Skip to content

Verify a release by hand

afmpeg's WithModuleRelease verifies releases for you. This page shows the same checks with nothing but gpg, curl, and sha256sum — useful for auditing, CI in another language, or just confirming the chain yourself. It mirrors exactly what afmpeg does (spec 0010 / 0011).

Set the release you want:

TAG=n8.1.2-10
BASE="https://gitlab.com/api/v4/projects/83847809/packages/generic/ffmpeg-wasi/$TAG"

1. Get the signing key from WKD

The release-signing key is published via the Web Key Directory on the phpboyscout.uk domain — a control plane independent of the GitLab repo that hosts the releases. Fetch it by email; gpg resolves WKD automatically:

gpg --locate-external-keys [email protected]

Confirm the fingerprint is exactly this (the value afmpeg pins):

710881C1 DDAE ABD1 38E5 3004  A216 6E59 EB60 60E1
gpg --fingerprint [email protected]

If the fingerprint differs, stop — do not trust the release.

2. Verify the signature over the manifest

checksums.txt.sig is an OpenPGP detached signature over checksums.txt:

curl -fsSLO "$BASE/checksums.txt"
curl -fsSLO "$BASE/checksums.txt.sig"

gpg --verify checksums.txt.sig checksums.txt

Expect Good signature from "ffmpeg-wasi Release Signing <[email protected]>". (gpg may add a "not certified with a trusted signature" web-of-trust warning — that is about your local trust DB, not the cryptographic validity; the fingerprint check in step 1 is the trust decision.)

3. Check the assets against the signed manifest

checksums.txt covers every asset, including provenance.json — so the one verified signature transitively certifies whatever you download. Grab what you need and check it:

curl -fsSLO "$BASE/ffmpeg-wasi-lgpl.wasm"
curl -fsSLO "$BASE/provenance.json"

sha256sum --ignore-missing -c checksums.txt

Expect ffmpeg-wasi-lgpl.wasm: OK and provenance.json: OK. (--ignore-missing checks only the files present; drop it once you've downloaded every asset.)

That's the whole chain: WKD key → OpenPGP signature over checksums.txt → SHA-256 of each asset. provenance.json then tells you exactly what went into the build.