Skip to content

Authoritative source for SHASUMS256.txt filename policy and generator revision for Node.js v26.5.0 #1170

Description

@Intelminder

Hello Node.js Release team,

I am documenting the provenance and validation policy for the official Node.js v26.5.0 checksum manifest. Could a releaser or release-infrastructure maintainer identify the authoritative, immutable sources for the following?

  1. Which release-infrastructure component generated SHASUMS256.txt for Node.js v26.5.0?
  2. What immutable repository commit, workflow revision, image identity, or equivalent release-infrastructure identity was used?
  3. What filename grammar does that generator intentionally emit?
  4. Are relative-path filename forms intentionally supported, or are entries required to be basenames?
  5. Which immutable revision of the official Node.js release-signing key set was applicable when v26.5.0 was released?
  6. Which official documentation or immutable source supports each answer?

For an answer to be usable as provenance evidence, please provide immutable links or identifiers tied specifically to v26.5.0 where available. If the relevant generator is private or its exact release-time revision cannot be established, confirmation of that limitation would also be useful.

This is a general release-process question. No manifest entry, checksum, filename, or private diagnostic information is being requested or disclosed.

Thank you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions