3 ms·
It's great to see efforts towards integration of strong cryptographic verifications. But what I currently miss is something much simpler: SHA digests for releas
by mavam 11y ago
It's great to see efforts towards integration of strong cryptographic verifications. But what I currently miss is something much simpler: SHA digests for release tarballs. I've already contacted github support, but apparently this concern never made it high up enough in their priority list.
- zokier 11y agoIf you are downloading the releases over HTTPS then do digests really add any value at all?
- cuckcuckspruce 11y agoYes, because they allow you to have mirror sites. Serve the digest from the main machine over HTTPS and distribute the tarballs from a CDN or mirror network.
- deleted 11y ago[deleted]
- lolidaisuki 11y agoWhat good is an SHA without a signature? Maybe you could just include the sums in your README or something.