Skip to content
Discussion options

You must be logged in to vote

Hi @wolfycom4, it sounds like you downloaded the wrong thing.
You should download one of the compiled assets from the release, which are scanned for malware and then signed:

If you instead download the source code, there is indeed a zip bomb in the data for CKAN's testing suite, which we use to ensure that CKAN is not vulnerable to such an attack. This file is not included in the application builds that are provided to users.

See #4501 for a previous discussion of this.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by HebaruSan
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
Support Issues that are support requests Duplicate Duplicate of another issue
2 participants