whitesource / unified-agent-distribution

51 stars 48 forks source link

Possible to sign or release a checksum alongside release? #1

Closed ropnop closed 4 years ago

ropnop commented 4 years ago

Hello - it would be beneficial for us to verify the JAR after downloading it in our pipelines. Could you release a checksum or (even better) sign the JAR and let us verify it with a public key? That way we could verify it after downloading in a pipeline but before executing it. Thanks

SenuraMalaka commented 4 years ago

The checksums are posted in here for each release. image

annarozin commented 4 years ago

please see @SenuraMalaka answer