Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Download page builds SHA-512/signature links from artifact-root instead of checksum-root

オープン 初心者向け
#185 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
75/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
css, html, jekyll

調査の方向性

この issue は download.md ファイルの 51-52 行目にあります。まず、リポジトリの _releases/ ディレクトリを探し、リリースデータの構造を理解します(checksum-root と artifact-root を探します)。テンプレートを修正して、SHA-512 と署名リンクの href に release.checksum-root を使用するようにします。Jekyll サイトをローカルでビルドし、生成されたリンクが downloads.apache.org を指し、HTML ではなくプレーンテキスト/署名ファイルを返すことを確認してテストします。

索引モデルが issue の本文から書いたものです。

説明

The SHA-512 and Signature columns on the download page link to the mirror selector rather than the canonical distribution host, so they return an HTML mirror-selection page instead of the file.

Reproduction

on https://nuttx.apache.org/download/, click any current release's SHA-512 link (e.g. 13.0.1). curl shows the difference:

Generated: https://www.apache.org/dyn/closer.lua/nuttx/12.12.0/apache-nuttx-12.12.0.tar.gz.sha512 → 200 text/html, ~21 KB mirror-picker page
Canonical: https://downloads.apache.org/nuttx/12.12.0/apache-nuttx-12.12.0.tar.gz.sha512 → 200 text/plain, 158 bytes (the hash)
Same for .asc: the generated URL returns the ~21 KB HTML page; the downloads.apache.org URL returns the 833-byte PGP signature.

Root cause:

download.md:51-52 builds the .sha512/.asc hrefs from release.artifact-root. Every release file defines checksum-root (and key-file) for exactly this purpose — present since the first Apache release file (be0ee1f, 9.0.0, May 2020) — but no template reads them; the same commit wired the columns to artifact-root instead. A repo-wide grep confirms checksum-root/key-file are write-only (only other hit is the dormant generator helpers/syncbbrelease.py).

Scope:

affects all mirror-served Apache releases (9.1.1, 10.0.1, 10.1.0–13.0.1). Archive rows (9.0.0, 9.1.0, 10.0.0) have checksum-root == artifact-root, so they are unaffected and need no special handling. The page text itself (download.md:68-69) already states hashes/signatures are hosted at Apache, and the closer.lua page advises fetching signatures from the main distribution site rather than a mirror.

Proposed fix (scoped to download.md:51-52 only): build the SHA-512 and Signature hrefs from release.checksum-root, leaving the Archive column on artifact-root. Suggested regression check: assert built SHA/ASC hrefs start with each release's checksum-root and return non-HTML 200s.

主要言語
CSS
スター
24
フォーク
37
平均マージ
1時間 39分
マージ済み PR(30日)
1

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

apache/nuttx-website のほかの issue

apache/nuttx-website の issue をすべて見る

似ている issue

Documentation の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。