AppFlowy-IO / AppFlowy-IO/AppFlowy

[FR] hash of the releases

Open
#3,717 1 comment 4 reactions 0 assignees View on GitHub
new feature platform-windows
Dominant language
Dart
Stars
76.6k
Forks
6k
PR merge metrics
No merged PRs in 30d

Description

### Description

Adding hash codes of the releases under the github release page would be nice to verify the integrity of the zip/executable.
e.g. SHA256SUMS.txt

Another extra nice to have is to be able to fetch signing key and .asc signature file to verify as well.

I would like to verify the file if possible since after submitting the zip for windows and tar for linux to virustotal,
resulted in a trojan warning.

I'm not sure if this may be a false positive but wanted to make sure by verifying.
https://www.virustotal.com/gui/file/872b249d590493718f2daa470489e918fb646dfaf98dd6b298e498a8a72ed11f
https://www.virustotal.com/gui/file/006a12152b740cc2df49060c706943ee3202f7d0177f8fb5117d0b1e2982d4c8

And when trying to download the windows executable, particularly through Edge browser, it provides warning that publisher is unknown and also virustotal resulted in some malicious flags.
https://www.virustotal.com/gui/file/eaadfa17085e134a480d7241d9bbcf37f44a8358bc78ab7dee83655a5f8b024b

Virustotal didn't output any red flags for the .deb file though.

My targeted os: windows10, debian/ubuntu spins.

### Impact

for the somewhat privacy and security paranoid type like myself.

### Additional Context

_No response_

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.