How to Verify Jelby Builds
Every official Jelby release includes cryptographic build provenance (SLSA) and SHA-256 checksums. You can independently verify that your downloaded binary has not been tampered with and was built by GitHub Actions from the wilburn-pacific-company/jelby repository at a pinned commit.
1. Verify SLSA Build Provenance (Air-Gapped / Offline)
Every Jelby binary is attested with cryptographic SLSA provenance during the GitHub Actions build pipeline. You can verify that the binary was built unmodified from the wilburn-pacific-company/jelby source at a pinned commit.
gh attestation verify Jelby_x64-setup.exe --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelbygh attestation verify Jelby_aarch64.dmg --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelbygh attestation verify Jelby_amd64.AppImage --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby--repo wilburn-pacific-company/jelby specified?Binaries are distributed through jelby.ai to signed-in users. The SLSA attestation names the private source repository wilburn-pacific-company/jelby as the build source, which is why --repo points there.
Because Jelby is built within GitHub Enterprise, verification uses the pinned Sigstore trusted root (trusted_root.jsonl) included in each release, enabling repeatable, fully offline verification with no GitHub token.
2. Verify SHA-256 Checksums
Verify the integrity of downloaded binaries against our published checksums.
sha256sum -c --ignore-missing SHA256SUMS.txtcertutil -hashfile Jelby_x64-setup.exe SHA256Step-by-Step Verification Guide
Follow these commands in your terminal to perform independent validation
In addition to your platform installer (.exe, .dmg, or .AppImage), download the companion files from the Provenance & Integrity Bundles section of the download page (sign-in required):
SLSA bundle
Sigstore trust root
Plaintext hashes
Ensure you have the GitHub CLI (gh) installed (v2.49.0+), then run the offline verification command in the directory containing your downloaded files:
gh attestation verify <installer-file> --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby.github/workflows/release.yml@refs/tags/<tag> in wilburn-pacific-company/jelby. Run it in a terminal: when piped or scripted, gh prints nothing and exit code 0 is the result.If you prefer a fast integrity check against accidental download corruption, compare the SHA-256 hash. The checksum file lists every release artifact, so tell the tool to skip the ones you did not download:
sha256sum -c --ignore-missing SHA256SUMS.txtOn Windows, compare the hash directly:
certutil -hashfile Jelby_x64-setup.exe SHA256