Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When building appliances should check download against a checksum or GPG key #681

Open
JedMeister opened this issue Aug 4, 2016 · 2 comments

Comments

@JedMeister
Copy link
Member

As suggested by @ashkulz on his recent PR against the limesurvey appliance appliances should check validity of download at build time.

@JedMeister JedMeister added this to the 14.2 milestone Aug 4, 2016
@JedMeister JedMeister modified the milestones: 15.0, 14.2 Jun 21, 2017
@JedMeister
Copy link
Member Author

Let's start introducing this into v15.0?! Thoughts?

@JedMeister
Copy link
Member Author

Still haven't implemented this so bumping to v17.0.

Part of the issue is that we're often downloading files dynamically (so as to download the latest version) so we'd also need to discover the checksum and/or key to check against. Signed downloads would be easier in general (would only need to be updated when keys rotated) but it still doesn't seem that common...

@JedMeister JedMeister modified the milestones: 16.0, 17.0 Oct 13, 2020
@JedMeister JedMeister modified the milestones: 17.0, 18.0 Jul 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant