docs: Getting started guide could add mention of validating checksums
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 717
- Forks
- 1.2k
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 19
Description
At the moment in the getting start guide the instructions are to download and extract a tarball to use Prometheus. While the project provides SHA256 checksums on the download page, the documentation doesn't mention checking them.
In light of attacks like Codecov, a possibly useful addtion would be to mention that users should validate the checksum prior to extraction, to help detect any attempt at compromise.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Open the linked Prometheus getting started guide and compare its tarball download steps with the download page's SHA256 checksums. Add guidance to validate the checksum before extraction, then preview the rendered guide to confirm the instruction is clear and placed with the download steps.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100