mix mob.plugin.sign (mob_dev v0.7.2)

Copy Markdown View Source

Signs the plugin in <dir> (default: cwd) and writes priv/mob_plugin.sig. The signature covers the SHA-256 hashes of priv/mob_plugin.exs and every source file the manifest references — the manifest bytes are one of those files, so tampering with the manifest fails verification. The v2 envelope on disk carries the signed file_hashes list so MobDev.Plugin.Verify.verify_plugin/1 can check integrity without ever Code.eval_file-ing the manifest (see MOB-74).

mix mob.plugin.sign [--plugin <dir>]

Reads the private key for the plugin's :name from ~/.mob/keys/<name>.priv. Run mix mob.plugin.keygen first if you haven't already.

After signing, the printed fingerprint can be shared with host operators so they can run mix mob.plugin.trust <name> to record trust in their mob.exs.