Signed update packages
Every self-hosted release ships as one signed package. Check it on your own network before installing — no connection to us is needed.
Release signing key
No published key yet. The signing key is published here when the first signed package is issued. A sample package is provided for review before you commit.
What is inside each package
- manifest.json + manifest.sig
- List of every file with its SHA-256 checksum, signed with our Ed25519 release key.
- sbom.cdx.json
- CycloneDX software bill of materials: every bundled dependency, version and licence.
- SHA256SUMS
- Plain checksum list for sha256sum -c.
- verify.sh
- Offline check of the signature and every checksum. Needs only openssl 3 and sha256sum.
- install.sh
- Verifies first, backs up the database and current app, then applies new migrations and files.
- rollback.sh
- Restores a named backup; refuses if the backup is missing or its checksum fails.
- payload/
- The built application and the database migrations for this release.
Verify offline
unzip sitesafety-update-<version>.zip && cd sitesafety-update-<version> bash verify.sh /path/to/trusted-release-key.pem DATABASE_URL=... APP_DIR=/opt/sitesafety BACKUP_DIR=/var/backups/sitesafety bash install.sh # if needed: bash rollback.sh <backup-id printed by install.sh>
Sign in as an organisation admin to upload and check a package.
See the self-hosted licence summary for patch timescales and the mutual NDA for source review.