Skip to content

Add a note/cookbook entry about how to verify the integrity of what users downloads #4097

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
fabpot opened this issue Aug 6, 2014 · 2 comments

Comments

@fabpot
Copy link
Member

fabpot commented Aug 6, 2014

As you might know (http://fabien.potencier.org/article/73/signing-project-releases), all Symfony releases are now signed (it has been the case since June 2013). It means that Git tag are signed, but it also means that we publish (https://github.com/sensiolabs/checksums) signed SHA1 for files installed by Composer.

It would be great if we could have an article explaining why checking the integrity of what users download is important and how to do it properly.

@javiereguiluz
Copy link
Member

👍

Maybe this is a duplicate of #4089?

@fabpot
Copy link
Member Author

fabpot commented Aug 6, 2014

Yep. Closing.

@fabpot fabpot closed this as completed Aug 6, 2014
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants