-
Notifications
You must be signed in to change notification settings - Fork 158
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Please consider publishing a checksum for verifying precompiled binaries #449
Comments
I looked through the |
This repository uses GoReleaser and I guess GoReleaser has the capability to generate checksums. |
Checksums will be included from the next release. Here is an example of the checksums file:
|
Thank you so much for your care and attention to this issue! |
Relase for v1.7.3 includes the checksums: https://github.com/rhysd/actionlint/releases/tag/v1.7.3 |
It would be wonderful if the releases page for the precompiled binaries also included a section with a hash for verifying the authenticity of the binary, in order to mitigate supply chain attacks.
See https://github.com/GoogleCloudPlatform/cloud-sql-proxy/releases/tag/v2.13.0 for an example
The text was updated successfully, but these errors were encountered: