Download
Official Apache source releases
The official distribution channel for Apache Reqsign™ is the source release published through the ASF mirror system. Each release ships a source archive with a PGP signature and SHA-512 checksum:
- Download source releases — via the ASF mirror resolver.
- KEYS — release managers' public signing keys.
Verifying a release
# Import the release signing keys once:
curl -O https://downloads.apache.org/reqsign/KEYS
gpg --import KEYS
# Verify the signature and checksum of a downloaded artifact:
gpg --verify apache-reqsign-X.Y.Z-src.tar.gz.asc
sha512sum -c apache-reqsign-X.Y.Z-src.tar.gz.sha512
See the ASF release verification guide for details on why and how to verify.
Rust convenience packages
For day-to-day Rust development, releases are also published to crates.io. These packages are a convenience distribution built from the official source release — they do not replace it:
cargo add reqsign --features aws
reqsignon crates.io — the facade crate; see Installation for features.- Individual service crates (
reqsign-core,reqsign-aws-v4, ...) are linked from the API reference.
Release notes
Release notes for every version are published with the GitHub releases.
Historical releases
Older releases move out of the mirror system and remain permanently available in the Apache archive. Use the latest release unless you have a specific reason not to.