[Release] Add support for verifying .{asc,sha256,512} for .jar related files in `dev/release/verify_rc.sh`
Open
Type: enhancement
- Dominant language
- Java
- Stars
- 94
- Forks
- 152
- Avg merge
- 3d 16h
- Merged PRs (30d)
- 11
Description
### Describe the enhancement requested
We should:
* Download binary artifacts from GitHub Release
* Verify signature by `gpg --verify XXX.asc XXX`
* Verify checksum by `sha256 -c XXX.sha256` and `sha512 -c XXX.sha512`
Contributor guide
Research direction
Start with dev/release/verify_rc.sh and inspect how binary artifacts are downloaded and named from GitHub Releases. Add coverage for .asc, .sha256, and .sha512 files associated with .jar artifacts, using the verification commands in the issue; done means signatures and both checksum formats are checked.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, java, shell
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100