Now that we have a way to make sure the manifest is from Mozilla with bug 600034, we can include hashes in the manifest to ensure the downloaded .xpi is what was expected.
http://hg.mozilla.org/labs/sigma/rev/7833539dfa02 Give AddonManager the sha1 hash from the manifest to let it verify the file hash on download.
Assignee: nobody → edilee
Status: NEW → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.