Koenkk / Koenkk/zigbee-OTA

Verification process ota update files

Open
#943 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
667
Forks
330
Avg merge
15h 19m
Merged PRs (30d)
31

Description

Thanks for the awesome work on bringing OTAs to so many devices.

I have a question regarding the verification of the ota files.
It seems that anyone can create a PR with a new ota file for a device.
For example https://github.com/Koenkk/zigbee-OTA/pull/915
The user had no track record (recently created) and there is no visible connection to Sonoff.
This seems like a somewhat risky situation where no one really knows if the new firmware is from Sonoff or not.
Maybe I am missing something here and Koenkk has some other ways of verifying that the firmware is from a reputable source?
There is also a post in the home assistant community about this:
https://community.home-assistant.io/t/new-sonoff-trv-firmware/949900

Thanks in advance!

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing pull request #915 and the linked Home Assistant community post to understand the firmware provenance concern. Check the repository’s existing OTA contribution and verification process, if any. Done means reaching and documenting a clear decision about how new OTA files are verified before acceptance.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.