axodotdev / axodotdev/cargo-dist
do checksum integrity check in installers
Open
feature request
- Dominant language
- Rust
- Stars
- 2.1k
- Forks
- 149
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 32
Description
we make the checksums, let's use them in the installers to add a (thin) layer of security
Contributor guide
Research direction
No files or tests are named. Start by locating where checksums are generated and where the installers consume downloaded artifacts, then trace each supported installer path. Done means installers perform an integrity check using the generated checksums and have coverage for the supported paths.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100