mirror of
https://github.com/astral-sh/setup-uv.git
synced 2026-09-21 12:28:49 +00:00
Verify downloads with astral-sh/versions checksums (#1033)
`setup-uv` currently ignores the `sha256` supplied by the default `astral-sh/versions` manifest when a selected artifact is newer than its bundled checksum table, allowing that download to proceed without validation. Use the manifest checksum as a fallback after explicit and bundled checksums, and reject manifest entries that do not provide one. This preserves the stronger pinned hashes for known releases while verifying newer releases without requiring an action update. Part of #1032. --------- Co-authored-by: Zanie Blue <contact@zanie.dev> Co-authored-by: William Woodruff <william@yossarian.net> Co-authored-by: Kevin Stillhammer <kevin.stillhammer@gmail.com>
This commit is contained in:
@@ -227,10 +227,10 @@ describe("download-version", () => {
|
||||
expect(mockValidateChecksum).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("uses built-in checksums for default manifest downloads", async () => {
|
||||
it("uses the default manifest checksum as a fallback", async () => {
|
||||
mockGetArtifact.mockResolvedValue({
|
||||
archiveFormat: "tar.gz",
|
||||
checksum: "manifest-checksum-that-should-be-ignored",
|
||||
checksum: "manifest-checksum",
|
||||
downloadUrl: "https://example.com/uv.tar.gz",
|
||||
});
|
||||
|
||||
@@ -248,6 +248,7 @@ describe("download-version", () => {
|
||||
"x86_64",
|
||||
"unknown-linux-gnu",
|
||||
"0.9.26",
|
||||
"manifest-checksum",
|
||||
);
|
||||
});
|
||||
|
||||
@@ -400,6 +401,7 @@ describe("download-version", () => {
|
||||
"x86_64",
|
||||
"unknown-linux-gnu",
|
||||
"0.9.26",
|
||||
"manifest-checksum",
|
||||
);
|
||||
});
|
||||
|
||||
@@ -425,6 +427,7 @@ describe("download-version", () => {
|
||||
"x86_64",
|
||||
"unknown-linux-gnu",
|
||||
"0.9.26",
|
||||
"manifest-checksum",
|
||||
);
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user