A C library for asynchronous DNS requests https://c-ares.org/
  • C 88.9%
  • M4 6%
  • CMake 3.7%
  • Python 0.6%
  • Makefile 0.5%
  • Other 0.3%
Find a file
dependabot[bot] 5b181482e5
ci: bump the github-actions group with 3 updates (#1286)
Bumps the github-actions group with 3 updates:
[poseidon/wait-for-status-checks](https://github.com/poseidon/wait-for-status-checks),
[coverallsapp/github-action](https://github.com/coverallsapp/github-action)
and
[cross-platform-actions/action](https://github.com/cross-platform-actions/action).

Updates `poseidon/wait-for-status-checks` from
9530626e949e682ca077b96f6f2b5c5cdc4bf40d to
71e6db3c30e6925bbc4fd09e3a98b194ec6f7e24
<details>
<summary>Commits</summary>
<ul>
<li><a
href="71e6db3c30"><code>71e6db3</code></a>
Bump npm eslint-plugin-jest from 29.16.5 to v29.16.6</li>
<li><a
href="43d2cff109"><code>43d2cff</code></a>
Bump npm jest from 30.4.2 to v30.5.0 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1066">#1066</a>)</li>
<li><a
href="7b2747d2a5"><code>7b2747d</code></a>
Bump npm eslint-plugin-jest from 29.16.4 to v29.16.5 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1065">#1065</a>)</li>
<li><a
href="c31faf99d6"><code>c31faf9</code></a>
Bump npm eslint-plugin-jest from 29.16.3 to v29.16.4 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1064">#1064</a>)</li>
<li><a
href="609b9c3ebf"><code>609b9c3</code></a>
Bump npm eslint-plugin-jest from 29.16.2 to v29.16.3 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1063">#1063</a>)</li>
<li><a
href="d9b5692fc3"><code>d9b5692</code></a>
Bump npm <code>@​types/node</code> from 26.3.0 to v26.4.0 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1062">#1062</a>)</li>
<li><a
href="cd321f9638"><code>cd321f9</code></a>
Bump npm js-yaml from 5.4.0 to v5.4.1 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1061">#1061</a>)</li>
<li><a
href="1373bfe28b"><code>1373bfe</code></a>
Bump npm eslint-plugin-jest from 29.16.1 to v29.16.2 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1060">#1060</a>)</li>
<li><a
href="a0802a3cac"><code>a0802a3</code></a>
Bump npm js-yaml from 5.3.0 to v5.4.0 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1059">#1059</a>)</li>
<li><a
href="2a1cb33d1b"><code>2a1cb33</code></a>
Bump npm <code>@​types/node</code> from 26.2.0 to v26.3.0 (<a
href="https://redirect.github.com/poseidon/wait-for-status-checks/issues/1058">#1058</a>)</li>
<li>Additional commits viewable in <a
href="9530626e94...71e6db3c30">compare
view</a></li>
</ul>
</details>
<br />

