Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify tarball checksum from Appstore when downloading app release #48505

Open
provokateurin opened this issue Oct 1, 2024 · 0 comments
Open
Labels

Comments

@provokateurin
Copy link
Member

How to use GitHub

  • Please use the 👍 reaction to show that you are interested into the same feature.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Is your feature request related to a problem? Please describe.
Releases are not stored on the Appstore but on 3rd party services. In case of security issues an attacker might replace the release tarball.

Describe the solution you'd like
When downloading a release on the server the checksum from the Appstore should be used to verify the release.

Appstore counter-part: nextcloud/appstore#1499

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants