Hide Pre-1.038 firmware versions

Open
#288 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
50/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Domain
security

Research direction

Start by opening the referenced upgrade/download.html page and locating where firmware versions and file hashes are presented. Determine how versions below 1.0.38 are currently listed, then update the page to hide or clearly flag them and explain that users should compare the displayed hash with the value on their device. Verify the resulting wording and version list on the webpage.

Written by the indexing model from the issue text.

Description

Following the December 2025 vulnerabilty disclosure, perhaps the blockstream website should not list/recommend/offer the vulnerable firmware versions anymore. Or flag them as such. all those <1.0.38

Webpage is: https://jadefw.blockstream.com/upgrade/download.html

And thanks for now listing the file hashes when running the Serial/usb web updater on that page :) 👍 .

I do however suggest that some explananation below that text, to prompt the the user to match the hash value on the device, would now be the next webpage update.
The Jade product is aimed at Beginners/Intermediate users who are still learning to know to do that.

Thx!
M

Dominant language
C
Stars
497
Forks
131
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Blockstream/Jade

All issues in Blockstream/Jade

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.