Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-60031

URL SCM needs to be able to verify a checksum

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Major Major
    • urlscm-plugin
    • None

      It should be possible, when providing the URL, to fill out the expected checksum (SHA1, SHA256, whatever). As it downloads, the plugin will calculate the digest using the specified algorithm, and fail, if the downloaded file does not match the expectation.

      This is an important security-related feature – to guard against someone substituting the downloaded sources with their own version (either in transit or after hacking the file-repository).

            mdonohue mdonohue
            unitedmarsupials Mikhail T
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: