gezel Gezel Handboek

Release Artifact Sanity Check

Sanity-check a folder of release artifacts without executing them: inventory every package, verify hashes and signatures against trusted evidence, safely inspect every file inside archives and application bundles, scan for suspicious or secret-bearing content, and produce an evidence-backed ship or no-ship report. Use this for release artifact verification, installer signing checks, package integrity audits, supply-chain inspection, or a pre-publish binary review.

How it runs

#StepWho runs itWhat happens
1Inventory the release setDeveloperidentify every release record, artifact, checksum, signature, and package boundary
2Verify integrity and signingReviewerhash every artifact and validate signatures against a trusted identity
3Inspect every package memberDevelopersafely unpack app packages and scan every contained file
4Write the artifact sanity reportReviewerstate a ship decision with complete evidence and blockers
5EvaluateReviewergrade coverage and evidence; pass only when every acceptance criterion is met
6FinishReviewerstamp the decision and hand off the evidence-backed report

Say something like "sanity check release artifacts" or "audit release packages" or "verify installer signatures" or "inspect app bundles" or "check release artifact integrity" or "scan a release folder" in chat to start it.

Needs toolsets: builtin.security-intel, builtin.code-intel.

Watch this article as a slideshow