Hacker News new | ask | show | jobs
by zalmoxes 3331 days ago
Which package manager? :P
1 comments

What OS are you using?
Just to let people know, Handbrake is on Homebrew Cask in macOS.
Sadly Homebrew is terrible for this, the developer guide for how to get the hash for the files you're downloading is literally to just test run the download with an empty hash in the brew file, and it will calculate the hash from the file on the website. In this case Homebrew would not help, as galad87 mentions here https://news.ycombinator.com/reply?id=14282116&goto=item%3Fi....
And, what's your proposed alternative for calculating a hash?

Btw, we treat hash changes very seriously in homebrew-core; they are never merged without a confirmation from the upstream. Unfortunately Cask apparently doesn't live up to the same standard, but Homebrew Cask is not really Homebrew.

...which used the hash of the compromised version for ~3 days.