AppImage / AppImage/appimagetool

Sign releases with PGP

Đang mở
#129 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
C
Star
426
Fork
55
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

### Description

Currently it is not possible to verify the authenticity or cryptographic integrity of the downoads from github.com because the releases are not cryptographically signed.

This makes it hard for users to safely obtain the AppImage releases, and it introduces them (and potentially their downstream users' data) to watering hole attacks.

### Steps to Reproduce

1. Go to the repo page https://github.com/AppImage/appimagetool
2. Click Releases https://github.com/AppImage/appimagetool/releases
3. Click on the latest release (currently https://github.com/AppImage/appimagetool/releases/tag/1.9.1)
4. Look for the hash digest file and the signature of the hash digest file
5. ???
6. Get confused and open ticket

## Expected behavior: [What you expected to happen]

A few things are expected:

1. I should be able to download the appimagetool PGP key out-of-band from popular third-party keyservers (eg https://keys.openpgp.org/)
2. I should be able to download a cryptographic signature of the release (or, better, the releases' digest file, such as a `SHA256SUMS.asc` file) along with the release itself
3. The downloads page itself should include a link to the documentation page that describes how to do the above two steps

## Actual behavior: [What actually happened]

There's just literally no information on verifying downloads, and it appears that it is not possible to do so.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.