Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ISSUE] Checksum changed for 1.47.0? #3660

Closed
ghost opened this issue Jun 7, 2024 · 4 comments
Closed

[ISSUE] Checksum changed for 1.47.0? #3660

ghost opened this issue Jun 7, 2024 · 4 comments

Comments

@ghost
Copy link

ghost commented Jun 7, 2024

Hey folks, OpenTofu maintainer here. We received a complaint from a user that the checksum for Linux/AMD64 version 1.47.0 changed from c89f9dcd0b6159d3f15e74083c0e71dc7d799ed8ae61385b5962c8394314b684 to a4b2ebf71205365d3d30be4f288c100359a81c40da9f37e23947c9dea3521b3c and they are unable to install the provider.

Can someone with a visible org membership in the Databricks GitHub organization please confirm that this is not a supply chain attack and we are safe to reindex the provider? (We treat versions as soft-immutable to protect against supply chain attacks.)

(Also, if I may ask for an additional favor, could you please submit your public GPG key here so we can verify the binaries in the future?)

@pietern
Copy link
Contributor

pietern commented Jun 7, 2024

Hi! It is possible they observed a different hash for a very brief time window (max 15 mins). We had to run the release twice because the goreleaser action was broken (action log). The hashes you mention are both listed in the two separate job runs of goreleaser, so they are both expected.

We can submit our GPG key.

Thanks for raising this!

@pietern pietern closed this as completed Jun 7, 2024
@oliverangelil
Copy link

Issue continues to pop up right now.
Experiencing the same in two separate and independent VMs.

image

@ghost
Copy link
Author

ghost commented Jun 7, 2024

Thanks for confirming @pietern , I'll trigger the reindex shortly. Re: grace period that is not possible with our current architecture because we don't request permissions from provider authors to set up webhooks, but I opened an issue (please 👍 it) that would let provider authors request reindexing.

@oliverangelil
Copy link

fixed now. Thanks for the impressive turnaround time both!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants