# Verified 2026-09-18 against the real repo: anthropics/claude-code does not # publish GitHub build-provenance attestations (the attestations API 404s # for a fresh release asset) — tier 4, same-origin checksum only, not tier # 2. Motivation: track the fast-moving Claude Code CLI directly from # upstream releases rather than npm/curl|sh. # # Releases ship a combined `SHASUMS256.txt` (one line per platform asset, # same ` ` shape as scaleway-cli's `SHA256SUMS`) plus a # detached `SHASUMS256.txt.sig` PGP signature over that checksum file — # stronger than plain same-origin-sha256 (closer to tier 1, pinned-key # signature) but pkgwatch doesn't implement PGP/minisign verification yet # (see SPEC.md > Status: tier-1 `minisign` method not yet implemented). # Revisit and upgrade this package's tier once that lands. # # Release tags are static per-platform filenames (no version embedded), so # no `{version}` placeholder is needed, same as uv's config. Tracking the # glibc x86_64 Linux build (`claude-linux-x64.tar.gz`), not the musl # variant, to match this machine. [package.claude-code] repo = "anthropics/claude-code" asset_pattern = "claude-linux-x64.tar.gz" [package.claude-code.verification] method = "same-origin-sha256" checksum_asset_pattern = "SHASUMS256.txt"