Signs the plugin in <dir> (default: cwd) and writes
priv/mob_plugin.sig. The signature covers the SHA-256 hashes of
priv/mob_plugin.exs and every file the native build reads from the
plugin (MobDev.Plugin.Sign.build_inputs/2, MOB-297) — the manifest
bytes are one of those files, so tampering with the
manifest fails verification. The v2 envelope on disk carries the
signed file_hashes list so MobDev.Plugin.Verify.verify_plugin/1
can check integrity before it ever Code.eval_files the manifest
(see MOB-74).
mix mob.plugin.sign [--plugin <dir>]Reads the private key for the plugin's :name from
~/.mob/keys/<name>.priv. Run mix mob.plugin.keygen first if you
haven't already.
After signing, the printed fingerprint can be shared with host
operators so they can run mix mob.plugin.trust <name> to record
trust in their mob.exs.