For installation and common tasks, see the CLI overview. This reference is generated from development CLI help; run packslip pin --help for your installed version.

packslip pin

Print the signer fingerprint of a project’s keyless releases

Verify a release bundle and print the signer fingerprint of the repository that signed it: ps1_ and 26 characters. Run it on a release you already trust, because it fingerprints whichever repository signed the bundle it is given. A vendor publishes the fingerprint where consumers can read it without trusting a release, such as its README, and a consumer records it in its own configuration, such as a Dockerfile or CI workflow; packslip verify --pin then checks a release against it.

The fingerprint is derived from the forge’s issuer and repository ID only. It stays the same when the repository is renamed, moves to another owner, or signs from another workflow, and a repository that later takes over the old name gets a different one. Only keyless releases whose certificate records a repository ID have one; for a key-signed release, pin the key with packslip verify --pubkey.

Verification works as in packslip verify: the policy is the one the project’s name implies unless –identity, –identity-prefix, or –issuer replace it. See https://packslip.dev/docs/verifying/.

Arguments

Flags

Trust

Exit Status

CodeMeaning
0Printed the signer fingerprint
1Verification failed, the release has no signer fingerprint, or an input was unusable
2The command line is invalid

Examples

Print the fingerprint of a release you already trust

packslip pin packslip.sigstore.json