Closed dbrgn closed 6 years ago
Thanks for providing this crate!
There is something that makes me a bit uneasy though, which is the fact that the downloaded libsodium library is not checked during the build.
Could we maybe verify SHA256 checksums of the downloads in the build script?
I can provide a PR as soon as #46 is merged / handled (since that reorganized the build.rs file a bit and I don't want to make conflicting changes).
Thanks for providing this crate!
There is something that makes me a bit uneasy though, which is the fact that the downloaded libsodium library is not checked during the build.
Could we maybe verify SHA256 checksums of the downloads in the build script?