Closed
Description
Description
Gitea build process was found not reproducible. Please force strict verification against committed checksums for every dependency to avoid surprises and to better protect against supply chain attacks.
npi ci
should probably be used instead npm install
and break install process if any checksum mismatch occurs. Same for go modules (if works different now).
Related: #29326 (comment)
Gitea Version
1.21
Can you reproduce the bug on the Gitea demo site?
No
Log Gist
No response
Screenshots
No response
Git Version
No response
Operating System
No response
How are you running Gitea?
Compiled from sources.
Database
MySQL/MariaDB