Updates `coverallsapp/github-action` from 2.3.6 to 2.3.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/coverallsapp/github-action/releases">coverallsapp/github-action's
releases</a>.</em></p>
<blockquote>
<h2>v2.3.8</h2>
<h2>What's Changed</h2>
<ul>
<li>README.md: Update GitHub Actions by <a
href="https://github.com/cclauss"><code>@​cclauss</code></a> in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/259">coverallsapp/github-action#259</a></li>
<li>Spelling by <a
href="https://github.com/jsoref"><code>@​jsoref</code></a> in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/258">coverallsapp/github-action#258</a></li>
<li>Fix macOS install for Homebrew 6.0.0 tap trust requirement by <a
href="https://github.com/afinetooth"><code>@​afinetooth</code></a> in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/265">coverallsapp/github-action#265</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jsoref"><code>@​jsoref</code></a> made
their first contribution in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/258">coverallsapp/github-action#258</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/coverallsapp/github-action/compare/v2...v2.3.8">https://github.com/coverallsapp/github-action/compare/v2...v2.3.8</a></p>
<h2>v2.3.7</h2>
<h2>What's Changed</h2>
<ul>
<li>README.md: Use current actions/setup-node and LTS version of Node.js
by <a href="https://github.com/cclauss"><code>@​cclauss</code></a> in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/247">coverallsapp/github-action#247</a></li>
<li>Update workflow to update and verify release branch by <a
href="https://github.com/afinetooth"><code>@​afinetooth</code></a> in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/249">coverallsapp/github-action#249</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed <code>fail-on-error</code> behavior when download fails (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/253">#253</a>),
PR <a
href="https://redirect.github.com/coverallsapp/github-action/issues/254">#254</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/cclauss"><code>@​cclauss</code></a> made
their first contribution in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/247">coverallsapp/github-action#247</a></li>
<li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
their first contribution in <a
href="https://redirect.github.com/coverallsapp/github-action/pull/254">coverallsapp/github-action#254</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/coverallsapp/github-action/compare/v2...v2.3.7">https://github.com/coverallsapp/github-action/compare/v2...v2.3.7</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="8d6379e14d"><code>8d6379e</code></a>
Fix macOS install for Homebrew 6.0.0 tap trust requirement (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/265">#265</a>)</li>
<li><a
href="0a51d2e0b5"><code>0a51d2e</code></a>
Spelling (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/258">#258</a>)</li>
<li><a
href="dc7137bf23"><code>dc7137b</code></a>
README.md: Update GitHub Actions (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/259">#259</a>)</li>
<li><a
href="ba6dae8331"><code>ba6dae8</code></a>
Revise README for clarity on integrations and support</li>
<li><a
href="a5a505eafd"><code>a5a505e</code></a>
Update README with new sections and information</li>
<li><a
href="5cbfd81b66"><code>5cbfd81</code></a>
Fix fail-on-error to handle all installation and execution failures (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/254">#254</a>)</li>
<li><a
href="e988b39f49"><code>e988b39</code></a>
Update workflow to sync and verify release branch (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/249">#249</a>)</li>
<li><a
href="e7f4f977bd"><code>e7f4f97</code></a>
README.md: Use current actions/setup-node and LTS version of Node.js (<a
href="https://redirect.github.com/coverallsapp/github-action/issues/247">#247</a>)</li>
<li>See full diff in <a
href="648a8eb78e...8d6379e14d">compare
view</a></li>
</ul>
</details>
<br />

Updates `cross-platform-actions/action` from 1.3.0 to 1.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cross-platform-actions/action/releases">cross-platform-actions/action's
releases</a>.</em></p>
<blockquote>
<h2>Cross Platform Action 1.4.0</h2>
<h3>Added</h3>
<ul>
<li>Add support for FreeBSD on RISC-V 64 (<code>riscv64</code>) (<a
href="https://redirect.github.com/cross-platform-actions/action/issues/36">#36</a>)</li>
<li>Add support for NetBSD on VAX, running on the SIMH simulator</li>
<li>Add support for NetBSD 11.0 (<a
href="https://redirect.github.com/cross-platform-actions/action/issues/154">#154</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>OpenBSD on ARM64 now boots with the same EDK II UEFI firmware
(<code>uefi.fd</code>) as
every other ARM64 guest, instead of a separate Linaro UEFI build. The
QEMU
machine type for OpenBSD on ARM64 is now <code>virt,acpi=off</code>,
which makes the
kernel fall back to the device tree instead of hanging during ACPI
attach.
This removes the dependency on the Linaro release server, which no
longer
exists</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Don't log the <code>Tearing down VM</code> group when
<code>shutdown_vm</code> is <code>false</code>, since
the VM is not being torn down in that case
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/109">#109</a>)</li>
<li>The &quot;Start VM&quot; step could keep running for hours when the
VM failed to boot
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/158">#158</a>).
Waiting for the VM to become ready is now bounded by an actual wall
clock
timeout, instead of by a number of connection attempts, and a single SSH
connection attempt is bounded by <code>ConnectTimeout</code>.</li>
<li>The post job step now reports when the console log of the VM is
missing or
empty, instead of silently printing nothing
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/158">#158</a>)</li>
<li>A reboot of a guest that dies instead of rebooting now fails after
roughly
20 seconds, instead of after 13 minutes. The SSH session that issues the
reboot is bounded by <code>ServerAliveInterval</code>, so it no longer
blocks for the
full TCP retransmission time, and waiting for the VM to come back up is
given up on as soon as the guest announces a kernel panic on its serial
console</li>
<li>Advanced Matrix Extensions (AMX) is no longer exposed to the guests
on
x86-64, so which runner a job happens to get no longer decides whether
the
VM boots
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/158">#158</a>).
Kernels released before AMX existed fault as soon as userland starts,
which
affected NetBSD 9.4 and 10.1 and FreeBSD 12.4 on the runners that have
it</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/cross-platform-actions/action/blob/master/changelog.md">cross-platform-actions/action's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>All notable changes to this project will be documented in this
file.</p>
<p>The format is based on <a
href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>,
and this project adheres to <a
href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p>
<h2>[Unreleased]</h2>
<h2>[1.5.0] - 2026-08-28</h2>
<h3>Changed</h3>
<ul>
<li>NetBSD images download around 45% smaller -- 11.0 x86-64 goes from
497 MiB to
268 MiB -- which is most of what a NetBSD job spends on setup
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/151">#151</a>)</li>
<li>Every guest becomes usable sooner, by up to 8 seconds, because the
action no
longer waits on a readiness probe it sent before the guest was
listening</li>
<li>NetBSD guests are logged into without a credential, so no SSH key is
generated
and no resources disk is built to carry one. A custom image supplied
through
<code>image_url</code> still gets both, since it may expect them</li>
</ul>
<h3>Added</h3>
<ul>
<li>Add support for Haiku R1/beta6
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/165">#165</a>)</li>
<li>A <code>variant</code> input, selecting a named configuration of a
platform. Defaults to
<code>default</code>, which boots exactly as before, so no existing
workflow changes.
See <a
href="https://github.com/cross-platform-actions/action/blob/master/readme.md#variants-variant">Variants</a></li>
<li>The <code>microvm</code> variant for NetBSD on <code>x86-64</code>,
which reaches a usable guest in
roughly half the time. It is opt-in because it changes the hardware the
guest
sees: the root disk becomes <code>ld0</code> rather than
<code>sd0</code>, there is no PCI bus to
inspect, and <code>uname -v</code> reports a <code>MICROVM</code>
kernel. Asking for it where it
cannot be booted is an error, not a slow boot</li>
<li>Log a breakdown of how long each phase of setting up the VM took,
together
with how long the VM took to become reachable over SSH</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>5-level paging (LA57) is no longer exposed to the guests on x86-64
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/158">#158</a>).
FreeBSD 13.0 enables 5-level paging whenever the CPU reports it and
panics
in the trampoline that switches to it, so every job that landed on an
Intel
runner from Ice Lake onwards failed to boot</li>
<li>STIBP always-on mode is no longer exposed to the guests on x86-64
(<a
href="https://redirect.github.com/cross-platform-actions/action/issues/158">#158</a>).
Some
of the AMD runners report it without the STIBP and IBRS bits that
normally
come with it, which made DragonFly BSD write <code>IA32_SPEC_CTRL</code>
and take a
general protection fault while booting</li>
</ul>
<h3>Security</h3>
<ul>
<li>The guest's SSH port is only forwarded to the runner's loopback
address. It was
previously bound to every interface, making the guest reachable from
anything
that could reach the runner</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="24ef01df16"><code>24ef01d</code></a>
Release 1.4.0</li>
<li><a
href="ca658ecde2"><code>ca658ec</code></a>
Bump OpenBSD</li>
<li><a
href="de7ca386a0"><code>de7ca38</code></a>
Update changelog</li>
<li><a
href="f529a9b3b3"><code>f529a9b</code></a>
Fix <a
href="https://redirect.github.com/cross-platform-actions/action/issues/154">#154</a>:
Add support for NetBSD 11.0</li>
<li><a
href="9a8bf0a261"><code>9a8bf0a</code></a>
Attach two 2 GB scratch disks to the NetBSD/vax VM</li>
<li><a
href="9ff5d24253"><code>9ff5d24</code></a>
Add support for NetBSD on VAX via the SIMH simulator</li>
<li><a
href="48a3280325"><code>48a3280</code></a>
[no ci] Indicate the readme applies to master and not the latest
release</li>
<li><a
href="9bc6a97170"><code>9bc6a97</code></a>
Don't expose AMX to the guests</li>
<li><a
href="41fae45c45"><code>41fae45</code></a>
Fail fast when a guest crashes while rebooting</li>
<li><a
href="c84882c784"><code>c84882c</code></a>
Log the CPU of the host</li>
<li>Additional commits viewable in <a
href="5ea7e8e467...24ef01df16">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 03:52:44 +00:00
.github ci: bump the github-actions group with 3 updates (#1286) 2026-09-01 03:52:44 +00:00
.reuse docs: add AGENTS.md and modernize contributor documentation (#1231) 2026-07-05 13:05:21 -04:00
ci MacOS and iOS CI fixes (#1030) 2025-09-07 12:16:21 -04:00
cmake remove unneeded warning disablement 2024-06-23 08:13:57 -04:00
docs Revert "Mark parameters in callbacks as const" (#1060); document non-mutability instead (#1244) 2026-07-06 23:26:46 +00:00
include Revert "Mark parameters in callbacks as const" (#1060); document non-mutability instead (#1244) 2026-07-06 23:26:46 +00:00
LICENSES Punycode/IDNA support and encoding of Windows unicode search suffixes (#1031) 2026-07-08 08:26:22 -04:00
m4 Fix a few build issues on MidnightBSD. (#983) 2025-04-15 07:51:51 -04:00
src ares_hosts_file: store /etc/hosts as a bipartite adjacency (fixes #1049) (#1233) 2026-07-12 13:44:45 +00:00
test ares_hosts_file: store /etc/hosts as a bipartite adjacency (fixes #1049) (#1233) 2026-07-12 13:44:45 +00:00
.clang-format ci: validate clang-format on PR-changed lines (#1185) 2026-07-03 17:43:10 -04:00
.gitattributes recursive git attributes 2023-10-27 07:24:13 -04:00
.gitignore gitignore: ignore .dirstamp (#868) 2024-08-26 06:14:15 -04:00
AGENTS.md docs: add AGENTS.md and modernize contributor documentation (#1231) 2026-07-05 13:05:21 -04:00
AUTHORS Android JNI code leaks local references in some cases (#175) 2018-02-03 04:31:38 -05:00
BACKPORTING.md Add comment-driven backport workflow for release branches (#1175) 2026-07-02 08:24:35 -04:00
buildconf provide SPDX identifiers and a REUSE CI job to verify 2023-06-09 20:09:21 +02:00
buildconf.bat provide SPDX identifiers and a REUSE CI job to verify 2023-06-09 20:09:21 +02:00
c-ares-config.cmake.in provide SPDX identifiers and a REUSE CI job to verify 2023-06-09 20:09:21 +02:00
CMakeLists.txt Fix compiler warnings and add CARES_WERROR (enable -Werror in CI on clean toolchains) (#1191) 2026-07-04 13:10:02 +00:00
configure.ac Restore compatibility with Microsoft GDK (#1010) 2025-07-25 18:24:07 -04:00
CONTRIBUTING.md docs: add AGENTS.md and modernize contributor documentation (#1231) 2026-07-05 13:05:21 -04:00
DEVELOPER-NOTES.md docs: add AGENTS.md and modernize contributor documentation (#1231) 2026-07-05 13:05:21 -04:00
FEATURES.md Probe for failed servers instead of redirecting query (#877) 2024-09-09 10:04:04 -04:00
FUZZING.md array: fix array shifting when using an offset 2024-09-15 20:42:45 -04:00
GIT-INFO docs: convert INSTALL to MarkDown & tweak (#83) 2017-01-11 10:36:31 +00:00
INSTALL.md update some build instructions 2024-06-20 14:01:58 -04:00
libcares.pc.cmake CMake pkg-config windows: fix static library options 2024-08-07 09:43:39 -04:00
libcares.pc.in attempt to fix pkgconfig on windows for static builds 2024-01-28 12:38:59 -05:00
LICENSE.md don't put a heading on the license 2024-07-05 09:25:38 -04:00
Makefile.am chore: update some missed files to new MIT license (#920) 2024-12-07 07:53:43 -05:00
Makefile.dj Expose library/utility functions to tools (#860) 2024-08-22 19:09:33 -04:00
Makefile.m32 Port: restore Windows XP minimal support (#958) 2025-01-08 19:51:06 -05:00
Makefile.msvc chore: update some missed files to new MIT license (#920) 2024-12-07 07:53:43 -05:00
Makefile.netware remove unused SEND_QUAL_ARG2 2024-06-23 08:48:59 -04:00
Makefile.Watcom adig: rework command line arguments to mimic dig from bind (#890) 2024-09-25 11:13:53 -04:00
README.md ci: replace AppVeyor with GitHub Actions; drop dead Cirrus config (#1234) 2026-07-05 17:18:29 -04:00
README.msvc remove acountry from built tools as nerd.dk is gone (#554) 2023-09-27 18:20:54 -04:00
RELEASE-NOTES.md release-1.34.5 2025-04-08 07:00:32 -04:00
RELEASE-PROCEDURE.md RELEASE-PROCEDURE: document bumping the package version (AC_INIT / PROJECT) (#1241) 2026-07-06 23:58:58 +00:00
SECURITY.md [doc]: Security reporting requirement updates (#959) 2025-01-09 13:30:03 -05:00
sonar-project.properties SonarCloud: Fix additional code smells 2023-10-15 18:15:15 -04:00

c-ares logo

Build Status Windows Build Status Coverage Status CII Best Practices Fuzzing Status Bugs Coverity Scan Status

Overview

c-ares is a modern DNS (stub) resolver library, written in C. It provides interfaces for asynchronous queries while trying to abstract the intricacies of the underlying DNS protocol. It was originally intended for applications which need to perform DNS queries without blocking, or need to perform multiple DNS queries in parallel.

One of the goals of c-ares is to be a better DNS resolver than is provided by your system, regardless of which system you use. We recommend using the c-ares library in all network applications even if the initial goal of asynchronous resolution is not necessary to your application.

c-ares will build with any C89 compiler and is MIT licensed, which makes it suitable for both free and commercial software. c-ares runs on Linux, FreeBSD, OpenBSD, MacOS, Solaris, AIX, Windows, Android, iOS and many more operating systems.

c-ares has a strong focus on security, implementing safe parsers and data builders used throughout the code, thus avoiding many of the common pitfalls of other C libraries. Through automated testing with our extensive testing framework, c-ares is constantly validated with a range of static and dynamic analyzers, as well as being constantly fuzzed by OSS Fuzz.

While c-ares has been around for over 20 years, it has been actively maintained both in regards to the latest DNS RFCs as well as updated to follow the latest best practices in regards to C coding standards.

Code

The full source code and revision history is available in our GitHub repository. Our signed releases are available in the release archives.

See the INSTALL.md file for build information.

Communication

Issues and Feature Requests should be reported to our GitHub Issues page.

Discussions around c-ares and its use, are held on GitHub Discussions or the Mailing List. Mailing List archive here. Please, do not mail volunteers privately about c-ares.

Security vulnerabilities are treated according to our Security Procedure, please email c-ares-security at haxx.se if you suspect one.

Release keys

Primary GPG keys for c-ares Releasers (some Releasers sign with subkeys):

To import the full set of trusted release keys (including subkeys possibly used to sign releases):

gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2 # Daniel Stenberg
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys DA7D64E4C82C6294CB73A20E22E3D13B5411B7CA # Brad House

Verifying signatures

For each release c-ares-X.Y.Z.tar.gz there is a corresponding c-ares-X.Y.Z.tar.gz.asc file which contains the detached signature for the release.

