Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add checksum for gollum.war to release #2021

Closed
wants to merge 1 commit into from

Conversation

dometto
Copy link
Member

@dometto dometto commented Dec 21, 2023

No description provided.

@dometto
Copy link
Member Author

dometto commented Dec 21, 2023

On reflection, adding a checksum file does not seem very helpful. :) Checksums are supposed to give some protection with regard to man-in-the-middle attacks, but that function is not performed if the checksum must itself be downloaded by the user. We could, however, try to add the checksum to the text body of the release?

I guess the most optimal solution would be to actually GPG sign a (tarball of) the .war. But I don't see any way of doing that in an Actions workflow. If anyone has any idea what is considered best practice here, I'd be much obliged!

@dometto
Copy link
Member Author

dometto commented Jan 31, 2024

This is too complicated and arguably of little worth. Better to add the signature to the release manually for now.

@dometto dometto closed this Jan 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant