tree: e5aa69720e19a0ac79c549feda3c67795d5e7611
  1. src/
  2. Dockerfile
  3. README.md
containers/check-release/README.md

Daffodil Check Release Container

This container can be used to verify the signatures, checksums, signatures, and optionally reproducibility.

Note that it is possible to run the src/check-release.sh script standalone without the container, but the container provides an environment that has all the necessary dependencies and keys already installed, so it may make release verification easier.

To build or update the build release container image:

podman build -t daffodil-check-release containers/check-release/

To use the container image to check a release, run the following:

podman run -it --rm \
  daffodil-check-release "$DIST_URL" "$MAVEN_URL"

Alternatively, if you would like to do the same checks but also check for reproducibility, use the Release Candidate Container to build a release directory, then run the following:

podman run -it --rm \
  --volume <RELEASE_DIR>:/release \
  daffodil-check-release "<DIST_URL>" "<MAVEN_URL>" /release