0.1.0
all artifacts verified
disttown 0.1.0
First release of disttown, the CLI for publishing releases on your own terms: records in your repo, artifacts on storage you control, everything content-addressed.
Publishing
disttown publishhashes artifacts locally and lands the project record, release, and pointer moves in one atomic commit — a release either fully exists or doesn't.--blobsstores artifact bytes on your own PDS; the default targets any dumb HTTPS bucket you control.- Version strings are opaque and claimed earliest-live-wins: semver, ChronVer, whatever your project speaks.
Storage
disttown storage setupandstorage doctorcheck the things that actually break: anonymous GET, ETag and Content-Length behavior, and a permanent canary round-trip.
Lifecycle
disttown pointer setmoves channels (latest,next, …) atomically.disttown yankwrites a status record and repoints in the same commit — downloads by explicit version keep working, channel resolution refuses.
Trust
- Releases resolve without dist.town in the loop: handle → PDS → records → digest-verified bytes. The AppView is a convenience, never a dependency.
- Checksums come from the publisher-signed release record, so a compromised bucket cannot forge them.
Four platform artifacts ship with this release: linux/amd64, linux/arm64, darwin/amd64, and darwin/arm64 — each digest-pinned in the release record.
Artifacts
- disttown-linux-amd64.tar.gz
sha-256
b1fa644b63ce88066d473d19715be3fa53440b5ace0b1b74a64e00173bc43b07 - disttown-linux-arm64.tar.gz
sha-256
f2311f6a620a4cb981a6d1214c728ea91ee53bfe124fc67c3c52f6c78f5f76c8 - disttown-darwin-amd64.tar.gz
sha-256
1514ebdc67d0470866feb8d20b4831796a172ad096183e3b77feefb8d34d8f89 - disttown-darwin-arm64.tar.gz
sha-256
3ba2105cec10c484203b99c3b74dc5b72a07382c16cdda84ba1ba0dbe4b55b27