No way to verify releases.
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 56
Description
I just received a prompt to update to version 2.5.2 of Keybase desktop app. Being the paranoid person I am, I went online to verify that this is a legitimate release and not someone compromising the application upgrade process. Unfortunately, I found the following:
1. The website doesn't maintain a list of versions.
2. New versions do not result in a blog post.
3. New versions are not always announced via twitter.
4. The GitHub releases page does not have the latest release version.
5. The downloads page doesn't have any links that include the version being downloaded.
6. There is no changelog in the GitHub repository.
Basically after doing a non-trivial amount of research (way more than I should have to in order to verify a new release), I have come to the conclusion that the Keybase update process has been compromised and the latest version is 2.5.0 (per GitHub releases page) and I should not apply this update.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start by tracing how releases are published across the GitHub releases page, website, downloads page, and announcements; done should provide a consistent, publicly verifiable current version and release history.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100