-
Notifications
You must be signed in to change notification settings - Fork 227
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Files for new release 2.64.1 are missing in release.jfrog.io #2669
Comments
Thank you for reporting this issue @bb-Ricardo. |
Hi @eyalbe4, thank you, I was able to download the binaries and it works now in my case. Just a question: Is it planned to release checksum files or signatures as well, in order to be able to verify the binary is the actual release binary? Should I open another issue for that? |
Happy to hear the issue is resolved @bb-Ricardo. |
I know it sounds a bit crazy but we build our own repository and software installer for all sorts of standalone binaries which are used in our systems and pipelines and mostly are not part of any repository. While adding new releases to our repository we check the integrity of the binaries to lower the risk of supply chain attacks. Ideally it would look like this:
This can be usually done via cosign or GPG. Public keys which are published can then be used to verify the signature and therefore the checksums. Even if someone compromises the release.jfrog.io Artifactory instance and exchanges the binaries with malicious copies/versions, the integrity check would fail. |
@bb-Ricardo
Please let us know if that helps. |
Hi, I'm aware of the possibility to request the checksum vie It seems that this topic needs a separate issue. |
Describe the bug
A new version (2.64.1) of frog-cli was released on GitHub but the links to the release files under https://releases.jfrog.io/ui/repos/tree/General/jfrog-cli/v2-jf/2.64.1 return with 404.
Current behavior
Files are missing
Reproduction steps
try to download the files from the 2.64.1 release
Expected behavior
Files for release 2.64.1 be present
JFrog CLI version
2.64.1
Operating system type and version
any
JFrog Artifactory version
No response
JFrog Xray version
No response
The text was updated successfully, but these errors were encountered: