Skip to content
This repository has been archived by the owner on Jan 2, 2023. It is now read-only.

sign SHA256SUM files. #3525

Closed
graingert opened this issue Jun 19, 2017 · 6 comments
Closed

sign SHA256SUM files. #3525

graingert opened this issue Jun 19, 2017 · 6 comments
Labels
Milestone

Comments

@graingert
Copy link

graingert commented Jun 19, 2017

gpg --detach-sign SHA256SUMS

@graingert graingert changed the title sign SHASUM files. sign SHA256SUM files. Jun 19, 2017
@graingert
Copy link
Author

graingert commented Jun 19, 2017

If it were not for the fact that

SHA256 file is still downloadable from https://downloads.wkhtmltopdf.org/0.12/0.12.3/

It would have been impossible to share files found from the web as a temporary solution for those needing the file in #3518

However with signed SHA256SUM files everyone would know the provenance of the files, even if wkhtmltopdf.org were totally down.

@ashkulz
Copy link
Member

ashkulz commented Jun 19, 2017

Is that still a concern now that it's on github? Most projects releasing on Github don't even publish checksums...

@graingert
Copy link
Author

@ashkulz I think it's different for browsers.

@ashkulz
Copy link
Member

ashkulz commented Jun 19, 2017

I'd still have to publish the gpg key, deal with key rotation, etc. Makes sense for a bigger project, just not this one I feel...

@ashkulz
Copy link
Member

ashkulz commented Jun 10, 2018

0.12.5 was signed with a GPG key, and I'll sign the sha256sums file as well once the binaries are uploaded.

not sure how to share the key, is there a recommended practice for that?

@ashkulz ashkulz added this to the 0.12.5 milestone Jun 10, 2018
@ashkulz ashkulz added the Fixed label Jun 11, 2018
@ashkulz ashkulz closed this as completed Jun 11, 2018
@ashkulz
Copy link
Member

ashkulz commented Jun 12, 2018

Packages for 0.12.5 are available using signed checksums.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Development

No branches or pull requests

2 participants