MantisBT - CMake
View Issue Details
0016060CMakeCMakepublic2016-04-12 17:522016-06-10 14:21
raysatiro 
 
normalmajoralways
closedno change required 
 
 
0016060: Chrome warns cmake installer is harmful program
Using Chrome Version 49.0.2623.112 m I'm trying to download the cmake installer:

"The site ahead contains harmful programs

Attackers on cmake.org might attempt to trick you into installing programs that harm your browsing experience (for example, by changing your homepage or showing extra ads on sites you visit)."

https://cmake.org/download/ [^] and click on cmake-3.5.1-win32-x86.msi
https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html?hl=en-US#url=https://cmake.org/files/v3.5/cmake-3.5.1-win32-x86.msi [^]
No tags attached.
png cmake chrome says harmful programs.PNG (29,755) 2016-04-12 17:52
https://public.kitware.com/Bug/file/5674/cmake%20chrome%20says%20harmful%20programs.PNG
png
Issue History
2016-04-12 17:52raysatiroNew Issue
2016-04-12 17:52raysatiroFile Added: cmake chrome says harmful programs.PNG
2016-04-13 08:17Brad KingNote Added: 0040850
2016-04-15 08:15Brad KingNote Added: 0040864
2016-04-15 08:15Brad KingStatusnew => resolved
2016-04-15 08:15Brad KingResolutionopen => no change required
2016-04-15 14:38raysatiroNote Added: 0040870
2016-04-15 14:46Brad KingNote Added: 0040871
2016-06-10 14:21Kitware RobotNote Added: 0041192
2016-06-10 14:21Kitware RobotStatusresolved => closed

Notes
(0040850)
Brad King   
2016-04-13 08:17   
Yes, we are aware that this is happening. It is almost certainly a false positive and we are trying to have it fixed.

You can verify the download by checking the SHA-256 sum of the file:

d8ab3b5dd6ba6de6c88f676dc78bbc83aa3a5ffcdc0aa7b59a8007eeceb15241 cmake-3.5.1-win32-x86.msi

You can download these to see a gpg signature of our originally uploaded files:

 https://cmake.org/files/v3.5/cmake-3.5.1-SHA-256.txt [^]
 https://cmake.org/files/v3.5/cmake-3.5.1-SHA-256.txt.asc [^]
(0040864)
Brad King   
2016-04-15 08:15   
This seems to be resolved now.
(0040870)
raysatiro   
2016-04-15 14:38   
Thanks, I can confirm there's no warning for cmake-3.5.2-win32-x86.msi in Chrome 50.0.2661.75 m. I am curious, do you know what set off their detector, was it a problem with 3.5.1 or a false positive?
(0040871)
Brad King   
2016-04-15 14:46   
Re 0016060:0040870: There was nothing wrong with the 3.5.1 binary. It was a false positive. They were even triggering on some of the source .zip files!
(0041192)
Kitware Robot   
2016-06-10 14:21   
This issue tracker is no longer used. Further discussion of this issue may take place in the current CMake Issues page linked in the banner at the top of this page.