Releases: paulirotta/ahma
Release list
v0.19.2
Ahma v0.19.2
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.19.1
Ahma v0.19.1
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.19.0
Ahma v0.19.0
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.18.0
Ahma v0.18.0
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.17.1
Ahma v0.17.1
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.17.0
Ahma v0.17.0
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.16.9
Ahma v0.16.9
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.16.8
Ahma v0.16.8
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.16.7
Ahma v0.16.7
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.
v0.16.6
Ahma v0.16.6
Built from main via the CI pipeline.
Install
Linux / macOS:
curl -sSf https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"Windows (PowerShell 5.1+):
irm https://raw.githubusercontent.com/paulirotta/ahma/main/scripts/install.ps1 | iexUpdate an existing install:
ahma updateSupply chain protection — SLSA Level 3 via Sigstore
Every release archive and raw binary has a GitHub Build Provenance Attestation (Sigstore).
Attestations are keyless — signed by an ephemeral Fulcio certificate bound to this workflow's
OIDC identity. No private key exists; no rotation is needed.
ahma update and ahma verify --self verify the attestation automatically.
Manual out-of-band verification:
gh attestation verify ahma-release-linux-x86_64.tar.gz \
--repo paulirotta/ahmaAGPL + SLSA: two-layer supply chain defence
The ahma binary and security-relevant crates are AGPL-3.0-or-later.
AGPL requires source disclosure for any distributed or network-accessible modification,
closing the route of shipping a backdoored binary without publishing the changes.
The Sigstore attestation verifies that what you install was built from the published,
auditable source by the official CI pipeline.
Building from auditable source is always an option:
cargo install --git https://github.com/paulirotta/ahma ahma_bin --bin ahma --root ~/.local --lockedSee docs/release-signing.md
for the trust model and verification details.