feat: add SHA256 verification for direct downloads
Store SHA256 hashes when running update scripts and verify them
when downloading files at build time. This improves security by
detecting unexpected changes to downloaded artifacts.
Platforms covered: macOS (CPython, PyPy, GraalPy), iOS, Android,
virtualenv, and python-build-standalone. Windows (nuget) and
Linux (Docker) are excluded.
SHA256 sources per platform:
- macOS/iOS/Android CPython (python.org): sha256_sum from API
- GraalPy: .sha256 sidecar assets from GitHub releases
- python-build-standalone: SHA256SUMS file in release
- PyPy, BeeWare iOS, Maven (Chaquopy): stream-download and compute
Changes:
- cibuildwheel/util/file.py: add sha256 param to download()
- cibuildwheel/platforms/{macos,ios,android}.py: add sha256 to
PythonConfiguration and pass to download()
- cibuildwheel/venv.py: read sha256 from toml and pass to download()
- cibuildwheel/util/python_build_standalone.py: add sha256 to
PythonBuildStandaloneAsset and pass to download()
- cibuildwheel/resources/build-platforms.toml: add sha256 fields
- cibuildwheel/resources/virtualenv.toml: add sha256 field
- cibuildwheel/resources/python-build-standalone-releases.json: add sha256
- bin/update_pythons.py: compute/store sha256 per source strategy
- bin/update_virtualenv.py: compute sha256 by streaming download
- bin/update_python_build_standalone.py: parse SHA256SUMS file
Closes #908
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
This commit is contained in:
co-authored by
Copilot
parent
e3e7cc9e07
commit
97537fe937
@@ -3,6 +3,7 @@
|
||||
# /// script
|
||||
# dependencies = [
|
||||
# "cibuildwheel",
|
||||
# "requests",
|
||||
# ]
|
||||
#
|
||||
# [tool.uv.sources]
|
||||
@@ -11,6 +12,8 @@
|
||||
|
||||
import json
|
||||
|
||||
import requests
|
||||
|
||||
from cibuildwheel.extra import github_api_request
|
||||
from cibuildwheel.util.python_build_standalone import (
|
||||
PythonBuildStandaloneAsset,
|
||||
@@ -34,8 +37,27 @@ def main() -> None:
|
||||
f"repos/astral-sh/python-build-standalone/releases/tags/{latest_tag}"
|
||||
)["assets"]
|
||||
|
||||
# Build a sha256 map from the SHA256SUMS file in the release
|
||||
sha256_sums_urls = [
|
||||
ga["browser_download_url"] for ga in github_assets if ga["name"] == "SHA256SUMS"
|
||||
]
|
||||
name_to_sha256: dict[str, str] = {}
|
||||
if sha256_sums_urls:
|
||||
response = requests.get(sha256_sums_urls[0])
|
||||
response.raise_for_status()
|
||||
for line in response.text.splitlines():
|
||||
parts = line.split()
|
||||
if len(parts) == 2:
|
||||
sha256_hex, filename = parts
|
||||
# The filename may have a leading "./" or spaces - strip it
|
||||
name_to_sha256[filename.lstrip("./")] = sha256_hex
|
||||
|
||||
assets = [
|
||||
PythonBuildStandaloneAsset(name=ga["name"], url=ga["browser_download_url"])
|
||||
PythonBuildStandaloneAsset(
|
||||
name=ga["name"],
|
||||
url=ga["browser_download_url"],
|
||||
sha256=name_to_sha256.get(ga["name"], ""),
|
||||
)
|
||||
for ga in github_assets
|
||||
if ga["name"].endswith("install_only.tar.gz")
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user