Skip to content
This repository was archived by the owner on Jan 25, 2023. It is now read-only.

Releases page lists only MD5 checksums #165

Open
nbros652 opened this issue Dec 5, 2019 · 0 comments
Open

Releases page lists only MD5 checksums #165

nbros652 opened this issue Dec 5, 2019 · 0 comments

Comments

@nbros652
Copy link

nbros652 commented Dec 5, 2019

Webpage: https://github.com/sentinel-official/sentinel/releases

Issue: The only checksums listed for releases are MD5 checksums. While this may be sufficient for verifying against file corruption, it is really insufficient for verifying against file tampering. The generation of an MD5 checksum collision is not difficult and does not necessarily result in significant changes in file size.

Suggested Change: Include checksums that are less susceptible to collisions. Perhaps, it would be better to include a SHA256 checksum.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant