Rule Cascade
Get started

Download and verify

Install the rule-cascade command or its WebAssembly module from rules.sdods.com, after checking its SHA-256 checksum and its Sigstore signature.

The rule-cascade command is one static binary with no dependencies, for Linux, macOS and Windows on x86-64 and ARM64. rule-cascade.wasm is the same command for any WASI preview 1 host. Each version is built and signed by the project's release workflow from a release tag, and served from this site:

PathWhat it holdsCached
/download/<version>/One version, for good. Its files never changeone year, immutable
/download/latest/A copy of the newest version, and VERSION, its numberfive minutes

No version is published yet

The first signed release appears here, at /download/<version>/ and /download/latest/, once it is cut. The commands below are the ones to use then.

How the checks fit together

Two checks, and you need both. The checksum proves the file is the one listed in SHA256SUMS. The signature proves SHA256SUMS, and each file, were signed by the project's release workflow from a release tag: the signing certificate is issued by Sigstore to that workflow's GitHub Actions identity, and the signature is recorded in Sigstore's public transparency log.

Diagram, described in Mermaid: flowchart LR T[Release tag] --> W[Release workflow builds 7 files and SHA256SUMS] W --> K[Sigstore signs each file with the workflow identity] K --> P[Files and .sigstore.json bundles published here] P --> D[You download a file, its bundle and SHA256SUMS] D --> C{SHA-256 matches SHA256SUMS?} C -- no --> X[Delete it] C -- yes --> V{cosign verify-blob passes?} V -- no --> X V -- yes --> I[Install and run rule-cascade version]

You need cosign 3.0 or later for the signature (the bundles are Sigstore bundle format v0.3, which cosign 3 verifies by default). The commands download into the current directory and never run anything they have not verified. There is no curl | sh.

Choose the version and your file

VERSION=$(curl -fsSL https://rules.sdods.com/download/latest/VERSION)
FILE=rule-cascade-linux-amd64     # or -linux-arm64, -darwin-amd64, -darwin-arm64, rule-cascade.wasm
BASE=https://rules.sdods.com/download/$VERSION
echo "$VERSION $FILE"

Pin VERSION to a number instead of latest in a build script, so the build gets the same bytes every time.

Download the file, its signature bundle and the checksums

curl -fsSL --remote-name-all \
  "$BASE/$FILE" "$BASE/$FILE.sigstore.json" "$BASE/SHA256SUMS" "$BASE/SHA256SUMS.sigstore.json"

Done when four files are in the directory: the binary, its .sigstore.json, SHA256SUMS and SHA256SUMS.sigstore.json.

Check the checksum

grep "  $FILE\$" SHA256SUMS | shasum -a 256 -c -
rule-cascade-linux-amd64: OK

Done when it prints OK. Anything else: delete the file and download it again.

Verify the signatures

Verify SHA256SUMS and the file against the release workflow's identity. The identity is a regular expression: the release workflow of the project, run from a v tag; the issuer is GitHub Actions.

IDENTITY='^https://github\.com/YarlisAISolutions/rule-cascade/\.github/workflows/release\.yml@refs/tags/v'
ISSUER=https://token.actions.githubusercontent.com
for f in SHA256SUMS "$FILE"; do
  cosign verify-blob "$f" --bundle "$f.sigstore.json" \
    --certificate-identity-regexp "$IDENTITY" --certificate-oidc-issuer "$ISSUER" || break
done
Verified OK
Verified OK

Done when both print Verified OK. If either fails, do not run the file.

Install it and run it

chmod +x "$FILE"
sudo install -m 0755 "$FILE" /usr/local/bin/rule-cascade    # or any directory on your PATH
rule-cascade version

For the module, run it with a WASI host instead, for example wasmtime rule-cascade.wasm version.

rule-cascade 1.0.0-alpha.2 (specification 1.0.0, bundle format 1.0.0)

Done when rule-cascade version prints the version you downloaded. Next: the 5-minute quickstart.

In CI

Run the same four steps with VERSION pinned, and fail the job when any of them fails. Keep the downloaded files: the bundle is the evidence of what you installed.

On this page