Verification process ota update files
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 667
- Forks
- 330
- Avg merge
- 15h 19m
- Merged PRs (30d)
- 31
Description
Thanks for the awesome work on bringing OTAs to so many devices.
I have a question regarding the verification of the ota files.
It seems that anyone can create a PR with a new ota file for a device.
For example https://github.com/Koenkk/zigbee-OTA/pull/915
The user had no track record (recently created) and there is no visible connection to Sonoff.
This seems like a somewhat risky situation where no one really knows if the new firmware is from Sonoff or not.
Maybe I am missing something here and Koenkk has some other ways of verifying that the firmware is from a reputable source?
There is also a post in the home assistant community about this:
https://community.home-assistant.io/t/new-sonoff-trv-firmware/949900
Thanks in advance!
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing pull request #915 and the linked Home Assistant community post to understand the firmware provenance concern. Check the repository’s existing OTA contribution and verification process, if any. Done means reaching and documenting a clear decision about how new OTA files are verified before acceptance.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100