dra icon indicating copy to clipboard operation
dra copied to clipboard

Verify checksum of the downloaded file before extraction

Open iilyak opened this issue 1 year ago • 3 comments

It would be cool to be able to check the integrity of the download before extracting.

iilyak avatar Jan 21 '25 17:01 iilyak

HI! Yes, it might be a nice to have feature

devmatteini avatar Jan 25 '25 14:01 devmatteini

Hi there, what and amazing tool you've written I've wanted something like this integrated into asdf because maintaining the plugins is a thankless horrible jump.

I've also cross posted to here:-

https://github.com/asdf-vm/asdf/issues/1318

Anyway back to the subject.. I saw this announcement https://github.blog/changelog/2025-06-03-releases-now-expose-digests-for-release-assets/

so maybe this could be used to protect against corrupted downloads or mitm attacks

Dang, tested it and they only supported new releases and confirmed on the community chat

https://github.com/orgs/community/discussions/23512

gilesw avatar Jun 20 '25 13:06 gilesw

Hi there, what and amazing tool you've written I've wanted something like this integrated into asdf because maintaining the plugins is a thankless horrible jump.

Hi, I'm happy you found dra useful!

Anyway back to the subject.. I saw this announcement https://github.blog/changelog/2025-06-03-releases-now-expose-digests-for-release-assets/

so maybe this could be used to protect against corrupted downloads or mitm attacks

Dang, tested it and they only supported new releases and confirmed on the community chat

https://github.com/orgs/community/discussions/23512

Yeah, it looks like this is the easiest way to integrate the checksum verification. Even if it only works for newer releases, I think it's fine as a trade-off.

devmatteini avatar Jun 28 '25 12:06 devmatteini