Skip to content

RFE: Signed Versions / Checksums #1311

Closed
@goldzahn

Description

@goldzahn

Hi,

for security reasons I would appreciate OPENPGP-Signatures for the files provided under https://www.owasp.org/index.php/OWASP_Dependency_Check (Download: http://dl.bintray.com/jeremy-long/owasp/).

Maybe it's easier first to provide checksums of the files on https://www.owasp.org/index.php/OWASP_Dependency_Check (would not be too easy to attack the Owasp-Server and the download server). Checksums on the download server would not really make sense from a security standpoint as it would be no problem to also put the checksum of the forged program there.

Thanks
Regards
Tim

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions