Skip to content

Retrieve GitHub release asset checksums from GitHub API #5480

@jdx

Description

@jdx

Discussed in #5464

Originally posted by risu729 June 29, 2025
https://github.blog/changelog/2025-06-03-releases-now-expose-digests-for-release-assets/
On June 6th, GitHub started to generate SHA256 checksums for release assets.
We could use them to verify checksums for security.

Aqua backend currently verifies checksums if they are published and declared in the aqua-registry.
aqua has a proposal about this, but we still need to reimplement it to support.
aquaproj/aqua#3911

ubi doesn't support checksum validation, but it's tracked in houseabsolute/ubi#84.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions