Skip to content
Snippets Groups Projects
Closed check hashes of files we download against expected hash value
  • View options
  • check hashes of files we download against expected hash value

  • View options
  • Closed Issue created by Jacob Appelbaum

    Per #8283 (closed), we need to check the hash of each file we download against the expected value. This should ensure that we never build without explicitly approving each new version and a hash for each new version. It will also ensure that when an attacker tampers with the file on the remote server, we will not attempt to build likely hostile source bundles or load hostile extensions.

    I think I'll just write a simple macro to check all of the hashes after all the downloads complete. Does that seem like a reasonable approach?

    Linked items ... 0

  • Activity

    • All activity
    • Comments only
    • History only
    • Newest first
    • Oldest first
    Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading