Menu

#551 Please provide cryptographic signature of source tarball

3.0 Series
open
nobody
None
5
2025-11-05
2019-08-15
f0rt
No

A cryptographic signature of the source tarball (for example nsis-3.04-src.tar.bz2) would allow the verification that no third party has modified the code after its release (projects such as phpmyadmin, unrealircd, and proftpd have suffered from this kind of attack).

Discussion

  • Anders

    Anders - 2025-11-01

    Sourceforge provides SHA1 hashes of all files if you go into the "Files" section to download and click on the "(i)".

     
  • f0rt

    f0rt - 2025-11-03

    The SHA1 hash provides some protection but does not enable to check that no third party changes occurred after its release.

     
    • Anders

      Anders - 2025-11-05

      So you want the hash to be posted on a different server? I can try to remember to put the hash in the forum release posts.

      For the main .exe installer, the SHA2 is available in the WinGet manifests for our last couple of releases and even longer back in Chocolatey.

       

      Last edit: Anders 2025-11-05

Log in to post a comment.