-
-
Notifications
You must be signed in to change notification settings - Fork 12.9k
roxctl: fix checksum for 4.6.2 #207032
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
roxctl: fix checksum for 4.6.2 #207032
Conversation
https://github.com/stackrox/stackrox/actions?query=branch:4.6.2 The commit for version tag is changed. |
Did we also confirm this as intentional? Because that's the main problem, the tag moving can just as well be malicious. |
Diff between commits where tag was moved does not seem malicious: |
Upstream confirmed this was intentional |
🤖 An automated task has requested bottles to be published to this PR. |
HOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>
, where<formula>
is the name of the formula you're submitting?brew test <formula>
, where<formula>
is the name of the formula you're submitting?brew audit --strict <formula>
(after doingHOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>
)? If this is a new formula, does it passbrew audit --new <formula>
?found in
Tag moving evidence https://github.com/stackrox/stackrox/actions/workflows/release-ci.yaml:

matches the timeline.