Checksums of release files
Posted: Wed Mar 09, 2016 7:04 pm
Hi,
would it be possible to generate and publish checksums (MD5, SHA1, SHA256, SHA512) of the release files? Many distributions use them (or GPG signatures) to verify integrity. Instead of calculating them for every distribution (and the files might have been maliciously altered already), it would be good to have them available from the trusted source (where the source archives and builds are actually created). Shouldn't be hard to add the checksum-calculating-step to the scripts generating the archives and builds now.
Opinions?
would it be possible to generate and publish checksums (MD5, SHA1, SHA256, SHA512) of the release files? Many distributions use them (or GPG signatures) to verify integrity. Instead of calculating them for every distribution (and the files might have been maliciously altered already), it would be good to have them available from the trusted source (where the source archives and builds are actually created). Shouldn't be hard to add the checksum-calculating-step to the scripts generating the archives and builds now.
Opinions?