The file is also not signed so the checksums are not trustworthy anyway. 
Please sign the releases as we did in the past.

On 08/26/2015 10:28 AM, Antoine Pitrou wrote:
>
> Hello,
>
> The SourceForge download page for 1.10.0b1 mentions:
>
>   89e467cec774527dd254c1e039801726db1367433053801f0d8bc68deac74009
>   numpy-1.10.0b1.tar.gz
>
> But after downloading the file I get:
>
> $ sha256sum numpy-1.10.0b1.tar.gz
> 855695405092686264dc8ce7b3f5c939a6cf1a5639833e841a5bb6fb799cd6a8
> numpy-1.10.0b1.tar.gz
>
>
> Also, since SouceForge doesn't provide any HTTPS downloads (it
> actually redirects HTTPS to HTTP (*)), this all looks a bit pointless.
>
> (*) seems like SourceForge is becoming a poster child of worst
> practices...
>
> Regards
>
> Antoine.
_______________________________________________
NumPy-Discussion mailing list
NumPy-Discussion@scipy.org
http://mail.scipy.org/mailman/listinfo/numpy-discussion

Reply via email to