prometheus / prometheus/docs

docs: Getting started guide could add mention of validating checksums

Open
#1,946 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
717
Forks
1.2k
Avg merge
3d 15h
Merged PRs (30d)
19

Description

At the moment in the getting start guide the instructions are to download and extract a tarball to use Prometheus. While the project provides SHA256 checksums on the download page, the documentation doesn't mention checking them.

In light of attacks like Codecov, a possibly useful addtion would be to mention that users should validate the checksum prior to extraction, to help detect any attempt at compromise.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Open the linked Prometheus getting started guide and compare its tarball download steps with the download page's SHA256 checksums. Add guidance to validate the checksum before extraction, then preview the rendered guide to confirm the instruction is clear and placed with the download steps.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.