After fetching all of the possible valid signing keys and loading into your keychain as per the prior section, you can simply run the command below on the downloaded package and detached signature:

% gpg -v --verify c-ares-1.29.0.tar.gz.asc c-ares-1.29.0.tar.gz
gpg: enabled compatibility flags:
gpg: Signature made Fri May 24 02:50:38 2024 EDT
gpg:                using RSA key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
gpg: using pgp trust model
gpg: Good signature from "Daniel Stenberg <daniel@haxx.se>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 27ED EAF2 2F3A BCEB 50DB  9A12 5CC9 08FD B71E 12C2
gpg: binary signature, digest algorithm SHA512, key algorithm rsa2048

SLSA Provenance

This project generates SLSA provenance for its releases! This enables you to verify the integrity of the downloaded artifacts and ensure that the release was generated from the intended repository.

To verify the provenance of the release, please follow the instructions here.

Example:

$ curl -sO https://github.com/c-ares/c-ares/releases/download/v1.34.3/c-ares-1.34.3.intoto.jsonl
$ curl -sO https://github.com/c-ares/c-ares/releases/download/v1.34.3/c-ares-1.34.3.tar.gz
$ slsa-verifier verify-artifact c-ares-1.34.3.tar.gz \
    --provenance-path c-ares-1.34.3.intoto.jsonl \
    --source-uri github.com/c-ares/c-ares \
    --source-tag v1.34.3
Verified signature against tlog entry index 147812470 at URL: https://rekor.sigstore.dev/api/v1/log/entries/108e9186e8c5677a9bfd5bc5181d05ada688a805f9a59cfd082dec27cb6d6567f85b7382eea39dc5
Verified build using builder "https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v2.0.0" at commit c29e75d54c3743783d51a609980495cf553b4bca
Verifying artifact c-ares-1.34.3.tar.gz: PASSED

PASSED: SLSA verification passed

Features

See Features

Supported RFCs and Proposals

  • RFC1035. Initial/Base DNS RFC
  • RFC2671, RFC6891. EDNS0 option (meta-RR)
  • RFC3596. IPv6 Address. AAAA Record.
  • RFC2782. Server Selection. SRV Record.
  • RFC3403. Naming Authority Pointer. NAPTR Record.
  • RFC6698. DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol. TLSA Record.
  • RFC9460. General Purpose Service Binding, Service Binding type for use with HTTPS. SVCB and HTTPS Records.
  • RFC7553. Uniform Resource Identifier. URI Record.
  • RFC6844. Certification Authority Authorization. CAA Record.
  • RFC2535, RFC2931. SIG0 Record. Only basic parser, not full implementation.
  • RFC4034. Resource Records for the DNS Security Extensions (DNSSEC). DS, DNSKEY, RRSIG, and NSEC Records. Parsing and writing only; no DNSSEC validation is performed.
  • RFC5155. DNS Security (DNSSEC) Hashed Authenticated Denial of Existence. NSEC3 and NSEC3PARAM Records.
  • RFC4255. Using DNS to Securely Publish Secure Shell (SSH) Key Fingerprints. SSHFP Record.
  • RFC7873, RFC9018. DNS Cookie off-path dns poisoning and amplification mitigation.
  • draft-vixie-dnsext-dns0x20-00. DNS 0x20 query name case randomization to prevent cache poisioning attacks.
  • RFC7686. Reject queries for .onion domain names with NXDOMAIN.
  • RFC2606, RFC6761. Special case treatment for localhost/.localhost.
  • RFC2308, RFC9520. Negative Caching of DNS Resolution Failures.
  • RFC6724. IPv6 address sorting as used by ares_getaddrinfo().
  • RFC7413. TCP FastOpen (TFO) for 0-RTT TCP Connection Resumption.
  • RFC3986. Uniform Resource Identifier (URI). Used for server configuration.