Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verification key and installer hosted in the same place #5474

Open
Synteek opened this issue Feb 28, 2024 · 2 comments
Open

Verification key and installer hosted in the same place #5474

Synteek opened this issue Feb 28, 2024 · 2 comments
Assignees
Labels
💡 enhancement This issue describes an improvement, enhancement, or feature request for OpenShot

Comments

@Synteek
Copy link

Synteek commented Feb 28, 2024

Describe the new feature:
Currently, OpenShot Installer and shasum verification are hosted on the same service, under the same repository/user.

Latest as of this request:
github.com/OpenShot/openshot-qt/releases/download/v3.1.1/OpenShot-v3.1.1-x86_64.exe
github.com/OpenShot/openshot-qt/releases/download/v3.1.1/OpenShot-v3.1.1-x86_64.exe.sha256sum.verify

Describe the solution you'd like:
The shasum should be hosted elsewhere, or at least under a different major contributor's account than yours @jonoomph

@Synteek Synteek added the 💡 enhancement This issue describes an improvement, enhancement, or feature request for OpenShot label Feb 28, 2024
@hgftrdw45ud67is8o89
Copy link

+1 for proper security.

@jonoomph
Copy link
Member

jonoomph commented Apr 7, 2024

Thanks for the suggestion. The only issue is I am the only developer with write access to the OpenShot repos. We have had security issues in the past from other contributors pushing code. While I could move the shasum to a different website (i.e. openshot.org), I'm not sure that really mitigates the threat mentioned here. I will do some research into this. Thanks for the suggestion!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
💡 enhancement This issue describes an improvement, enhancement, or feature request for OpenShot
Projects
None yet
Development

No branches or pull requests

3 participants