Skip to content
This repository has been archived by the owner on Jul 4, 2023. It is now read-only.

External patches should have checksums #22524

Closed
sitsofe opened this issue Sep 13, 2013 · 1 comment
Closed

External patches should have checksums #22524

sitsofe opened this issue Sep 13, 2013 · 1 comment

Comments

@sitsofe
Copy link
Contributor

sitsofe commented Sep 13, 2013

While this initially sounds like Issue #15631 I think there's a case saying that there should be basic checks against corrupt (accidental or otherwise) external patches.

An example of this could be a linked patch that is on a publicly modifiable webpage. It seems reasonable to assert the patch is likely in the same state as when the formula was accepted...

An extension of this could be a --insecure option that when used once no longer requires patch checksums / allows usage of resources that can't be checksumed thus preserving a degree of backwards compatibility.

@MikeMcQuaid
Copy link
Member

Duplicate of #11956 and #21648.

@Homebrew Homebrew locked and limited conversation to collaborators Feb 17, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants