Skip to content

Please provide a signed version of install.ps1 #326

@dpaoliello

Description

@dpaoliello

The PowerShell install script (install/install.ps1) is currently unsigned, requiring anyone running it to bypass PowerShell's execution policy, potentially allowing a vector for a supply-chain attack (especially since it isn't obvious or easy to get a hash of the install scripts so that clients can verify them).

Can you please provide a signed version of the script - either checked-in or as part of the release artifacts.

Metadata

Metadata

Assignees

Labels

questionFurther information is requestedsecurityImprovements, bugfixes, or issues related to security

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions