Skip to content
This repository has been archived by the owner on Sep 5, 2020. It is now read-only.

0.8.10 not signed, and insecure checksum given in release #2272

Closed
VoidingWarranties opened this issue May 16, 2017 · 9 comments
Closed

0.8.10 not signed, and insecure checksum given in release #2272

VoidingWarranties opened this issue May 16, 2017 · 9 comments

Comments

@VoidingWarranties
Copy link

Part of this has already been brought up in #2236, but I don't think the issue was sufficiently addressed.

I have two concerns:

  1. For 0.8.10, MD5 checksums were listed for the prebuilt binaries instead of SHA256.
  2. The 0.8.10 tag was not signed, when the previous 4 release tags have been signed.

Why the sudden discrepancy in the release process?

@evertonfraga
Copy link
Member

@luclu can you change our build server to generate SHA256 checksums again?

@luclu
Copy link
Contributor

luclu commented May 16, 2017

@evertonfraga with pleasure, I will also update them for the geth bins as the sha256 checking routine has now been included for over 5 releases.
Could you please take a look at the signing, as I did that in a rush during the travis/upload issues?

@luclu luclu self-assigned this May 16, 2017
@hwinkler
Copy link

Weird this hasn't been fixed yet. Nobody should install an unsigned binary, that's a bad habit to get into where valuable data is at stake. Can you please escalate? It would be good to see the signing become well established as part of your build process, and unquestioned.

@paulfreeman
Copy link

What is the status of this issue? Mac OSX version 8.10 has incorrect file name associated with MD5 checksum. Version for download is not named 'unsigned'' and downloaded version is actually signed.

@hwinkler
Copy link

hwinkler commented Jun 6, 2017

Lack of response gives me an uncomfortable feeling about Ethereum processes.

@evertonfraga
Copy link
Member

As promised, v0.8.10 tag is now signed and its corresponding builds have SHA-256 checksums.

https://github.com/ethereum/mist/releases/tag/v0.8.10

@evertonfraga
Copy link
Member

@hwinkler we had a huge amount of issues opened in the last weeks, due to increasing attention drawn to ethereum. That slowed down our ability to cope with the issues, but we're working on this.

I am closing this, thanks.

@evertonfraga
Copy link
Member

SHA-256 checksums are back on our build process: #2917

Also, they are listed on v0.9.0 release. Thanks.

@lock
Copy link

lock bot commented Mar 30, 2018

This thread has been automatically locked because it has not had recent activity. Please open a new issue for related bugs and link to relevant comments in this thread.

@lock lock bot unassigned luclu Mar 30, 2018
@lock lock bot locked and limited conversation to collaborators Mar 30, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

5 participants