://github.com/charmbracelet/vhs/releases/download/v0.7.2/checksums.txt.pem' \
--signature 'https://github.com/charmbracelet/vhs/releases/download/v0.7.2/checksums.txt.sig' \
./checksums.txt
If the output is Verified OK, you can safely use it to verify the checksums of other artifacts you downloaded from the release using sha256sum:
sha256sum --ignore-missing -c checksums.txt
Done! You artifacts are now verified!
Thoughts? Questions? We love hearing from you. Feel free to reach out on Twitter, The Fediverse, or on Discord.
