-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Labels
enhancementNew feature or requestNew feature or request
Description
Adding an "integrity" string for the file we're fetching to prevent any unexpected changes would be good for security.
- fetch: https://example.com/some/file.cc
integrity: sha256-BLAHBLAHBLAH # support multiple algos?
outdir: some/dirIf the integrity check doesn't match whats in the build receipe after a fetch the build should fail.
If a recipe doesn't have an integrity string we should print a warning with the integrity string so its easy to copy. Maybe even a flag to automatically write to the receipe.
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request