Menu

#13 Please make tgz-archive verifiable

open
nobody
security (1)
5
2014-07-30
2014-07-30
Benedikt Wi
No

Would it be possible to have the tgz-archive (collada-dom-2.4.0.tgz) being signed using GnuPG or another OpenPGP-compatible program? Downloading an unsigned file via http can be changed by anyone on the way from sourceforge to your own ISP, so you cannot be sure that there isn't someone injecting malicious code when you download the archive.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB