-
-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Fix: Add checksum verification of dynamic asm downloads #877
Conversation
Thank you for creating a pull request!Please check out the information below if you have not made a pull request here before (or if you need a reminder how things work). Code Quality and Contributing GuidelinesIf you have not done so already, please familiarise yourself with our Contributing Guidelines and Code Of Conduct, even if you have contributed before. TestsGithub actions will run a set of jobs against your PR that will lint and unit test your changes. Keep an eye out for the results from these on the latest commit you submitted. For more information, please see our testing documentation. In order to run the advanced pipeline tests (executing a set of mock pipelines), it requires an admin to post |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Simplicity suggestion
Also suggest adding Ref: TOB-TEMURIN-xx
in the description as a reference for these fixes :-)
Noting that downloading and using an MD5 checksum file from the same place as the tarball is not ideal, but since the version can be dynamically obtained from a build.properties
file we can't hard code it along with the version number (unless we add that to build.properties)
I'm ok to approve this as-is so we have some sort of check, but we should create an issue to come up with a better solution for the future.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approving, but as per earlier comment let's get another issue created to look at doing this in a better way in the future - and to look for other similar instances
ping @karianna for rereview |
Fixes #876
Include MD5 checksum verification of ASM downloads.