OTB Works release feed
The public record of every OTB Works release. Machine readable, signed, and safe to copy or archive.
Files
- index.json Every published release, listed by channel.
- update-bundle.json All of the files below in one download, for an instance with no internet access.
- keys.json The release signing keys, vouched for by the offline root key.
- revocations.json Releases and licences that Outside The Box has withdrawn.
- releases/<version>/manifest.json One signed manifest per release: image digest, SBOM digest, schema range and build inputs.
You do not have to trust this server
Every file here is signed. An OTB Works instance checks the whole chain offline, against a root public key built into its own image, before it acts on anything it reads.
Whoever controls this web server can withhold a file or serve an older copy of one. They cannot forge a release, alter an image digest, or make a withdrawn version look current. That is why the feed is ordinary static hosting, and why mirroring it or carrying it on a USB stick is just as safe.
Privacy
This site sets no cookies and uses no analytics or tracking of any kind. Requests are served by Azure Static Web Apps, which records standard web server information: the IP address the request came from, the time, the file requested, and the user agent. That data is used to run and secure the service, and for nothing else.
An OTB Works instance that reads this feed sends nothing about itself. There is no instance identifier, licence detail, version, usage data or credential in the request. If you would rather your instance made no request at all, the update check can be turned off, and the files above can be downloaded on another machine and uploaded to it instead.
Questions about this notice: privacy@outsidethebox.io.