if the package author provides a checksum or signature, it should be verified when downloading
Open
- Dominant language
- JavaScript
- Stars
- 39
- Forks
- 15
- PR merge metrics
- No merged PRs in 30d
Description
Only one of these is necessary (either checksum or signature). Figure out which makes the most sense before implementing this.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. First determine whether checksum or signature verification fits binwrap's package-download flow, then define how author-provided verification data is supplied and how successful and failed verification are tested.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100