Let's document how to verify a Node.js downloads on the website
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Documentazione
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- git, nextjs, nodejs, typescript
- Ambito
- documentation, security, web-dev
Direzione di ricerca
Inizia esaminando la pagina Downloads del sito web e la modifica correlata al README di nodejs/node, prendendo nota della dipendenza dalla raccomandazione aggiornata. Documenta una revisione attendibile di nodejs/release-keys e lo SHA-256 del relativo gpg-only-active-keys/pubring.kbx; il lavoro è completo quando le istruzioni per la verifica sono pubblicate sul sito web.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
As discussed in https://github.com/nodejs/node/issues/58904#issuecomment-3031456396, the way we document how to verify Node.js downloads is not ideal, and there seems to be consensus for switching our recommendation from the public OpenPGP.org server to our own nodejs/release-keys repository. On top of changes in the nodejs/node README, we should also host on the website what is the trusted way to verify a Node.js download.
What we need to provide on the website (presumably on the Downloads page) would be:
- a git commit hash to a revision of nodejs/release-keys that contain keys to all.
- a SHA-256 of the
gpg-only-active-keys/pubring.kbxon that revision.
Opening this now in case it involves design changes, but it shouldn't land until after the nodejs/node README is edited (currently it still points to keys.openpgp.org as the recommended source).
- Lingua principale
- TypeScript
- Stelle
- 6.9k
- Fork
- 6.5k
- Merge medio
- 2g 9h
- PR unite (30g)
- 29
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nodejs/nodejs.org
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
nodejs/nodejs.org#9162 · 1 commento ·
-
web-agenda
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
nodejs/nodejs.org#9098 · 3 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
nodejs/nodejs.org#8828 · 4 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 55/100
nodejs/nodejs.org#9166 · 3 commenti · 1 reazione ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
nodejs/nodejs.org#9140 · 10 commenti · 3 reazioni ·
Tutte le issue di nodejs/nodejs.org
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
bug v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
modelcontextprotocol/inspector#2458 · 1 commento ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
carbon-design-system/ibm-products#9907 ·