Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Enabling usePackageHashValidation Feature to ClientSetup Script #247

Closed
2 tasks done
ryanrichter94 opened this issue Jun 7, 2024 · 0 comments · Fixed by #268
Closed
2 tasks done

Add Enabling usePackageHashValidation Feature to ClientSetup Script #247

ryanrichter94 opened this issue Jun 7, 2024 · 0 comments · Fixed by #268
Assignees
Labels
3 - Review This is for tickets that need to be reviewed prior to being complete. ChocolateyForBusinessAzure Issue affects Chocolatey For Business in Azure Environment. Note the issue will be synced there. Enhancement Enhancements are things that are improvements or features. Security Related to security in some way. Much of what we do is centered around security and this is higher.

Comments

@ryanrichter94
Copy link
Member

ryanrichter94 commented Jun 7, 2024

Checklist

  • I have verified this is the correct repository for opening this issue.
  • I have verified no other issues exist related to my request.

Is Your Feature Request Related To A Problem? Please describe.

With the introduction of the new usePackageHashValidation Feature with Chocolatey V 2.3.0 this seems like a no brainer to add to our standard ClientSetup client config we ship.

Describe The Solution. Why is it needed?

Adding this would be another tip in the hat to security since we setup all of our environments to pull packages out of Nexus, which supports hosting the SHA512 hash of the packages hosted in it.

Additional Context

No response

Related Issues

No response

┆Issue is synchronized with this Github issue by Unito

@ryanrichter94 ryanrichter94 added Enhancement Enhancements are things that are improvements or features. 0 - _Triaging New tickets that need to be hashed out a bit more before they hit the backlog. Security Related to security in some way. Much of what we do is centered around security and this is higher. ChocolateyForBusinessAzure Issue affects Chocolatey For Business in Azure Environment. Note the issue will be synced there. labels Jun 7, 2024
@ryanrichter94 ryanrichter94 added 1 - Ready Tickets that are on deck/assigned. All ready to go. and removed 0 - _Triaging New tickets that need to be hashed out a bit more before they hit the backlog. labels Jun 28, 2024
@steviecoaster steviecoaster self-assigned this Sep 5, 2024
steviecoaster added a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 6, 2024
With Chocolatey 2.3.0 we introduced a feature which will
validate the checksum of a downloaded nupkg with the SHA512
checksum that the repository reports.

This increases confidence that the nupkg you are installing
is in fact the nupkg you expect
steviecoaster added a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 6, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
steviecoaster added a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 6, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
JPRuskin pushed a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 24, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
JPRuskin pushed a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 30, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
JPRuskin pushed a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Sep 30, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
@ryanrichter94 ryanrichter94 added 3 - Review This is for tickets that need to be reviewed prior to being complete. and removed 1 - Ready Tickets that are on deck/assigned. All ready to go. labels Oct 1, 2024
JPRuskin pushed a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Oct 15, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
JPRuskin pushed a commit to steviecoaster/choco-quickstart-scripts that referenced this issue Oct 18, 2024
With Chocolatey 2.3.0 we introduced a feature
which will validate the checksum of a downloaded
nupkg with the SHA512 checksum that the repository
reports.

This increases confidence that the nupkg you are
installing is in fact the nupkg you expect.

This change enables the feature on the server as
it is being setup, and adds the command to turn on
the feature to the ClientSetup script.
JPRuskin added a commit that referenced this issue Oct 18, 2024
(#247) Enable packageHashValidation feature
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3 - Review This is for tickets that need to be reviewed prior to being complete. ChocolateyForBusinessAzure Issue affects Chocolatey For Business in Azure Environment. Note the issue will be synced there. Enhancement Enhancements are things that are improvements or features. Security Related to security in some way. Much of what we do is centered around security and this is higher.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants