Verify TunaOS Downloads and Images
TunaOS gives you several ways to check what you downloaded. This guide covers checksums, Software Bills of Materials (SBOMs), and Cosign signatures. It applies to ISO downloads, container images, and package repositories.
1. Verify ISO Checksums (SHA-256)β
Not every ISO category on the download server publishes a checksum file today. The download page shows a checksums link for each category that has one, and no link for a category that does not. The tacklebox category is the one that publishes checksums now; the main live-isos lineup does not yet.
Where no checksum file exists, the strongest check available is the Cosign signature on the container image the ISO was built from. See section 2.
Verify on Linux and macOSβ
-
Open the download page, then select the checksums link for the category you downloaded from. That link gives you the exact file to fetch. Its name carries a date and a build hash:
curl -O https://download.tunaos.org/tacklebox/bazzite-gnome-latest.isocurl -O https://download.tunaos.org/tacklebox/bazzite-gnome-SHA256SUMS-20260902-b37b7a2 -
Check the ISO against the list:
sha256sum -c bazzite-gnome-SHA256SUMS-20260902-b37b7a2 --ignore-missingA good file gives you this output:
bazzite-gnome-latest.iso: OK -
To print the hash and compare it yourself:
sha256sum bazzite-gnome-latest.iso
Verify on Windows (PowerShell)β
Run Get-FileHash in PowerShell:
Get-FileHash .\albacore-gnome-latest.iso -Algorithm SHA256
Compare the printed hash string with the hash in the SHA256SUMS file.
2. Verify Container Image Signatures with Cosignβ
TunaOS signs its container images with Sigstore Cosign. The signatures are keyless: GitHub Actions makes them through OpenID Connect (OIDC).
Install Cosignβ
Install cosign using Homebrew or your package manager:
brew install cosign
Verify Keyless Signaturesβ
To check an official image against the identity that GitHub Actions signs with:
cosign verify \
--certificate-identity-regexp "https://github.com/tuna-os/" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
ghcr.io/tuna-os/albacore:latest
When valid, cosign prints the certificate claims, issuer URL, and confirmation that the signature is valid.
Verify with the Public Keyβ
TunaOS also provides a cosign.pub public key in the root of the tunaOS repository.
To verify with cosign.pub:
# Download the public key
curl -O https://raw.githubusercontent.com/tuna-os/tunaOS/main/cosign.pub
# Verify the container image
cosign verify --key cosign.pub ghcr.io/tuna-os/albacore:latest
Verify Repository Metadata Signatures (Cloudflare R2)β
TunaOS hosts its RPM and DEB repositories on Cloudflare R2, keyless-signed. You can check a metadata blob such as repomd.xml on its own:
cosign verify-blob \
--key cosign.pub \
--signature repomd.xml.sig \
repomd.xml
3. Inspect Software Bills of Materials (SBOM)β
TunaOS attaches an SPDX / CycloneDX SBOM to container images during the build workflow. You can inspect the list of included packages and dependencies or scan for vulnerabilities.
Download the Image SBOMβ
Use cosign to download the embedded SBOM:
cosign download sbom ghcr.io/tuna-os/albacore:latest > albacore-sbom.json
Inspect Packages with Syftβ
Use Syft to inspect packages in the image:
# Install syft
brew install syft
# View package list
syft ghcr.io/tuna-os/albacore:latest
Scan for Vulnerabilities with Grypeβ
Use Grype to scan the downloaded SBOM or container image:
# Install grype
brew install grype
# Scan the SBOM file
grype sbom:albacore-sbom.json
# Or scan the container image directly
grype ghcr.io/tuna-os/albacore:latest
4. Secure Boot and UEFI Validationβ
The official base images use signed shim loaders and kernels. The signature comes from the Microsoft UEFI CA, or from an upstream distribution key (AlmaLinux, Red Hat, Canonical, Debian).
To check Secure Boot status and enroll MOK keys on installed systems, see the Secure Boot & UEFI Guide.