Skip to content
This repository has been archived by the owner on Jan 10, 2023. It is now read-only.

Please provide a digital signature #186

Closed
szepeviktor opened this issue Aug 3, 2019 · 4 comments · Fixed by #207
Closed

Please provide a digital signature #186

szepeviktor opened this issue Aug 3, 2019 · 4 comments · Fixed by #207
Assignees

Comments

@szepeviktor
Copy link
Contributor

szepeviktor commented Aug 3, 2019

See the real danger in https://twitter.com/pear/status/1086634389465956352
and pypa/get-pip#41

Related #171

@szepeviktor
Copy link
Contributor Author

szepeviktor commented Aug 3, 2019

You could consider placing the bash script and the signature on very different platforms.

drazisil added a commit that referenced this issue Sep 24, 2019
drazisil added a commit that referenced this issue Sep 24, 2019
@drazisil drazisil self-assigned this Sep 24, 2019
@szepeviktor
Copy link
Contributor Author

szepeviktor commented Sep 24, 2019

@drazisil Thank you for providing the hash.

Could you make it available for a script (a machine) too?

@drazisil
Copy link
Contributor

@szepeviktor Could you describe more what you are looking for? Do you mean as a separate, fetchable file?

@szepeviktor
Copy link
Contributor Author

szepeviktor commented Sep 24, 2019

@drazisil Yes. Please see the links at the top. I would be ideal to host the bash script on one infrastructure and the hash on another one.

So one can verify the hash in a script.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants