Validate checksums of downloaded files
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start by inventorying the PowerShell scripts and their download paths. Determine where official SHA-256 values can be obtained for each downloaded binary, then verify downloads against those values and cover both matching and mismatching cases. Done means every internet-downloaded binary is rejected when its checksum does not match.
Written by the indexing model from the issue text.
Description
It's important for secure tool supply chain management that all packages that get downloaded from the internet get validated to be the same bits as officially published. Please add validating sha256 checksum of any downloaded binaries to ensure the bits downloaded are official and haven't been tampered with.
- Dominant language
- PowerShell
- Stars
- 213
- Forks
- 120
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/install-scripts
-
up-for-grabs
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
dotnet/install-scripts#686 · 2 reactions ·
-
untriaged
Difficulty 3/5 1-2 days Newbie friendliness 52/100
dotnet/install-scripts#741 ·
-
area-infra
dotnet/install-scripts#699 · 2 reactions · 1 assignee ·
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
dotnet/install-scripts#595 · 5 comments ·
-
needs-pm-discussion
Difficulty 5/5 Over a week Newbie friendliness 35/100
dotnet/install-scripts#580 · 1 comment · 5 reactions ·
All issues in dotnet/install-scripts
Similar issues
-
bug carvel-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
carvel-dev/kapp-controller#1861 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Expose REVIEW_PATH_SPEC as a review.yml input to scope the diff (skip vendored/reference paths) Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
microsoft/BC-ALAgents#71 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
k3s-io/k3s-ansible#565 ·