Skip to main content

Function: verifyManifestSignatures()

verifyManifestSignatures(info, publicKeys): object

Verifies a manifest against a trust list of Ed25519 public keys. The manifest is accepted when ANY trusted key validates ANY of the signatures it carries (see collectManifestSignatures); this is what lets a release be dual-signed during key rotation and an install trust [old, new].

For each trusted key, signatures tagged with that key's computeUpdateManifestKeyId are tried first, then untagged (legacy signature) entries — so a stale or foreign keyId never prevents a legitimately signed manifest from verifying. Never throws on a bad signature; malformed keys still throw, since that is a configuration error. Returns the id of the trusted key that verified, if any.

Before any signature is tried the manifest must pass validateSignedManifestShape; a manifest that does not is rejected with reason set, regardless of what it is signed with.

Parameters​

info​

UpdateInfo

publicKeys​

(string | KeyObject)[]

Returns​

object

keyId?​

optional keyId?: string

ok​

ok: boolean

reason?​

optional reason?: string