Skip to content

Request to add PGP signature, or hashes. #1295

@jgratero

Description

@jgratero

It has been quite a while since I inquired about this:

SHA256, MD5 hashes...

But, I keep wondering, given that things are different now (supply chain attacks are now a thing, like the one experienced by Noteplus++), wouldn't it make sense to add a)Hashes to compare files, or b) a PGP signature, that gives us the chance to ascertain that the files being downloaded are indeed coming from you?

As it is, Windows Smartscreen is already blocking the last release. The issue is not overriding it, as this not a particularly difficult task. I can certainly do it. The issue is: How can I know that the warning from Smartscreen is a false positive (and therefore, discard it), if I cannot be sure that this file is coming from you? Because I have nothing to attest it otherwise.

Thank you for hearing this concern.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions