Issue with verification doc
- Dominant language
- JavaScript
- Stars
- 65
- Forks
- 162
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 18
Description
https://www.apache.org/info/verification.html says:
"Signatures and checksums are only available from the official Apache Software Foundation site."
I think that is no longer true, as they are also available from the CDN.
Whilst that is an official site, it cannot also be 'the site'.
Also other documentation says to only download these from apache.org/dist => downloads.apache.org.
The page is also not clear on what users are supposed to do to check a download. I think it should say that at least one of the methods should be used, ideally using the sig, but failing that please at least check the hash.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the verification page at https://www.apache.org/info/verification.html and locate its source in the www-site repository; no source file is named in the issue. Done means the page accurately describes official signature and checksum locations and clearly explains that users should verify with a signature when possible, or at least with a hash.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100