Skip to content

Please provide a signed version of install.ps1 #326

@dpaoliello

Description

@dpaoliello

The PowerShell install script (install/install.ps1) is currently unsigned, requiring anyone running it to bypass PowerShell's execution policy, potentially allowing a vector for a supply-chain attack (especially since it isn't obvious or easy to get a hash of the install scripts so that clients can verify them).

Can you please provide a signed version of the script - either checked-in or as part of the release artifacts.

Metadata

Metadata

Assignees

Labels

questionFurther information is requestedsecurityImprovements, bugfixes, or issues related to security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions