0

It seems that the author of a project can upload arbitrary binary files on the release page, and I don't see a way to verify that the binary is actually built from the source code without malicious modifications.

Surprisingly after some search, I did not find discussions on this potential issue. Is it that I've missed something, or people simply just trust those binaries?

schroeder
  • 123,438
  • 55
  • 284
  • 319
Mayoi
  • 1
  • I removed github because this issue applies to any open source project (or any released binaries, for that matter). – schroeder Jan 25 '20 at 22:39
  • @schroeder Thank you, I finally received the answer after asking a question here. – Mayoi Jan 25 '20 at 22:43

0 Answers0