Skip to content

Conversation

@AaronChen0
Copy link
Contributor

@AaronChen0 AaronChen0 commented Jul 30, 2025

Close #1986

Tested on https://github.com/AaronChen0/shadowsocks-rust/actions/runs/16648845765.
I will update the links if musl.cc get any updates.

@zonyitoo zonyitoo merged commit 71ee956 into shadowsocks:master Aug 4, 2025
17 checks passed
@shadowsocks69420
Copy link
Contributor

shadowsocks69420 commented Aug 4, 2025

I think sha512sum check at build time should be added for this one as the content of the link it points to can be altered by the author at anytime without anyone noticing.

@zonyitoo For the time being, I suggest we create a new repository under the shadowsocks org then move the same artifacts to the newly created repository so that only trusted individuals can modify them. This should be fairly trivial IMO.

@AaronChen0
Copy link
Contributor Author

AaronChen0 commented Aug 4, 2025

I had actually thought about this issue before, but I am not familiar with docker at all, never use it. Pull requests are welcome if you can add hardcoded sha512sum check.

Yes. Moving the artifacts to a new repo of shadowsocks org is preferred.

@zonyitoo
Copy link
Collaborator

zonyitoo commented Aug 6, 2025

I think sha512sum check at build time should be added for this one as the content of the link it points to can be altered by the author at anytime without anyone noticing.

@zonyitoo For the time being, I suggest we create a new repository under the shadowsocks org then move the same artifacts to the newly created repository so that only trusted individuals can modify them. This should be fairly trivial IMO.

That is reasonable. @madeye what do you think?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Docker image v1.23.5 is missing

3 participants