Download and verify
Install the rule-cascade command or its WebAssembly module from rules.sdods.com, after checking its SHA-256 checksum and its Sigstore signature.
The rule-cascade command is one static binary with no dependencies, for Linux, macOS and Windows
on x86-64 and ARM64. rule-cascade.wasm is the same command for any WASI preview 1 host. Each
version is built and signed by the project's release workflow from a release tag, and served from
this site:
| Path | What it holds | Cached |
|---|---|---|
/download/<version>/ | One version, for good. Its files never change | one year, immutable |
/download/latest/ | A copy of the newest version, and VERSION, its number | five minutes |
No version is published yet
/download/<version>/ and /download/latest/, once it is cut. The commands below are the ones to use then.How the checks fit together
Two checks, and you need both. The checksum proves the file is the one listed in SHA256SUMS. The
signature proves SHA256SUMS, and each file, were signed by the project's release workflow from a
release tag: the signing certificate is issued by Sigstore to that workflow's GitHub Actions
identity, and the signature is recorded in Sigstore's public transparency log.
You need cosign 3.0 or later for
the signature (the bundles are Sigstore bundle format v0.3, which cosign 3 verifies by default). The commands download into the current directory and never run anything they have
not verified. There is no curl | sh.
Choose the version and your file
VERSION=$(curl -fsSL https://rules.sdods.com/download/latest/VERSION)
FILE=rule-cascade-linux-amd64 # or -linux-arm64, -darwin-amd64, -darwin-arm64, rule-cascade.wasm
BASE=https://rules.sdods.com/download/$VERSION
echo "$VERSION $FILE"Pin VERSION to a number instead of latest in a build script, so the build gets the same bytes
every time.
Download the file, its signature bundle and the checksums
curl -fsSL --remote-name-all \
"$BASE/$FILE" "$BASE/$FILE.sigstore.json" "$BASE/SHA256SUMS" "$BASE/SHA256SUMS.sigstore.json"Done when four files are in the directory: the binary, its .sigstore.json, SHA256SUMS and
SHA256SUMS.sigstore.json.
Check the checksum
grep " $FILE\$" SHA256SUMS | shasum -a 256 -c -rule-cascade-linux-amd64: OKDone when it prints OK. Anything else: delete the file and download it again.
Verify the signatures
Verify SHA256SUMS and the file against the release workflow's identity. The identity is a
regular expression: the release workflow of the project, run from a v tag; the issuer is GitHub
Actions.
IDENTITY='^https://github\.com/YarlisAISolutions/rule-cascade/\.github/workflows/release\.yml@refs/tags/v'
ISSUER=https://token.actions.githubusercontent.com
for f in SHA256SUMS "$FILE"; do
cosign verify-blob "$f" --bundle "$f.sigstore.json" \
--certificate-identity-regexp "$IDENTITY" --certificate-oidc-issuer "$ISSUER" || break
doneVerified OK
Verified OKDone when both print Verified OK. If either fails, do not run the file.
Install it and run it
chmod +x "$FILE"
sudo install -m 0755 "$FILE" /usr/local/bin/rule-cascade # or any directory on your PATH
rule-cascade versionFor the module, run it with a WASI host instead, for example wasmtime rule-cascade.wasm version.
rule-cascade 1.0.0-alpha.2 (specification 1.0.0, bundle format 1.0.0)Done when rule-cascade version prints the version you downloaded. Next:
the 5-minute quickstart.
In CI
Run the same four steps with VERSION pinned, and fail the job when any of them fails. Keep the
downloaded files: the bundle is the evidence of what you installed.
What Rule Cascade is
One rule contract, compiled once and evaluated by the same pure function in the browser, the backend and any other language.
5-minute quickstart
Try a rule in your browser with nothing installed, then get the command, write a rule with golden tests, check it, compile it and evaluate a request.