Skip to content

Improve security of the solution via e.g. MD5 checksums #9

@matiwinnetou

Description

@matiwinnetou

Allowing native code to run on anybody's machine is dangerous.

  1. Currently download_libs.sh doesn't contain md5 checksums. IMHO this is necessary.
  2. Ideally a developer should never add those to native folder but actually only it should be done via CI upon verification of md5 checksums

There could be other measures / ideas taken for this but the things above should be minimum, especially that project is from cryptocurrency / where trojan horses stealing things like wallet passwords are common.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions