Skip to content

Checksum mismatch from static files hosted at download.docker.com #47495

Answered by neersighted
mhazegh asked this question in Q&A
Discussion options

You must be logged in to vote

Hi, thanks for asking!

I can verify that both checksums represent official builds performed by Docker Inc. We uploaded some additional packages during this patch cycle after the first build, and I overlooked the fact that we do not ensure that we avoid clobbering any of the static binary files when performing a re-upload.

I assume that my predecessors thought that unnecessary as there is no index file in the repository that represents those files -- however, clearly (and quite reasonably) that is a silly assumption, as consumers of those files may very well want to verify them.

For now, you should not see any repeats of this incident, both as backfilling new packages is very rare (and onl…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@mhazegh
Comment options

Comment options

You must be logged in to vote
1 reply
@mhazegh
Comment options

Answer selected by mhazegh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants