JarSignVerifier should check all zip entries
HyCraftHD opened this issue ยท 0 comments
Currenty the JarSignVerifier only checks the manifest and the .class files if they are signed.
We should also check all other resources excluding directories and the certificate files with the end .SF .DSA .EC .RSA