Skip to content

Commit

Permalink
doc: Add download page (apache#219)
Browse files Browse the repository at this point in the history
* doc: Add download page

* Fix links
  • Loading branch information
liurenjie1024 authored and shaeqahmed committed Dec 9, 2024
1 parent b33d3fd commit 2b8d1b5
Showing 1 changed file with 42 additions and 0 deletions.
42 changes: 42 additions & 0 deletions website/src/download.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,45 @@
~ under the License.
-->

# Apache Iceberg™ Rust Downloads

The official Apache Iceberg-Rust releases are provided as source artifacts.

## Releases

The latest source release is [0.2.0](https://www.apache.org/dyn/closer.lua/iceberg/iceberg-rust-0.2.0/apache-iceberg-rust-0.2.0-src.tar.gz?action=download) ([asc](https://downloads.apache.org/iceberg/iceberg-rust-0.2.0/apache-iceberg-rust-0.2.0-src.tar.gz.asc),
[sha512](https://downloads.apache.org/iceberg/iceberg-rust-0.2.0/apache-iceberg-rust-0.2.0-src.tar.gz.sha512)).

For older releases, please check the [archive](https://archive.apache.org/dist/iceberg/).

## Notes

* When downloading a release, please verify the OpenPGP compatible signature (or failing that, check the SHA-512); these should be fetched from the main Apache site.
* The KEYS file contains the public keys used for signing release. It is recommended that (when possible) a web of trust is used to confirm the identity of these keys.
* Please download the [KEYS](https://downloads.apache.org/iceberg/KEYS) as well as the .asc signature files.

### To verify the signature of the release artifact

You will need to download both the release artifact and the .asc signature file for that artifact. Then verify the signature by:

* Download the KEYS file and the .asc signature files for the relevant release artifacts.
* Import the KEYS file to your GPG keyring:

```shell
gpg --import KEYS
```

* Verify the signature of the release artifact using the following command:

```shell
gpg --verify <artifact>.asc <artifact>
```

### To verify the checksum of the release artifact

You will need to download both the release artifact and the .sha512 checksum file for that artifact. Then verify the checksum by:

```shell
shasum -a 512 -c <artifact>.sha512
```

0 comments on commit 2b8d1b5

Please sign in to comment.