Validate checksums of downloaded files

Open
#583 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
powershell
Domain
devops, security

Research direction

Start by inventorying the PowerShell scripts and their download paths. Determine where official SHA-256 values can be obtained for each downloaded binary, then verify downloads against those values and cover both matching and mismatching cases. Done means every internet-downloaded binary is rejected when its checksum does not match.

Written by the indexing model from the issue text.

Description

needs-pm-discussion

It's important for secure tool supply chain management that all packages that get downloaded from the internet get validated to be the same bits as officially published. Please add validating sha256 checksum of any downloaded binaries to ensure the bits downloaded are official and haven't been tampered with.

Dominant language
PowerShell
Stars
213
Forks
120
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dotnet/install-scripts

All issues in dotnet/install-scripts

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.