Jelby Mascot - Blue Raspberry
JelbyAutonomous Coding Agent
Cryptographic Supply Chain Integrity

How to Verify Jelby Builds

Every official Jelby release includes cryptographic build provenance (SLSA) and SHA-256 checksums. You can independently verify that your downloaded binary has not been tampered with and was built by GitHub Actions from the wilburn-pacific-company/jelby repository at a pinned commit.

Recommended (Strongest)

1. Verify SLSA Build Provenance (Air-Gapped / Offline)

Every Jelby binary is attested with cryptographic SLSA provenance during the GitHub Actions build pipeline. You can verify that the binary was built unmodified from the wilburn-pacific-company/jelby source at a pinned commit.

Windows Installer Verification
gh attestation verify Jelby_x64-setup.exe --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby
macOS Installer Verification
gh attestation verify Jelby_aarch64.dmg --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby
Linux Package Verification
gh attestation verify Jelby_amd64.AppImage --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby
Why is --repo wilburn-pacific-company/jelby specified?

Binaries are distributed through jelby.ai to signed-in users. The SLSA attestation names the private source repository wilburn-pacific-company/jelby as the build source, which is why --repo points there.

Because Jelby is built within GitHub Enterprise, verification uses the pinned Sigstore trusted root (trusted_root.jsonl) included in each release, enabling repeatable, fully offline verification with no GitHub token.

2. Verify SHA-256 Checksums

Verify the integrity of downloaded binaries against our published checksums.

Jelby_x64-setup.exe
Available upon release publication
Jelby_aarch64.dmg
Available upon release publication
Jelby_amd64.AppImage
Available upon release publication
Automated Checksum Command:
sha256sum -c --ignore-missing SHA256SUMS.txt
Windows:
certutil -hashfile Jelby_x64-setup.exe SHA256

Step-by-Step Verification Guide

Follow these commands in your terminal to perform independent validation

1Download Release Assets & Companion Files

In addition to your platform installer (.exe, .dmg, or .AppImage), download the companion files from the Provenance & Integrity Bundles section of the download page (sign-in required):

release-attestation.json

SLSA bundle

trusted_root.jsonl

Sigstore trust root

SHA256SUMS.txt

Plaintext hashes

2Run the GitHub CLI Attestation Verifier

Ensure you have the GitHub CLI (gh) installed (v2.49.0+), then run the offline verification command in the directory containing your downloaded files:

gh attestation verify <installer-file> --bundle release-attestation.json --custom-trusted-root trusted_root.jsonl --repo wilburn-pacific-company/jelby
A successful run prints Loaded digest sha256:… for file://<installer>, then Verification succeeded! with the build workflow .github/workflows/release.yml@refs/tags/<tag> in wilburn-pacific-company/jelby. Run it in a terminal: when piped or scripted, gh prints nothing and exit code 0 is the result.
3Alternative: Checksum Validation

If you prefer a fast integrity check against accidental download corruption, compare the SHA-256 hash. The checksum file lists every release artifact, so tell the tool to skip the ones you did not download:

sha256sum -c --ignore-missing SHA256SUMS.txt

On Windows, compare the hash directly:

certutil -hashfile Jelby_x64-setup.exe SHA256