The checksums listed on the web page do not match when verified. I’m wondering if it’s known how long the package has been compromised.
Web page text:
(19.6 MB MB) Checksum (SHA-256):
MD5 25c35940bf4168d0cccaa45deb908634
Results:
sha256sum openpbs_23.06.06.rockylinux_8.8.zip
a4800110f7369ff35f17b401026e119a097e407637e32c2f29a85ffbc80d58cc openpbs_23.06.06.rockylinux_8.8.zip
md5sum openpbs_23.06.06.rockylinux_8.8.zip
ed60d7763c2b167858a80e78e1289a95 openpbs_23.06.06.rockylinux_8.8.zip
