Citrine

com.greenart7c3.citrine
by greenart7c3

Citrine is a nostr relay for android. It allows any nostr client that supports Android to send and receive events from this application.

First release: Aug 18, 2025, 11 total releases.

Most recent release: Sep 18, 2026.

Repo

Appears in 23 app stacks.

34,465 sats / 19 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Sep 18, 2026 3.2.0
    ## Citrine 3.2.0 - Fixed silent crashes (OOM) with the relay aggregator enabled: REQ queries now stream results in batches instead of materializing the full match set in memory - Bounded relay aggregator memory: capped outbound relays at 200 and bounded caches - Added an option to hide the graph in the show events page - Out-of-memory errors are now logged to the in-app log screen so they can be diagnosed - Updated dependencies (including Quartz 1.15.2) - Updated translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.citrine), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page
    More…
    ](https://github.com/greenart7c3/Citrine/releases/tag/v3.2.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v3.2.0.txt` and `manifest-v3.2.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v3.2.0.txt.sig manifest-v3.2.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v3.2.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Sep 11, 2026 3.1.1
    ## Citrine 3.1.1 - Fixed an NIP-42 auth bypass where kind-22242 AUTH events were added to the connection without signature verification - Scoped REQ subscription ids per connection so a duplicate id from one socket can no longer clobber another's subscription - NIP-45: COUNT filters now aggregate into a single count response without EOSE and no longer register live subscriptions - Fixed NIP-42 access control denying authenticated users filtering kinds-less {"#p":[<own pubkey>]} - Replaceable events now tie-break on the lowest id at equal created_at (NIP-01) - ids and authors filters are now exact 64-hex matches (NIP-01) - Standardized OK message prefixes for duplicate, deleted, and blocked events (NIP-01/09) - NIP-11: relay info document is now built quote-safe and advertises Access-Control-Allow-Headers; dropped deprecated NIP-04
    More…
    - NIP-86: added unbanpubkey and unallowpubkey; allowpubkey no longer unbans as a side effect Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.citrine), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v3.1.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v3.1.1.txt` and `manifest-v3.1.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v3.1.1.txt.sig manifest-v3.1.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v3.1.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Aug 14, 2026 3.1.0
    ## Citrine 3.1.0 - Added NIP-29 relay-based groups support - Added NIP-86 relay management API and settings screen - Added a tool to rebroadcast stored events to selected relays - Offer to purge stored events when banning a pubkey locally - Added configurable REJECTED_KINDS to block non-publishable artifact kinds - Added import-from-lists picker to access control settings - Added nsite (NIP-5A) support to Web Clients - Modernized the browse nsites list: website icons, search bar, sort by last update, and install progress
    More…
    - Added a setting to choose relays for fetching nsites, with dedicated defaults (nsite.run, nos.lol, nostr.land) - Show nsite description and restyle nsite lists as cards with an author header - Performance improvements on the WebSocket and REQ query hot paths - Removed permessage-deflate extension from the WebSocket server - Fixed Tor not starting/stopping when the expose-via-Tor setting changes - Always stop Tor when the relay service is destroyed - Show the home screen without waiting for the service to bind - Subscribe to all kinds when the aggregator kinds list is empty - Move the aggregator kinds reset button below the text field - Persist logs to a local database and gate logcat to debug builds - Updated Gradle, Kotlin, and project dependencies - Updated translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.citrine), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v3.1.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v3.1.0.txt` and `manifest-v3.1.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v3.1.0.txt.sig manifest-v3.1.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v3.1.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Jun 19, 2026 3.0.1
    ## Citrine 3.0.1 - Fixed a crash when unregistering an unregistered Pokey receiver Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.citrine), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v3.0.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release
    More…
    In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v3.0.1.txt` and `manifest-v3.0.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v3.0.1.txt.sig manifest-v3.0.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v3.0.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Jun 16, 2026 3.0.0
    ## Citrine 3.0.0 - Added Negentropy (NIP-77) support - Added external signer and NIP-42 AUTH support to the relay aggregator - Honor NIP-51 mute lists in the relay aggregator - Cap the relay aggregator at 3 relays per author with configurable source and indexer relays - Reuse cached follow/mute/metadata on aggregator restart and network change - Pause the relay aggregator on limited/restricted networks - Filter onion relay URLs from the aggregator when the outbound proxy is disabled - Reject reposts that embed protected events
    More…
    - Show local, Wi-Fi, and Tor addresses with copy actions on the home screen - Redesigned settings screen split into a hub with category sub-screens - Preserve mute lists from age-based deletion by default - Added option to preserve specific event kinds from age-based deletion - Made the ephemeral mute response a setting, defaulting to off - Reduced relay aggregator battery drain - Performance improvements on the relay hot path and event-receive path - Fixed WebSocket connections that sometimes don't close - Skip duplicate foreground service notifications - Dedupe AUTH challenges so external signers are not re-prompted - Updated Gradle and refreshed library dependencies - Updated translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.citrine), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v3.0.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v3.0.0.txt` and `manifest-v3.0.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v3.0.0.txt.sig manifest-v3.0.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v3.0.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Mar 11, 2026 2.0.0 Release page →
    ## Citrine 2.0.0-pre2 - Improve the relay performance by changing the indexes, database queries and how the kotlin coroutines run - Better performance when hosting web apps - Start each web app in their own port - Better interface for the events screen - Updated dependencies - Use FTS for search queries - Support for expanding the event in the event screen - Option for downloading tagged events
    More…
    Download it with [Zapstore](https://zapstore.dev/apps/naddr1qvzqqqr7pvpzqateqake4lc2fn77lflzq30jfpk8uhvtccalc66989er8cdmljceqqtkxmmd9enhyet9deshyaphvvejucmfw3exjmn9hzj8uf), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v2.0.0-pre2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v2.0.0-pre2.txt` and `manifest-v2.0.0-pre2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v2.0.0-pre2.txt.sig manifest-v2.0.0-pre2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v2.0.0-pre2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Jan 21, 2026 v1.0.2 Release page →
    ## Citrine 1.0.2 - Fix a crash when trying to restore follows Download it with [zap.store](https://zap.store/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v1.0.2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release
    More…
    In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v1.0.2.txt` and `manifest-v1.0.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v1.0.2.txt.sig manifest-v1.0.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v1.0.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Jan 16, 2026 v1.0.1 Release page →
    ## Citrine 1.0.1 - Performance improvements in content resolver by @npub1kpv7arjpaa3f37x9m9cu6sk9weeykt84kcrkd070m4amcmuk0r8sk74mkw - Fix SQL injection by @npub1kpv7arjpaa3f37x9m9cu6sk9weeykt84kcrkd070m4amcmuk0r8sk74mkw - Proper error handling in content resolver by @npub1kpv7arjpaa3f37x9m9cu6sk9weeykt84kcrkd070m4amcmuk0r8sk74mkw Download it with [zap.store](https://zap.store/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v1.0.1) If you like my work consider making a [donation](https://greenart7c3.com)
    More…
    ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v1.0.1.txt` and `manifest-v1.0.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v1.0.1.txt.sig manifest-v1.0.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v1.0.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Jan 6, 2026 v1.0.0 Release page →
    ## Citrine 1.0.0 - Added crash report handler - Support for content resolver by @npub1kpv7arjpaa3f37x9m9cu6sk9weeykt84kcrkd070m4amcmuk0r8sk74mkw - Broadcast events to relays when back online by @npub1kpv7arjpaa3f37x9m9cu6sk9weeykt84kcrkd070m4amcmuk0r8sk74mkw - Added some missing string resources from settings screen - Host web apps - Better performance when loading the kind field Download it with [zap.store](https://zap.store/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page
    More…
    ](https://github.com/greenart7c3/Citrine/releases/tag/v1.0.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v1.0.0.txt` and `manifest-v1.0.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v1.0.0.txt.sig manifest-v1.0.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v1.0.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Nov 17, 2025 v0.9.0 Release page →
    ## Citrine 0.9.0 - Migrate to new quartz version - Add proxy to the settings screen - Add backup setup in the settings screen - Keep the last 5 backups - Update dependencies - Fix import and export Download it with [zap.store](https://zap.store/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page
    More…
    ](https://github.com/greenart7c3/Citrine/releases/tag/v0.9.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v0.9.0.txt` and `manifest-v0.9.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v0.9.0.txt.sig manifest-v0.9.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v0.9.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
  • Aug 18, 2025 v0.8.2 Release page →
    ## Citrine 0.8.2 - Close connections when it’s sending invalid frames - Better handling of disconnections - refactors how WebSocket connections and subscriptions are managed - Support for mute - Always accepts ephemeral events - Fix auth command results by @npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6 - Make protected events readable by anyone by @npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6 - Fix EOSE message by @npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6
    More…
    - Allow localhost access to bypass nip 70 checks by @npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6 - Dispatch events to subscriptions from the same connection it came from by @npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6 Download it with [zap.store](https://zap.store/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.citrine) or download it directly in the [releases page ](https://github.com/greenart7c3/Citrine/releases/tag/v0.8.2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v0.8.2.txt` and `manifest-v0.8.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v0.8.2.txt.sig manifest-v0.8.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v0.8.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.