Rule Cascade
Get started

Download and verify

Install the rcas command or its WebAssembly module from rulescascade.com, after checking its SHA-256 checksum and its Sigstore signature.

The rcas command is one static binary with no dependencies, for Linux, macOS and Windows on x86-64 and ARM64. rcas.wasm is the same command for any WASI preview 1 host. Each version is built and signed by the project's release workflow from a release tag, and served from this site:

PathWhat it holdsCached
/download/<version>/One version, for good. Its files never changeone year, immutable
/download/latest/A copy of the newest version, and VERSION, its numberfive minutes

Latest: 1.0.0-alpha.5. Every file has a Sigstore bundle beside it (<file>.sigstore.json), and SHA256SUMS lists the checksums of all of them.

PlatformFileSignature
Linux, x86-64rcas-linux-amd64bundle
Linux, ARM64rcas-linux-arm64bundle
macOS, Intelrcas-darwin-amd64bundle
macOS, Apple siliconrcas-darwin-arm64bundle
Windows, x86-64rcas-windows-amd64.exebundle
Windows, ARM64rcas-windows-arm64.exebundle
WebAssembly (WASI preview 1)rcas.wasmbundle
ChecksumsSHA256SUMSbundle

All versions: 1.0.0-alpha.5, 1.0.0-alpha.4. The SHA-256 of each version's SHA256SUMS is pinned in the site's source, and the build refuses files that do not match it or whose signature does not verify.

How the checks fit together

Two checks, and you need both. The checksum proves the file is the one listed in SHA256SUMS. The signature proves SHA256SUMS, and each file, were signed by the project's release workflow from a release tag: the signing certificate is issued by Sigstore to that workflow's GitHub Actions identity, and the signature is recorded in Sigstore's public transparency log.

Diagram, described in Mermaid: flowchart LR T[Release tag] --> W[Release workflow builds 7 files and SHA256SUMS] W --> K[Sigstore signs each file with the workflow identity] K --> P[Files and .sigstore.json bundles published here] P --> D[You download a file, its bundle and SHA256SUMS] D --> C{SHA-256 matches SHA256SUMS?} C -- no --> X[Delete it] C -- yes --> V{cosign verify-blob passes?} V -- no --> X V -- yes --> I[Install and run rcas version]

You need cosign 3.0 or later for the signature (the bundles are Sigstore bundle format v0.3, which cosign 3 verifies by default). The commands download into the current directory and never run anything they have not verified. For a one-line install that performs the same checks, see Install.

Choose the version and your file

VERSION=$(curl -fsSL https://rulescascade.com/download/latest/VERSION)
FILE=rcas-linux-amd64     # or -linux-arm64, -darwin-amd64, -darwin-arm64, rcas.wasm
BASE=https://rulescascade.com/download/$VERSION
echo "$VERSION $FILE"

Pin VERSION to a number instead of latest in a build script, so the build gets the same bytes every time.

Download the file, its signature bundle and the checksums

curl -fsSL --remote-name-all \
  "$BASE/$FILE" "$BASE/$FILE.sigstore.json" "$BASE/SHA256SUMS" "$BASE/SHA256SUMS.sigstore.json"

Done when four files are in the directory: the binary, its .sigstore.json, SHA256SUMS and SHA256SUMS.sigstore.json.

Check the checksum

grep "  $FILE\$" SHA256SUMS | shasum -a 256 -c -
rcas-linux-amd64: OK

Done when it prints OK. Anything else: delete the file and download it again.

Verify the signatures

Verify SHA256SUMS and the file against the release workflow's identity. The identity is a regular expression: the release workflow of the project, run from a v tag; the issuer is GitHub Actions.

IDENTITY='^https://github\.com/YarlisAISolutions/rule-cascade/\.github/workflows/release\.yml@refs/tags/v'
ISSUER=https://token.actions.githubusercontent.com
for f in SHA256SUMS "$FILE"; do
  cosign verify-blob "$f" --bundle "$f.sigstore.json" \
    --certificate-identity-regexp "$IDENTITY" --certificate-oidc-issuer "$ISSUER" || break
done
Verified OK
Verified OK

Done when both print Verified OK. If either fails, do not run the file.

Install it and run it

chmod +x "$FILE"
sudo install -m 0755 "$FILE" /usr/local/bin/rule-cascade    # or any directory on your PATH
rcas version

For the module, run it with a WASI host instead, for example wasmtime rcas.wasm version.

rcas 1.0.0-alpha.5 (specification 1.0.0, bundle format 1.0.0)

Done when rcas version prints the version you downloaded. Next: the 5-minute quickstart.

In CI

Run the same four steps with VERSION pinned, and fail the job when any of them fails. Keep the downloaded files: the bundle is the evidence of what you installed.

On this page