keybase / keybase/client

No way to verify releases.

Open
#13,546 12 comments 1 reaction 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

I just received a prompt to update to version 2.5.2 of Keybase desktop app. Being the paranoid person I am, I went online to verify that this is a legitimate release and not someone compromising the application upgrade process. Unfortunately, I found the following:
1. The website doesn't maintain a list of versions.
2. New versions do not result in a blog post.
3. New versions are not always announced via twitter.
4. The GitHub releases page does not have the latest release version.
5. The downloads page doesn't have any links that include the version being downloaded.
6. There is no changelog in the GitHub repository.

Basically after doing a non-trivial amount of research (way more than I should have to in order to verify a new release), I have come to the conclusion that the Keybase update process has been compromised and the latest version is 2.5.0 (per GitHub releases page) and I should not apply this update.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by tracing how releases are published across the GitHub releases page, website, downloads page, and announcements; done should provide a consistent, publicly verifiable current version and release history.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.