Downloaded files silently change over time
I noticed that the download URLs for extensions (like "https://extensions.gnome.org/extension-data/${uuid}.v${version}.shell-extension.zip"
) are not static – the hash of the downloaded file changes over time even though the URL stays constant.
This is a major issue as it means that the downloads cannot be trusted.
I can't 100% exclude that there isn't a mistake on my part just yet, but there are really strong clues that suggest this is actually happening. I haven't had the possibility to actually see two different downloads just yet in order to diff them, as I only tracked their sha256sums so far.