AppFlowy-IO / AppFlowy-IO/AppFlowy
[FR] hash of the releases
- Dominant language
- Dart
- Stars
- 76.6k
- Forks
- 6k
- PR merge metrics
- No merged PRs in 30d
Description
### Description
Adding hash codes of the releases under the github release page would be nice to verify the integrity of the zip/executable.
e.g. SHA256SUMS.txt
Another extra nice to have is to be able to fetch signing key and .asc signature file to verify as well.
I would like to verify the file if possible since after submitting the zip for windows and tar for linux to virustotal,
resulted in a trojan warning.
I'm not sure if this may be a false positive but wanted to make sure by verifying.
https://www.virustotal.com/gui/file/872b249d590493718f2daa470489e918fb646dfaf98dd6b298e498a8a72ed11f
https://www.virustotal.com/gui/file/006a12152b740cc2df49060c706943ee3202f7d0177f8fb5117d0b1e2982d4c8
And when trying to download the windows executable, particularly through Edge browser, it provides warning that publisher is unknown and also virustotal resulted in some malicious flags.
https://www.virustotal.com/gui/file/eaadfa17085e134a480d7241d9bbcf37f44a8358bc78ab7dee83655a5f8b024b
Virustotal didn't output any red flags for the .deb file though.
My targeted os: windows10, debian/ubuntu spins.
### Impact
for the somewhat privacy and security paranoid type like myself.
### Additional Context
_No response_
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.