test-reporter icon indicating copy to clipboard operation
test-reporter copied to clipboard

Please sign a sums file, or checksums.

Open envygeeks opened this issue 8 years ago • 1 comments

Please offer a way for us to validate that the download is not compromised, with a GPG key you publish somewhere we can get it, that's also hosted on a keyserver. I feel that blindly downloading a binary wthout any checksum, is cause for disaster. And people would say, well it's over SSL, but SSL doesn't prevent somebody from hosting a compromised binary.

envygeeks avatar Nov 29 '17 04:11 envygeeks

Hi @chrishulton Has their been any progress on this?

craig-davis avatar Aug 24 '18 21:08 craig-davis