← dashboard

Publish a package

Drop a signed envelope + the blob; this box verifies before storing.

1. Signed metadata envelope (.toml)

The TOML rubixd sign produced — package metadata plus a [publish] block with the signature. The page refuses a bare package TOML with no signature block.

2. Artifact blob

The binary the envelope signs (ELF, docker-archive tarball, …). The same bytes rubixd sign hashed.

Parsed from the envelope

Package
Version
Kind
Signed by
Digest
Blob
Uploading… 0%