Skip to content

GitHub announces stance on sha256 stability

github.blog
18 pointstgamblin2 comments
On HN

Comments

If you rely on stable archives for security (ensuring you don’t accidentally trigger a tarbomb, for example), we recommend you switch to release assets instead of using source downloads.

Isn't that actually the only way you could get a zipbomb? git-archive will never generate a zipbomb...

I think they're being too lenient to be honest. Projects were assuming too much by recording and relying upon those hashes.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.