Skip to content

GHC downloads are unsigned

Hi,

I recently came across a feature that is patched in 7.6 but not in 7.4; cause to upgrade. The Haskell website has binary downloads, ie http://www.haskell.org/ghc/download_ghc_7_6_1#x86_64linux but there are no SHA1 hashes or GPG signatures.

This may seem like busy work, but it's important to know who is building software and how it was built. Would it be possible to first of all post md5sums or sha1sums of the builds, and then down the road get that file GPG signed by someone responsible for the process?

Not sure where best to file this; sorry for noise if this is the wrong place.

AfC

Trac metadata
Trac field Value
Version 7.6.1
Type FeatureRequest
TypeOfFailure OtherFailure
Priority normal
Resolution Unresolved
Component Build System
Test case
Differential revisions
BlockedBy
Related
Blocking
CC
Operating system
Architecture
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information