Good afternoon! Thanks for maintaining this! I could not find any checksum published next to the prebuilt archives under static-php-cli/bulk/ and common/ (for example php-8.4.17-cli-linux-x86_64.tar.gz): no <file>.sha256, no SHA256SUMS per directory, and nothing in the listing or README.txt. #958 and the 3.0 RFC (#959) cover verifying spc's own build inputs, not these outputs.
I'm building a tool that downloads these builds for users (vivace, a Composer-compatible installer, viv php install). Today the best it can do is record its own hash after the first download, which catches later corruption but not a tampered or truncated first fetch.
Would you be willing to publish a SHA256SUMS file per directory, or a .sha256 sibling per archive, from the same CI job that uploads them? Either is enough for a client to verify; per-file siblings are simpler for a client that fetches one archive. Signing is a separate, bigger step; checksums alone would close the gap for download integrity over a redirecting CDN.
Thanks for your consideration!
Good afternoon! Thanks for maintaining this! I could not find any checksum published next to the prebuilt archives under
static-php-cli/bulk/andcommon/(for examplephp-8.4.17-cli-linux-x86_64.tar.gz): no<file>.sha256, noSHA256SUMSper directory, and nothing in the listing orREADME.txt. #958 and the 3.0 RFC (#959) cover verifying spc's own build inputs, not these outputs.I'm building a tool that downloads these builds for users (vivace, a Composer-compatible installer,
viv php install). Today the best it can do is record its own hash after the first download, which catches later corruption but not a tampered or truncated first fetch.Would you be willing to publish a
SHA256SUMSfile per directory, or a.sha256sibling per archive, from the same CI job that uploads them? Either is enough for a client to verify; per-file siblings are simpler for a client that fetches one archive. Signing is a separate, bigger step; checksums alone would close the gap for download integrity over a redirecting CDN.Thanks for your consideration!