Re: Packages Verified with MD5

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 13 January 2014 00:58, Taylor Hornby <havoc@xxxxxxxxx> wrote:
> If so, this should be fixed as soon as possible. How feasible would it
> be? Could it be as simple as making a script that:
>
> 1. Finds the 'source' and 'md5sums' lines.
> 2. Downloads the packages and checks the md5sums.
> 3. Computes the SHA256sums, and adds them to the file.
>
> If there's anything I can do to help, let me know.

Makepkg supports MD5 and the SHAs. A PKGBUILD can have multiple
checksums, but it depends on the maintainer which of them they'd
prefer to use. You can get them to deprecate the practice of using
MD5-only PKGBUILDs.

You're actually concerned about a part of the packaging process that
requires human discretion. It is up to the packager to verify that the
sources are good. They can proactively search for authentic checksums
and signatures.


--
GPG/PGP ID: C0711BF1


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux