5 ms·
There has been chatter about doing this for over 8 years in the WordPress bug tracker, and I vaguely recollect chatter about it even earlier, around when automa
by ddebernardy 7y ago
There has been chatter about doing this for over 8 years in the WordPress bug tracker, and I vaguely recollect chatter about it even earlier, around when automated updates were first introduced. What's surprising is that this hasn't been done earlier, and speaking personally I do not think this deserves any praise - on the contrary.
https://core.trac.wordpress.org/ticket/18577 https://core.trac.wordpress.org/ticket/18577 - Updates and downloads should be delivered securely (signed and delivered over SSL), opened 8 years ago, partially closed 6 years ago (because it began to use SSL).
https://core.trac.wordpress.org/ticket/25052 https://core.trac.wordpress.org/ticket/25052 - Updates and downloads should be signed, opened 6 years ago, closed 6 days ago.
https://core.trac.wordpress.org/ticket/39309 https://core.trac.wordpress.org/ticket/39309 - Secure WordPress Against Infrastructure Attacks, opened 2 years ago, closed 12 days ago.