Signing, authentication and telemetry notes for gitaiflow.
SHA-256 checksum manifest (SHA256SUMS) and an Ed25519 signature over it (SHA256SUMS.sig). Checksum verification is mandatory in every installer; signature verification is best-effort in install.sh (needs OpenSSL 3.2+), not attempted in install.ps1, and mandatory on the MCP path.streamable HTTP and validates requested repositories against its configured workspace allow-list.change-summary/, CHANGELOG.md, RELEASE_NOTES.md) and local state under ~/.gitaiflow. Keep MCP_ALLOWED_WORKSPACES as narrow as you can, and review generated AI output before sharing it outside your team.| File | OS | Architecture |
|---|---|---|
| gitaiflow-darwin-arm64 | macOS (Apple Silicon: M1, M2, M3, M4) | arm64 |
| gitaiflow-linux-amd64 | Linux (Ubuntu, Debian, RedHat, standard cloud VMs) | x86_64 |
| gitaiflow-linux-arm64 | Linux (AWS Graviton, Raspberry Pi, Apple Silicon Docker) | aarch64 / arm64 |
| gitaiflow-windows-amd64.exe | Windows 10, 11, Server | x86_64 |