-
Notifications
You must be signed in to change notification settings - Fork 14
Open
Labels
questionFurther information is requestedFurther information is requestedsecurityImprovements, bugfixes, or issues related to securityImprovements, bugfixes, or issues related to security
Description
The PowerShell install script (install/install.ps1) is currently unsigned, requiring anyone running it to bypass PowerShell's execution policy, potentially allowing a vector for a supply-chain attack (especially since it isn't obvious or easy to get a hash of the install scripts so that clients can verify them).
Can you please provide a signed version of the script - either checked-in or as part of the release artifacts.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requestedsecurityImprovements, bugfixes, or issues related to securityImprovements, bugfixes, or issues related to security