Skip to content

Developing formulae or casks #4861

Oct 25, 2023 · 2 comments · 2 replies
Discussion options

You must be logged in to vote

The .dmg is cryptographically signed, hence there is no need for a checksum (it is implicitly part of the signing).

That makes no sense, the checksum is there to ensure you get the correct file. If I point the cask to https://releases.threema.ch/web-electron/v1/release/Threema-compromised.dmg and sign that it is still a bad file.

Still, for you convenience, we provide a sha256 checksum here: https://releases.threema.ch/web-electron/v1/release/Threema-Latest.dmg.sha256

We don't dynamically download checksums so that doesn't help for brew.

The only way that brew can start using a checksum is if there is a versioned download from threema. Otherwise any update will break the cask for ever…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@bwagner
Comment options

Answer selected by bwagner
Comment options

You must be logged in to vote
1 reply
@SMillerDev
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants