-
Notifications
You must be signed in to change notification settings - Fork 80
Download signature with installer #139
Comments
I'm leaning towards no on this issue because I feel like this will give users a false sense of security GitHub does become compromised. |
Not sure where a false sense of security could be given. Even if Github is compromised and both the This issue is simply about convenience without any security change. |
Of course, to be absolutely sure I'd have to meet you in person and verify that the public key I have retrieved is really yours. ;-) |
Would it be reasonable to assume that if any of the release files are tampered with, that the files used in the |
But I didn't request the install script to perform the GPG verification, did I? ;-) Again, all I'm requesting is to conveniently download the |
The installer script currently only downloads the latest
.phar
. To check the integrity of that file, one has to manually download the matching signature (see #123) from Github releases.It would be useful if the installer did this automatically and download the
box.phar.sig
next to thebox.phar
, thus one can simply rungpg --verify box.phar.sig box.phar
afterwards.The text was updated successfully, but these errors were encountered: