Open
Description
https://www.apache.org/info/verification.html says:
"Signatures and checksums are only available from the official Apache Software Foundation site."
I think that is no longer true, as they are also available from the CDN.
Whilst that is an official site, it cannot also be 'the site'.
Also other documentation says to only download these from apache.org/dist => downloads.apache.org.
The page is also not clear on what users are supposed to do to check a download. I think it should say that at least one of the methods should be used, ideally using the sig, but failing that please at least check the hash.
Metadata
Metadata
Assignees
Labels
No labels
Activity