Checksum for FIrefox ESR 78.6.1 - Software Supply Chain Security
With concerns about supply chain security, I would like the ability to ensure that the file download matches a recognized checksum. Downloading from: https://www.mozilla.… (閱讀更多)
With concerns about supply chain security, I would like the ability to ensure that the file download matches a recognized checksum.
Downloading from: https://www.mozilla.org/en-US/firefox/78.6.1/releasenotes/ yields checksum SHA256 55249C4861FE521CB32D72785481A146B64812AF2ECE7341FAAA5C79ABC0F395
This does not match any of the checksums available at: https://archive.mozilla.org/pub/firefox/releases/78.6.1esr/
Best practice would be to publish the official checksum along with the release notes.
Is there another way to close the loop on this?