<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>signing on SOW</title>
    <link>https://sow.pgsty.com/tags/signing/</link>
    <description>Recent content in signing on SOW</description>
    <generator>Hugo</generator>
    <language>en</language>
    
    
    
      <lastBuildDate>Fri, 28 Aug 2026 18:32:04 +0800</lastBuildDate>
    
    
      <atom:link href="https://sow.pgsty.com/tags/signing/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>SOW v0.4.0</title>
        <link>https://sow.pgsty.com/blog/release/sow-v0.4.0/</link>
        <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/blog/release/sow-v0.4.0/</guid>
        <description>&lt;p&gt;SOW 0.4.0 is an integrity and recovery release for Managed repositories. It makes&#xA;the deep checker&amp;rsquo;s I/O contract explicit, prevents RPM trust from being assembled&#xA;across unrelated keys, adds an audited way to correct mutable publication-target&#xA;settings, and closes the remaining v0.3 migration and interrupted-publication gaps.&lt;/p&gt;&#xA;&lt;p&gt;Plain repository behavior and the public &lt;code&gt;pool/ + dists/&lt;/code&gt; layout do not change.&lt;/p&gt;&#xA;&lt;h2 id=&#34;upgrade-from-03&#34;&gt;Upgrade from 0.3&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-callout td-callout--important&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-circle-exclamation&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Migrate every v0.3 Repository explicitly&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;Stop all Workspace writers, back up the Workspace, install 0.4.0, and run&#xA;&lt;code&gt;sow repo migrate REPOSITORY&lt;/code&gt;&#xA;once for each Repository before ordinary reads or writes. The migration is&#xA;explicit and one-way; do not reopen a migrated database with SOW 0.3.&lt;/p&gt;</description>
      </item>
    <item>
        <title>SOW v0.2.0</title>
        <link>https://sow.pgsty.com/blog/release/sow-docs-launch/</link>
        <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/blog/release/sow-docs-launch/</guid>
        <description>&lt;p&gt;SOW 0.2.0 is a self-contained RPM and DEB repository manager from&#xA;&lt;a href=&#34;https://pigsty.io&#34;&gt;Pigsty&lt;/a&gt;. Release artifacts target Linux and macOS as single Go&#xA;executables.&lt;/p&gt;&#xA;&lt;h2 id=&#34;two-operating-modes&#34;&gt;Two operating modes&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Plain mode&lt;/strong&gt; indexes RPM and DEB files already present at one directory&amp;rsquo;s top level:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-b4801182-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-b4801182-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sow create /srv/repo&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;It writes &lt;code&gt;repodata/&lt;/code&gt;, &lt;code&gt;Packages&lt;/code&gt;, and &lt;code&gt;Packages.gz&lt;/code&gt; in place. Plain mode has no&#xA;Workspace, state database, generations, or DEB &lt;code&gt;Release&lt;/code&gt; signing.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Tutorials</title>
        <link>https://sow.pgsty.com/docs/tutorial/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/tutorial/</guid>
        <description>&lt;p&gt;Each tutorial starts from a new workspace. Commands are intended to be run in order;&#xA;replace uppercase placeholders and package paths for your environment.&lt;/p&gt;&#xA;&lt;p&gt;If you have not installed SOW yet, start with &lt;a href=&#34;https://sow.pgsty.com/docs/start/install/&#34;&gt;Installation&lt;/a&gt; and&#xA;&lt;a href=&#34;https://sow.pgsty.com/docs/start/quickstart/&#34;&gt;Quick Start&lt;/a&gt;. The tutorials below cover the managed repository path.&lt;/p&gt;&#xA;&lt;div class=&#34;td-content-cards td-content-cards--auto&#34; id=&#34;td-cards-b3843302-0&#34;&gt;&#xA;&#xA;&lt;article id=&#34;td-card-b3843302-cards-0-0&#34; class=&#34;td-content-card&#34;&gt;&#xA;&lt;div class=&#34;td-content-card__body&#34;&gt;&#xA;&lt;div class=&#34;td-content-card__head&#34;&gt;&lt;a class=&#34;td-content-card__title&#34; href=&#34;https://sow.pgsty.com/docs/tutorial/yum-repo/&#34;&gt;Build a YUM Repository&lt;/a&gt;&lt;/div&gt;&#xA;&lt;div class=&#34;td-content-card__description&#34;&gt;&lt;p&gt;A managed RPM repository with per-architecture views, &lt;code&gt;noarch&lt;/code&gt; projection, debuginfo filtering,&#xA;version limits, and a working &lt;code&gt;dnf&lt;/code&gt; client configuration.&lt;/p&gt;&#xA;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;/article&gt;&#xA;&lt;article id=&#34;td-card-b3843302-cards-0-1&#34; class=&#34;td-content-card&#34;&gt;&#xA;&lt;div class=&#34;td-content-card__body&#34;&gt;&#xA;&lt;div class=&#34;td-content-card__head&#34;&gt;&lt;a class=&#34;td-content-card__title&#34; href=&#34;https://sow.pgsty.com/docs/tutorial/apt-repo/&#34;&gt;Build an APT Repository&lt;/a&gt;&lt;/div&gt;&#xA;&lt;div class=&#34;td-content-card__description&#34;&gt;&lt;p&gt;A managed DEB repository with a Debian-style pool, &lt;code&gt;by-hash&lt;/code&gt; indexes, and a deb822 client&#xA;configuration.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Features</title>
        <link>https://sow.pgsty.com/docs/feature/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/feature/</guid>
        <description>&lt;p&gt;SOW has two isolated execution paths. Plain mode is a stateless rebuild of one directory;&#xA;Managed mode records package membership and immutable repository generations in a workspace.&#xA;Neither path silently adopts state from the other.&lt;/p&gt;&#xA;&lt;h2 id=&#34;capability-matrix&#34;&gt;Capability matrix&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Capability&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34; style=&#34;text-align: right&#34;&gt;Plain&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34; style=&#34;text-align: right&#34;&gt;Managed&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;RPM and DEB metadata&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Mixed RPM + DEB operation&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;one directory&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;one Repository, separate Dists&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Persistent membership and generations&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Per-architecture views and neutral packages&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;exclude&lt;/code&gt; and version &lt;code&gt;limit&lt;/code&gt; policy&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Metadata signing&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;RPM and DEB&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;RPM package signing&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;&lt;code&gt;--sign-with&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;&lt;code&gt;never&lt;/code&gt;, &lt;code&gt;fill&lt;/code&gt;, &lt;code&gt;always&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Transaction journal and recovery&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;rerun &lt;code&gt;create&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;workspace, Repository, publication&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Queryable operation log and JSONL export&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Publication targets&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;no&lt;/td&gt;&#xA;      &lt;td style=&#34;text-align: right&#34;&gt;filesystem and R2&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;SOW parses packages and renders metadata in-process. It does not invoke&#xA;&lt;code&gt;createrepo_c&lt;/code&gt;, &lt;code&gt;dpkg-scanpackages&lt;/code&gt;, &lt;code&gt;reprepro&lt;/code&gt;, or &lt;code&gt;modifyrepo_c&lt;/code&gt;. RPM package signing&#xA;is the exception: it needs the host &lt;code&gt;rpm&lt;/code&gt; command and GPG environment because it rewrites&#xA;package payloads.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Sign Your Repository</title>
        <link>https://sow.pgsty.com/docs/tutorial/signing/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/tutorial/signing/</guid>
        <description>&lt;p&gt;SOW has two independent signing paths:&lt;/p&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Path&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Output&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Client control&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;RPM metadata&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;repodata/repomd.xml.asc&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;repo_gpgcheck=1&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;APT metadata&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;InRelease&lt;/code&gt; and &lt;code&gt;Release.gpg&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;Signed-By&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;RPM package body&lt;/td&gt;&#xA;      &lt;td&gt;embedded RPM signature&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;gpgcheck=1&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;APT trusts package hashes through the signed &lt;code&gt;Release&lt;/code&gt;; SOW does not re-sign DEB package&#xA;bodies. Start with metadata signing. Add RPM package signing only when you own the signing&#xA;policy for those package bytes.&lt;/p&gt;&#xA;&lt;h2 id=&#34;1-create-a-dedicated-key&#34;&gt;1. Create a dedicated key&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The commands below create an unencrypted example key. Use a protected key and a&#xA;&lt;code&gt;passphrase&lt;/code&gt; reference for production; see the &lt;a href=&#34;https://sow.pgsty.com/docs/reference/config/#passphrase-references&#34;&gt;configuration reference&lt;/a&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Signing Model</title>
        <link>https://sow.pgsty.com/docs/feature/signing/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/feature/signing/</guid>
        <description>&lt;p&gt;There are two different questions a client can ask about a repository, and SOW answers them with two separate mechanisms. Confusing them is the most common source of &amp;ldquo;I signed it but &lt;code&gt;dnf&lt;/code&gt; still complains&amp;rdquo;, so this page starts by pulling them apart.&lt;/p&gt;&#xA;&lt;h2 id=&#34;two-independent-trust-chains&#34;&gt;Two independent trust chains&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Metadata signing&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;RPM package signing&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Question answered&lt;/td&gt;&#xA;      &lt;td&gt;&amp;ldquo;Is this index really from you, and unmodified?&amp;rdquo;&lt;/td&gt;&#xA;      &lt;td&gt;&amp;ldquo;Is this &lt;code&gt;.rpm&lt;/code&gt; file really from you?&amp;rdquo;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Configured by&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;signing.rpm.metadata&lt;/code&gt;, &lt;code&gt;signing.deb.metadata&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;signing.rpm.packages&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Produces&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;repodata/repomd.xml.asc&lt;/code&gt;, &lt;code&gt;InRelease&lt;/code&gt;, &lt;code&gt;Release.gpg&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;an OpenPGP signature embedded in the package&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Changes package bytes&lt;/td&gt;&#xA;      &lt;td&gt;no&lt;/td&gt;&#xA;      &lt;td&gt;yes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Client setting&lt;/td&gt;&#xA;      &lt;td&gt;dnf &lt;code&gt;repo_gpgcheck=1&lt;/code&gt;, apt &lt;code&gt;Signed-By&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;dnf &lt;code&gt;gpgcheck=1&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Available in Plain mode&lt;/td&gt;&#xA;      &lt;td&gt;no&lt;/td&gt;&#xA;      &lt;td&gt;yes, via &lt;code&gt;create -S KEY&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;They are configured separately and can be used separately. Metadata signing alone is usually the right starting point: it authenticates the whole index in one place and requires no change to the packages you received from upstream.&lt;/p&gt;</description>
      </item>
    <item>
        <title>sow show</title>
        <link>https://sow.pgsty.com/docs/command/show/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/command/show/</guid>
        <description>&lt;p&gt;&lt;code&gt;sow show&lt;/code&gt; resolves one package reference in the selected Repository and prints the complete Package&#xA;Object. It is read-only and takes no write lock.&lt;/p&gt;&#xA;&lt;h2 id=&#34;synopsis&#34;&gt;Synopsis&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-9d3997e0-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;text&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-9d3997e0-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sow show PACKAGE [-C|--workdir DIR] [-r|--repo NAME] [-d|--dist NAME]... [--json]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Flag&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Meaning&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Default&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-C, --workdir DIR&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Workspace discovery start directory&lt;/td&gt;&#xA;      &lt;td&gt;current directory&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-r, --repo NAME&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Select a Repository&lt;/td&gt;&#xA;      &lt;td&gt;&lt;a href=&#34;https://sow.pgsty.com/docs/command/#repository-selection&#34;&gt;selection rules&lt;/a&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-d, --dist NAME&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Narrow candidates to these Dists; repeatable&lt;/td&gt;&#xA;      &lt;td&gt;Repository scope&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;--json&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Wrap the result in the &lt;code&gt;sow.cli/v1&lt;/code&gt; envelope&lt;/td&gt;&#xA;      &lt;td&gt;false&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h2 id=&#34;package-reference&#34;&gt;Package reference&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;PACKAGE&lt;/code&gt; accepts a &lt;code&gt;sha256:&amp;lt;hex&amp;gt;&lt;/code&gt; content identity, canonical &lt;code&gt;rpm:&amp;lt;NEVRA&amp;gt;&lt;/code&gt; or&#xA;&lt;code&gt;deb:&amp;lt;name&amp;gt;=&amp;lt;version&amp;gt;:&amp;lt;arch&amp;gt;&lt;/code&gt; coordinate, full package filename, or bare binary name. See&#xA;&lt;a href=&#34;https://sow.pgsty.com/docs/reference/package-ref/&#34;&gt;Package References&lt;/a&gt; for the exact grammar.&lt;/p&gt;</description>
      </item>
    <item>
        <title>sow check</title>
        <link>https://sow.pgsty.com/docs/command/check/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://sow.pgsty.com/docs/command/check/</guid>
        <description>&lt;p&gt;&lt;code&gt;sow check&lt;/code&gt; is the deep read-only gate for a managed Repository. It hashes bytes, validates state,&#xA;reconstructs expected views, and verifies declared signatures. It never repairs, builds, recovers an&#xA;Operation, or takes the write lock.&lt;/p&gt;&#xA;&lt;h2 id=&#34;synopsis&#34;&gt;Synopsis&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-e118a099-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;text&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-e118a099-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sow check [-j|--jobs N] [-C|--workdir DIR] [-r|--repo NAME] [-d|--dist NAME]... [--json]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Flag&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Meaning&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Default&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-j, --jobs N&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Parallel verification workers; at least &lt;code&gt;1&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;logical CPU count&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-C, --workdir DIR&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Workspace discovery start directory&lt;/td&gt;&#xA;      &lt;td&gt;current directory&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-r, --repo NAME&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Select a Repository&lt;/td&gt;&#xA;      &lt;td&gt;&lt;a href=&#34;https://sow.pgsty.com/docs/command/#repository-selection&#34;&gt;selection rules&lt;/a&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;-d, --dist NAME&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Verify named Dists; repeatable&lt;/td&gt;&#xA;      &lt;td&gt;all Dists&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;--json&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;Emit the &lt;code&gt;sow.cli/v1&lt;/code&gt; envelope&lt;/td&gt;&#xA;      &lt;td&gt;false&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h2 id=&#34;verification-layers&#34;&gt;Verification layers&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;In steady state, the checker reports nine ordered layers:&lt;/p&gt;</description>
      </item>
    
  </channel>
</rss>
