Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Download Verification #1282

Open
3knight opened this issue Feb 7, 2024 · 2 comments
Open

Download Verification #1282

3knight opened this issue Feb 7, 2024 · 2 comments

Comments

@3knight
Copy link

3knight commented Feb 7, 2024

Would it be possible to sign releases with gpg so users can verify downloads? If not, how about releasing the corresponding checksums, preferably across multiple platforms (github, website, X)?

@TheJackiMonster
Copy link
Collaborator

The download links on the website already point to Github. So there's already only one place to download the releases.

@3knight
Copy link
Author

3knight commented Feb 8, 2024

@TheJackiMonster You are totally right but I think there is a misunderstanding about what I was asking. I am wondering about signing the releases with GPG. This way, end users could use GPG to verify the authenticity of the download. An example I could use is something like KeepassXC. You can check it out here if you'd like, https://keepassxc.org/verifying-signatures/.

The thing about "github, website, X)" was in regards to checksum values. It would allow for different form of verification if signing releases isn't an option. Posting it across multiple platforms would prevent a single point of failure, and make it harder to exploit.

I'm just asking because I think it would go along way in helping make sure people are downloading authentic, genuine software. GPG is free software and available on all platforms, making it convenient.

Thanks for the consideration and I hope this is a better explanation, I can see how my original post could imply something else, my bad.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants