Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

The deployment check needs sha256sum, which macOS does not have

Open Beginner friendly
#7 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
bash, shell
Domain
devops

Research direction

Start in scripts/verify-deployment.sh, where sha256sum --check --status is called at line 19 and sha256sum "$fetched" at line 30. Pick the hashing tool once at the top, falling back to shasum -a 256, and check the fixture tests/fixtures/access_policy.wasm.sha256, which both tools read. Run bash -n on the script, then simulate macOS by hiding sha256sum from PATH on Linux. Done when both tools give the same output and a mismatched fixture still exits 1.

Written by the indexing model from the issue text.

Description

bug good first issue help wanted

Written against commit 78d0a89; later commits may have moved things, so check the code first.

Size: Trivial

Description
scripts/verify-deployment.sh uses sha256sum --check --status (line 19) and sha256sum "$fetched" (line 30). macOS ships shasum (shasum -a 256) and no sha256sum unless coreutils is installed, so on a Mac the first command of the README's "Run it, from nothing" section fails with sha256sum: command not found. The README says Windows users should use WSL and says nothing about macOS, but the script otherwise only needs bash and the Stellar CLI, which both run on a Mac.

Current state

  • scripts/verify-deployment.sh lines 19 and 30.
  • tests/fixtures/access_policy.wasm.sha256 is in sha256sum format (<hash> <file>), which shasum -a 256 -c also reads.

What to build
Pick the tool once at the top (sha256sum if present, else shasum -a 256, else the missing-tool message from the sibling issue) and use it for both the check and the hash. Keep the output and exit codes the same.

Acceptance criteria

  • The script gives the same output with either tool (show both, even if you can only run one for real: say which you could not run).
  • A fixture that does not match the pin still exits 1 with the same message.
  • bash -n scripts/verify-deployment.sh passes.

Out of scope
Windows without WSL.

Verification
bash scripts/verify-deployment.sh on Linux; on macOS, or with sha256sum hidden from PATH on Linux (env PATH=...).

Dominant language
Rust
Stars
2
Forks
2
Avg merge
49m
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Sorogate/example-consumer

All issues in Sorogate/example-consumer

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.