Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#68140 - [hunspell-en] use https, sha256
Attached to Project:
Arch Linux
Opened by T.J. Townsend (blakkheim) - Wednesday, 07 October 2020, 18:38 GMT
Last edited by Andreas Radke (AndyRTR) - Friday, 09 October 2020, 05:19 GMT
Opened by T.J. Townsend (blakkheim) - Wednesday, 07 October 2020, 18:38 GMT
Last edited by Andreas Radke (AndyRTR) - Friday, 09 October 2020, 05:19 GMT
|
DetailsDescription:
Attached diff switches the hunspell-en package to use HTTPS for downloads and upgrades from MD5 to SHA256 for verification. Sources were verified to match the previous MD5 (for what little that's worth). |
This task depends upon
Comment by T.J. Townsend (blakkheim) -
Wednesday, 07 October 2020, 18:47 GMT
Minor correction for the description: switched from SHA1, not MD5.
Comment by Andreas Radke (AndyRTR) -
Friday, 09 October 2020, 05:19 GMT
Fixed the downloads in svn trunk. SourceForge does offer only sha1sums to verify the source. That's still better than to check against a selfcomputed checksum using some more secure algorithm.
hunspell-en.diff