wrenam icon indicating copy to clipboard operation
wrenam copied to clipboard

Verify (and possible mirror) NPM installers

Open siepkes opened this issue 7 years ago • 3 comments

As discussed in #24 the openam-ui-ria project pulls in an NPM installer via a Maven plugin. We need a way to verify the NPM installer we downloaded.

This might require adding functionality to the com.github.eirslett:frontend-maven-plugin plugin. NPM provides a list with hashes of the installers (SHASUMS256.txt) and has also signed this list (SHASUMS256.txt.asc).

siepkes avatar Jun 07 '18 08:06 siepkes

@Kortanul FYI

siepkes avatar Jun 07 '18 08:06 siepkes

@siepkes got your message about this, but am not sure if I'm the best one to take this on.

Kortanul avatar Jun 16 '18 17:06 Kortanul

@Kortanul Didn't mean to imply you should take it on ;-). The FYI was more about this is something that is also of value for IDM and so that you are aware of this "hole" in our verification process.

siepkes avatar Jun 16 '18 20:06 siepkes