PublicVPNList VPN 0.1.8 Linux beta — source materials and verification The core and native library are redistributed unchanged from the official sing-box 1.14.2 linux-amd64 release. PublicVPNList is not an official SagerNet app. core-module-sources.tar.gz contains the exact Go module zip/mod/info files and source-inventory.json with Go checksum-database verified module sums. Extract each needed module zip with its original module@version directory. The main module is github.com/sagernet/sing-box@v1.14.2. Core source revision: af6e64c3b69e6132ebaee0e1a3d24e93903f6709. Toolchain used by upstream binary: Go1.26.8. Original flags and module versions: core-modules.json in the notices archive. Core build example from the extracted sing-box module: CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -tags "with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,with_cloudflared,with_naive_outbound,with_usbip,with_openvpn,with_openconnect,badlinkname,tfogo_checklinkname0,with_purego" -o sing-box ./cmd/sing-box The Go driver resolves module versions from go.mod/go.sum. Network access or a local GOPROXY populated from the supplied zip/mod/info files is required. This builds the source; bit-for-bit matching of upstream build metadata is not claimed. The release CLI/version linker metadata is in the upstream build scripts. None of the core or native source was modified for this application. Native library: Extract github.com/sagernet/cronet-go@v0.0.0-20260912104727-0d28acc44093 from the Go source collection. Extract naiveproxy-72a06c9f.tar.gz as its naiveproxy/ directory, matching upstream's submodule layout. It is a complete snapshot of SagerNet/naiveproxy at72a06c9fca0e2d228588c7f3074bf7efff3ff686. From cronet-go/, use the included cmd/build-naive driver: go run ./cmd/build-naive --target linux/amd64 download-toolchain go run ./cmd/build-naive --target linux/amd64 build go run ./cmd/build-naive --target linux/amd64 package The scripts download the pinned Chromium toolchain/sysroot and build the native library. Read cmd/build-naive and naiveproxy/src/build.sh for native requirements and output paths. These are upstream source-build instructions; a full Chromium rebuild was not executed on the publisher's workstation. Source and original third-party notices are available without login or charge alongside the binary. Retain original notices when redistributing components. https://github.com/SagerNet/sing-box/tree/v1.14.2 https://github.com/SagerNet/cronet-go/tree/0d28acc44093 https://github.com/SagerNet/naiveproxy/tree/72a06c9fca0e2d228588c7f3074bf7efff3ff686 Verify downloads: sha256sum --ignore-missing -c SHA256SUMS openssl pkeyutl -verify -pubin -inkey release-public.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig The initial publisher key is obtained over the site's HTTPS connection. Save a trusted copy for subsequent releases. A checksum alone authenticates no publisher. This signature is an Ed25519 release signature, not a Windows Authenticode certificate or a security audit. Linux installs do not require a Windows publisher certificate. Release manifests are for offline verification; the app does not yet install automatic updates.