feat: updated signature vertification and copyright in README

pull/3281/head
yougotwill 3 months ago
parent e6b652a854
commit ab4debf9d0

@ -5,12 +5,16 @@
## Summary
Session integrates directly with [Oxen Service Nodes](https://docs.oxen.io/about-the-oxen-blockchain/oxen-service-nodes), which are a set of distributed, decentralized and Sybil resistant nodes. Service Nodes act as servers which store messages offline, and a set of nodes which allow for onion routing functionality obfuscating users IP Addresses. For a full understanding of how Session works, read the [Session Whitepaper](https://getsession.org/whitepaper).
<br/><br/>
![DesktopSession](https://i.imgur.com/ydVhH00.png)
<br/>
<br/>
<img src="https://i.imgur.com/ydVhH00.png" alt="Screenshot of Session Desktop" />
## Want to Contribute? Found a Bug or Have a feature request?
Please search for any [existing issues](https://github.com/session-foundation/session-desktop/issues) that describe your bug in order to avoid duplicate submissions. <br><br>Submissions can be made by making a pull request to our development branch.If you don't know where to start contributing please read [Contributing.md](CONTRIBUTING.md) and refer to issues tagged with the [Good-first-issue](https://github.com/session-foundation/session-desktop/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+issue%22) tag.
Please search for any [existing issues](https://github.com/session-foundation/session-desktop/issues) that describe your bug in order to avoid duplicate submissions.
Submissions can be made by making a pull request to our development branch.If you don't know where to start contributing please read [Contributing.md](CONTRIBUTING.md) and refer to issues tagged with the [good-first-issue](https://github.com/session-foundation/session-desktop/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+issue%22) tag.
## Supported platforms
@ -22,47 +26,101 @@ Build instructions can be found in [Contributing.md](CONTRIBUTING.md).
## Verifying signatures
Get Kee's key and import it:
**Step 1:**
Add Jason's GPG key. Jason Rhinelander, a member of the [Session Technology Foundation](https://session.foundation/) and is the current signer for all Session Desktop releases. His GPG key can be found on his GitHub and other sources.
```shell
wget https://github.com/jagerman.gpg
gpg --import jagerman.gpg
```
wget https://raw.githubusercontent.com/oxen-io/oxen-core/dev/utils/gpg_keys/KeeJef.asc
gpg --import KeeJef.asc
**Step 2:**
Get the signed hashes for this release. `SESSION_VERSION` needs to be updated for the release you want to verify.
```shell
export SESSION_VERSION=1.15.0
wget https://github.com/session-foundation/session-desktop/releases/download/v$SESSION_VERSION/signature.asc
```
Get the signed hash for this release, the SESSION_VERSION needs to be updated for the release you want to verify
**Step 3:**
Verify the signature of the hashes of the files.
```shell
gpg --verify signature.asc 2>&1 |grep "Good signature from"
```
export SESSION_VERSION=1.15.0
wget https://github.com/session-foundation/session-desktop/releases/download/v$SESSION_VERSION/signatures.asc
The command above should print "`Good signature from "Jason Rhinelander...`". If it does, the hashes are valid but we still have to make the sure the signed hashes match the downloaded files.
**Step 4:**
Make sure the two commands below return the same hash for the file you are checking. If they do, file is valid.
<details>
<summary>Linux</summary>
```shell
sha256sum session-desktop-linux-amd64-$SESSION_VERSION.deb
grep .deb signature.asc
```
Verify the signature of the hashes of the files
</details>
<details>
<summary>macOS</summary>
**Apple Silicon**
```shell
sha256sum releases/session-desktop-mac-arm64-$SESSION_VERSION.dmg
grep .dmg signature.asc
```
gpg --verify signatures.asc 2>&1 |grep "Good signature from"
**Intel**
```shell
sha256sum releases/session-desktop-mac-x64-$SESSION_VERSION.dmg
grep .dmg signature.asc
```
The command above should print "`Good signature from "Kee Jefferys...`"
If it does, the hashes are valid but we still have to make the sure the signed hashes matches the downloaded files.
</details>
<details>
<summary>Windows</summary>
Make sure the two commands below returns the same hash.
If they do, files are valid
**Powershell**
```PowerShell
Get-FileHash -Algorithm SHA256 session-desktop-win-x64-$SESSION_VERSION.exe # checksum is uppercase but should otherwise match
Select-String -Pattern ".exe" signature.asc
```
sha256sum session-desktop-linux-amd64-$SESSION_VERSION.deb
grep .deb signatures.asc
**Bash**
```shell
sha256sum session-desktop-win-x64-$SESSION_VERSION.exe
grep .exe signature.asc
```
</details>
## Debian repository
Please visit https://deb.oxen.io/<br/>
Please visit https://deb.oxen.io/
## License
Copyright 2011 Whisper Systems<br/>
Copyright 2013-2017 Open Whisper Systems<br/>
Copyright 2019-2023 The Oxen Project<br/>
Licensed under the GPLv3: https://www.gnu.org/licenses/gpl-3.0.html<br/>
Copyright 2011 Whisper Systems
Copyright 2013-2017 Open Whisper Systems
Copyright 2019-2024 The Oxen Project
Copyright 2024-2025 Session Technology Foundation
Licensed under the GPLv3: https://www.gnu.org/licenses/gpl-3.0.html
## Attributions

Loading…
Cancel
Save