For complete examples, see the guides. This reference is generated from CLI help.

packslip verify

Verify a packslip, or a release list, against a pinned identity or key

Check the signature, log evidence, and statement structure. With –artifact, also check local files against signed digests and artifact sizes. Without it, only the bundle is checked. Verification failures exit with status 1; no remote artifacts or provenance are fetched.

Pin a keyless signer with –identity or –identity-prefix and –issuer, or a signing key with –pubkey. Without an explicit pin, derive the policy from the document’s claimed GitHub or GitLab project. Consumers must separately match the project and version to their intended request. For release lists, expiry and remembered sequence checks are the consumer’s responsibility. See https://packslip.dev/docs/verifying/ .

Arguments

Flags