Skip to content

fix: verify installer scripts with bundled checksums - #192

Closed
fengmk2 wants to merge 2 commits into
mainfrom
fix/verify-installer
Closed

fengmk2 wants to merge 2 commits into
mainfrom
fix/verify-installer

Conversation

@fengmk2

@fengmk2 fengmk2 commented Oct 8, 2026

Copy link
Copy Markdown
Member

Installer downloads previously ran without integrity checks. A compromised download source could execute code on CI runners.

GitHub Actions, GitLab, and Azure now check installer scripts against bundled SHA-256 checksums before execution. Download URLs use immutable upstream commits. The checks also cover mirrors and legacy helpers.

Known versions keep their matching installer. Dist-tags, preview builds, and unknown versions use a default installer with a bundled checksum. If all version-specific sources fail, installation also uses this default. Changes to installer scripts require a setup-vp update.

@fengmk2
fengmk2 force-pushed the fix/verify-installer branch from ad25c27 to 1c8d652 Compare October 8, 2026 06:03
@fengmk2 fengmk2 closed this Oct 8, 2026
@fengmk2
fengmk2 deleted the fix/verify-installer branch October 8, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant