Getting a validation warning for markdeep script
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- javascript
- 领域
- build-system, security
调研方向
定位 casual-effects.com/markdeep/latest/markdeep.min.js 的下载和校验和验证规则。检查当前 URL 和预期 sha256 的定义方式,然后固定 artifact 版本并更新其校验和,使固定文件的验证成功。
由索引模型根据 Issue 内容生成。
描述
./casual-effects.com/markdeep/latest/markdeep.min.js: FAILED
sha256sum: WARNING: 1 computed checksum did NOT match
DANGER: Validation failed for downloaded third-party code; tampered with?
It looks like this pulls the latest version, and validates against a checksum, so it will start failing any time a new markdeep is released. We should either pin the version, or stop validating the checksum. Pinning the version is the safer choice, but I suddenly realize this is volunteering me for a pretty tedious job constantly trying to stay up to date with security bugs and such in downstream libraries. That sucks.
- 主要语言
- Haskell
- 星标
- 1.3k
- 派生
- 201
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
google/codeworld 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 78/100
-
难度 4/5 3-5 天 新手友好度 35/100
-
难度 4/5 3-5 天 新手友好度 35/100
-
my solution 未关闭
难度 4/5 3-5 天 新手友好度 25/100
-
难度 4/5 3-5 天 新手友好度 25/100
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 70/100
-
doclayout-0.6 未关闭
难度 2/5 1-3 小时 新手友好度 75/100
commercialhaskell/stackage#8126 ·
-
documentation
难度 2/5 1-3 小时 新手友好度 65/100
-
enhancement tricorder
难度 2/5 1-3 小时 新手友好度 75/100