Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Npmjs.org and GitHub 2.3.0 release packages checksum differs #93

Closed
wilkko opened this issue Jun 12, 2023 · 2 comments
Closed

Npmjs.org and GitHub 2.3.0 release packages checksum differs #93

wilkko opened this issue Jun 12, 2023 · 2 comments

Comments

@wilkko
Copy link

wilkko commented Jun 12, 2023

Npmjs.org and GitHub 2.3.0 release packages checksum differs.

Our firewall virus scanner started flagging for https://registry.npmjs.org/clipboardy/-/clipboardy-2.3.0.tgz clipboard_i686.exe on May 31th:
image

Checked the checksum:
$ wget -O github_clipboardy-2.3.0.tgz https://github.com/sindresorhus/clipboardy/archive/refs/tags/v2.3.0.tar.gz
$ wget -O npmjsorg_clipboardy-2.3.0.tgz https://registry.npmjs.org/clipboardy/-/clipboardy-2.3.0.tgz

$ sha256sum npmjsorg_clipboardy-2.3.0.tgz
9e80e29dabb1ee5690905227970d3e3be4cf6330b542cc0571e4cd1a2bf279f4 npmjsorg_clipboardy-2.3.0.tgz
$ sha256sum github_clipboardy-2.3.0.tgz
4712cf7cfaa04ac65d1e0529ea0e67a02de210ffdbfe01af39390c18cd882aab github_clipboardy-2.3.0.tgz

@sindresorhus
Copy link
Owner

The archive between npm and GitHub is not guaranteed to match. They don't use the exact same archive.

@sindresorhus sindresorhus closed this as not planned Won't fix, can't repro, duplicate, stale Jun 12, 2023
@sindresorhus
Copy link
Owner

As for the virus alert. That is a false-positive. You will have to report that to your anti-virus vendor.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants