Releases
Native artifacts
Section titled “Native artifacts”Dovik 1.1.0 publishes these archives:
dovik-v1.1.0-windows-x64.zipdovik-v1.1.0-linux-x64.tar.gzdovik-v1.1.0-macos-x64.tar.gzdovik-v1.1.0-macos-arm64.tar.gz
Every native archive has an adjacent .sha256 file. Verify the checksum before extraction, then confirm:
dovik --versiondovikd --versiondovik --helpdovikd --helpFor 1.1.0, both version commands must report 1.1.0. Linux and macOS binaries must retain executable permissions.
GitHub build provenance attestations cover the release archives and checksums. The release workflow rebuilds on matching native runners from the tagged revision and verifies the unpacked file set outside the checkout.
With GitHub CLI installed, verify downloaded release files with:
gh attestation verify dovik-v1.1.0-windows-x64.zip --repo MrMaxie/dovikUse sha256sum -c FILE.sha256 on Linux or macOS. On Windows, compare Get-FileHash FILE -Algorithm SHA256 with the value in the adjacent checksum file.
npm packages
Section titled “npm packages”The dovik package installs the command shims and selects the matching optional native package for Windows x64, Linux x64, macOS x64, or macOS arm64. Every npm version is assembled from the already published and attested GitHub Release archives.
The Scoop manifest and GHCR image published with 1.0.0 remain available as historical artifacts. New releases are distributed only through GitHub Release archives and npm.
Signing limitations
Section titled “Signing limitations”Dovik 1.1.0 does not provide Authenticode signing or macOS notarization. It also does not ship installers, Homebrew, Winget, Scoop, container images, Linux arm64, or Windows arm64 packages.