Replies: 1 comment 1 reply
-
Scoop will prompt about this.
Hash checks is to verify file integrity. For security: Use
|
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I'd like to have transparency how package authors collects check sums.
https://github.com/ScoopInstaller/Scoop/wiki/App-Manifest-Autoupdate says about
autoupdate.hash.url
.What if installer maintainers don't provide hash sums in a separate file?
What is the security of a hash sum retrieval? Is it based solely on HTTPS security of
autoupdate.hash.url
?Is that hash sum verified against virus scanners, like:
Beta Was this translation helpful? Give feedback.
All reactions