The SHA-384 checksum is good for security, of course. But it isn't of much use if the GitHub account is hacked, since both the file and the hash are on GitHub.
The composer installer is on getcomposer.com, but it has a cross-check on GitHub, so that you can verify the checksum yourself.
Shouldn't we have a cross-check as well?
The SHA-384 checksum is good for security, of course. But it isn't of much use if the GitHub account is hacked, since both the file and the hash are on GitHub.
The composer installer is on getcomposer.com, but it has a cross-check on GitHub, so that you can verify the checksum yourself.
Shouldn't we have a cross-check as well?