32-bit
zipgithub.com · known platform- SHA-256
- 9978e1bae2e20a9cf9cba32d7e98bedcdf892159a613f23755e354512c057e46
by The Syncthing Authors · MPL-2.0
Open Source Continuous File Synchronization
These URLs are the ones The Syncthing Authors declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what The Syncthing Authors published. Delete it.
Windows · PowerShell
Get-FileHash "syncthing-windows-amd64-v2.1.2.zip" -Algorithm SHA256macOS · Linux
shasum -a 256 "syncthing-windows-amd64-v2.1.2.zip"Expected output
4626c13012e9620ece2393bfc3300aeafead654695d5dc096a873c27a7543c96
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 3 of 3 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 3 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 3 of 3 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 1 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | MPL-2.0A declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions Syncthing registers itself to handle.
Every version with a published manifest, newest first. Useful when you need an older build for compatibility.