Reference
Release Verification
What a Row-Template release contains, how to verify it yourself, and exactly what a matching checksum does and does not prove.
Releases are published at github.com/iitzSeriZdev/Row-Template/releases. The installer follows the stable channel: releases/latest/download always resolves to the newest release that is not a draft or pre-release.
What a release contains
| Asset | Purpose |
|---|---|
row-template-<version>.tar.gz |
The payload: every design, built for each panel, the management library and its components, the row-template command, install.sh, VERSION |
SHA256SUMS |
The SHA-256 checksum of the tarball |
manifest.txt |
name, version, artifact, min_xui and created — read as data, never executed. min_xui applies to 3X-UI only. |
install.sh |
The bootstrap used by the one-command install |
Inside the tarball, a second SHA256SUMS lists the checksum of every file, and every design carries its own checksum — templates/<id>/template.html.sha256 for 3X-UI, and shells/<panel>/<id>/shell.html.sha256 for each panel. The installer checks the page for your panel against its checksum, and refuses one built for another panel.
Verify a download
In the folder holding the downloaded files:
sha256sum -c SHA256SUMS
row-template-1.4.0.tar.gz: OK
Then, optionally, every file inside it:
tar -xzf row-template-1.4.0.tar.gz
cd row-template-1.4.0 && sha256sum -c SHA256SUMS --quiet && echo "all files OK"
The installer performs the first check itself on every install and update, and refuses to continue on a mismatch.
What a matching checksum proves
It proves integrity relative to that checksum file: your tarball is bit-for-bit the one named in SHA256SUMS, with no corruption or truncation in transit.
It does not, on its own, prove who published it. Someone able to replace the tarball on the download host could replace SHA256SUMS at the same time. Trust in the publisher comes from elsewhere:
- HTTPS authenticates GitHub and protects the transfer;
- control of the GitHub repository decides who can publish a release.
“Checksum verified” is not the same as “signed by the author.”
Signed tags
A signed git tag would give cryptographic proof of authorship. No Row-Template release tag is signed so far — v1.3.0, v1.3.1 and v1.4.0 are plain tags, so git tag -v v1.4.0 reports that there is nothing to verify — and trust rests on HTTPS and on control of the repository, as above. If a later release is tagged with a signature, verify it with git tag -v and that tag’s name, against a key you already trust.
Reproducible builds
Releases are built with tools/make-release.sh, and the build is deterministic: the same sources produce the same designs, for every panel, byte for byte. From a checkout of the release tag you can rebuild them and compare each design’s checksum with the one shipped in the release.