Follow these steps to verify the PGP signature:
-
Install the npm pkgsign.
-
Get the version of tronbox dist.tarball
$ npm view tronbox dist.tarball
https://registry.npmjs.org/tronbox/-/tronbox-2.7.25.tgz
- Get the tarball
wget https://registry.npmjs.org/tronbox/-/tronbox-2.7.25.tgz
- Verify the tarball
$ pkgsign verify tronbox-2.7.25.tgz --package-name tronbox
extracting unsigned tarball...
building file list...
verifying package...
package is trusted
You can find the signature public key here.
0.4.24
0.4.25
0.5.4
0.5.8
0.5.9
0.5.10
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.6.0
0.6.2
0.6.8
0.6.12
0.6.13
0.7.0
0.7.6
0.7.7
0.8.0
0.8.6
0.8.7
0.8.11
0.8.18
0.8.20
For more versions details: https://github.com/tronprotocol/solidity/releases