teejee2008 / ukuu

A paid version of Ukuu is now available with more features. https://teejeetech.in/2019/01/20/ukuu-v19-01/ Kernel Update Utility for Ubuntu-based distributions. Provides desktop notifications when new mainline kernel is available. Lists kernels from http://kernel.ubuntu.com/~kernel-ppa/mainline/ with options to install and remove.
https://teejeetech.in/ukuu
GNU Lesser General Public License v3.0
400 stars 157 forks source link

Please verify the GPG signatures before installing kernel packages downloaded over plain http #38

Open andersk opened 6 years ago

andersk commented 6 years ago

The Ubuntu mainline kernels come with GPG-signed hashes (CHECKSUMS, CHECKSUMS.gpg), but this utility ignores them. Since the downloads are over plain HTTP, there is nothing to stop a network attacker from modifying the kernel packages in transit.