Skip to content

Publish checksums beside the prebuilt binaries on dl.static-php.dev #1245

Description

@svandragt

Good afternoon! Thanks for maintaining this! I could not find any checksum published next to the prebuilt archives under static-php-cli/bulk/ and common/ (for example php-8.4.17-cli-linux-x86_64.tar.gz): no <file>.sha256, no SHA256SUMS per directory, and nothing in the listing or README.txt. #958 and the 3.0 RFC (#959) cover verifying spc's own build inputs, not these outputs.

I'm building a tool that downloads these builds for users (vivace, a Composer-compatible installer, viv php install). Today the best it can do is record its own hash after the first download, which catches later corruption but not a tampered or truncated first fetch.

Would you be willing to publish a SHA256SUMS file per directory, or a .sha256 sibling per archive, from the same CI job that uploads them? Either is enough for a client to verify; per-file siblings are simpler for a client that fetches one archive. Signing is a separate, bigger step; checksums alone would close the gap for download integrity over a redirecting CDN.

Thanks for your consideration!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions