Skip to content

A plugin should print the checksums to the log #58

@igor-petruk

Description

@igor-petruk

It is important to verify that it was a CI that uploaded the artifacts.

Assume I am a Github repo owner, but I don't own the CI server - I use a public one.

A user can then read CI logs to see the checksums, download the archive and check them. This prevents the Github owner from deleting the CI release and putting a malicious binary manually, providing a correct new hash sum.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions