OpenBazaar / openbazaar-desktop

OpenBazaar 2.0 Desktop Client (talks to openbazaar-go server daemon)
MIT License
647 stars 186 forks source link

Missing shasums and file signatures to verify downloads? #1877

Closed Emily7777 closed 4 years ago

Emily7777 commented 4 years ago

Where are the download SHASUMS and file signatures published?

I'm sure you can imagine that we can't really trust the download with a crypto wallet until we can verify it wasn't changed.

Please advise.

hoffmabc commented 4 years ago

Here is the SHA file. https://github.com/OpenBazaar/openbazaar-desktop/releases/download/v2.3.8/SHA256SUMS.v2.3.8.asc

Here are verification instructions if you want to use the scripts. https://github.com/OpenBazaar/openbazaar-desktop/tree/master/verify