Skip to main content

add_verify_hash

Function add_verify_hash 

Source
pub fn add_verify_hash(lua: &Lua, quiet: bool) -> Result<(), Error>
Expand description

Exposes cryptographic utilities to the Lua environment.

These functions allow package scripts to perform security validations:

  • verifyHash: Checks a file’s SHA-256 or SHA-512 integrity.
  • verifySignature: Validates a detached PGP signature using a local or remote key.
  • addPgpKey: Dynamically imports a trusted PGP key into the Zoi keyring.

This provides the “Chain of Trust” within the package build process, ensuring that downloaded assets have not been tampered with.