Visitar URL original
Let's document how to verify a Node.js downloads on the website · Issue #7942 · nodejs/nodejs.org · GitHub
Skip to content

Let's document how to verify a Node.js downloads on the website #7942

Description

@aduh95

As discussed in nodejs/node#58904 (comment), the way we document how to verify Node.js downloads is not ideal, and there seems to be consensus for switching our recommendation from the public OpenPGP.org server to our own nodejs/release-keys repository. On top of changes in the nodejs/node README, we should also host on the website what is the trusted way to verify a Node.js download.

What we need to provide on the website (presumably on the Downloads page) would be:

  • a git commit hash to a revision of nodejs/release-keys that contain keys to all.
  • a SHA-256 of the gpg-only-active-keys/pubring.kbx on that revision.

Opening this now in case it involves design changes, but it shouldn't land until after the nodejs/node README is edited (currently it still points to keys.openpgp.org as the recommended source).

Activity

  1. the-gabe commented on Jul 3, 2025

    @the-gabe
  2. aduh95 commented on Jul 3, 2025

    @aduh95
    Author
  3. the-gabe commented on Jul 3, 2025

    @the-gabe
  4. aduh95 commented on Jul 3, 2025

    @aduh95
    Author
  5. NoWayJA commented on Jul 3, 2025

    @NoWayJA
  6. MikeMcC399 commented on Jul 9, 2025

    @MikeMcC399
  7. aduh95 commented on Jul 9, 2025

    @aduh95
    Author
  8. MikeMcC399 commented on Jul 9, 2025

    @MikeMcC399
    Contributor

    I've marked my previous post as off-topic, as it concerns details of how to verify Node.js downloads. Instead I note that the https://nodejs.org/en/download page already links to the https://github.com/nodejs/node#verifying-binaries section and to avoid repeating information, I suggest to leave it that way without making changes to the website

    Image
  9. aduh95 commented on Jul 9, 2025

    @aduh95
    ContributorAuthor

    the https://nodejs.org/en/download page already links to the https://github.com/nodejs/node#verifying-binaries section and to avoid repeating information, I suggest to leave it that way without making changes to the website

    The idea behind having the information on the website is that if, for whatever reason, you cannot (or don't want to) access and/or trust github.com, having the information on the website provides an alternative.
    Repeating the information does indeed come with downsides (more maintenance burden to keep it up-to-date), but also with upsides (mainly the info is more broadly available). There's a tradeoff to be made, and maybe the current link is the "right" tradeoff, or maybe not, I don't claim consensus on that point to be clear.

  10. AugustinMauroy commented on Jul 13, 2025

    @AugustinMauroy
    Member

    Antoine can we just fetch (on SSR) GH raw and display it with our style ?

  11. MikeMcC399 commented on Jul 28, 2025

    @MikeMcC399
    Contributor

    @aduh95

    There's a tradeoff to be made, and maybe the current link is the "right" tradeoff, or maybe not, I don't claim consensus on that point to be clear.

    I would tend to keep it simple and retain just the current link https://github.com/nodejs/node#verifying-binaries where the content has just been updated. The keyrings are located on GitHub (https://github.com/nodejs/release-keys), so there is a reliance there in any case.

  12. joyeecheung commented on Nov 2, 2025

    @joyeecheung
    Member

    We are discussing it again in nodejs/node#60490 and at least @aduh95 and I agree that this should not be in the Node.js README because it clutters the README with too many details that should be in a dedicated page. I suggest that we just move that information to the website and let the README link the website instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions