turnkeylinux / tracker

TurnKey Linux Tracker
https://www.turnkeylinux.org
70 stars 16 forks source link

When building appliances should check download against a checksum or GPG key #681

Open JedMeister opened 8 years ago

JedMeister commented 8 years ago

As suggested by @ashkulz on his recent PR against the limesurvey appliance appliances should check validity of download at build time.

JedMeister commented 7 years ago

Let's start introducing this into v15.0?! Thoughts?

JedMeister commented 3 years ago

Still haven't implemented this so bumping to v17.0.

Part of the issue is that we're often downloading files dynamically (so as to download the latest version) so we'd also need to discover the checksum and/or key to check against. Signed downloads would be easier in general (would only need to be updated when keys rotated) but it still doesn't seem that common...