winget install doesn't unblock files after downloading. "Open File - Security Warning" hangs deploy #9408

Closed
opened 2026-01-31 01:53:42 +00:00 by claunia · 1 comment
Owner

Originally created by @RMMSecurity on GitHub (Jul 3, 2020).

Environment

Windows build number: 10.0.18363.900

Steps to reproduce

Attempted to install Firefox on the latest build with and without -h for silent installs.

install -h -e --id Mozilla.Firefox

Expected behavior

Found Firefox [Mozilla.Firefox]
This application is licensed to you by its owner.
Microsoft is not responsible for, nor does it grant any licenses to, third-party packages.
Downloading https://download-installer.cdn.mozilla.net/pub/firefox/releases/77.0.1/win64/en-US/Firefox%20Setup%2077.0.1.msi
  ██████████████████████████████  50.5 MB / 50.5 MB
Successfully verified installer hash
Installing ...
Successfully installed!

Actual behavior

Found Firefox [Mozilla.Firefox]
This application is licensed to you by its owner.
Microsoft is not responsible for, nor does it grant any licenses to, third-party packages.
Downloading https://download-installer.cdn.mozilla.net/pub/firefox/releases/77.0.1/win64/en-US/Firefox%20Setup%2077.0.1.msi
  ██████████████████████████████  50.5 MB / 50.5 MB
Successfully verified installer hash
Installing ...
Installer failed with exit code: 1223

image

The installer downloads the file then doesn't unblock it which gives the end user a security warning. This doesn't work under a non-interactive session like as LocalSystem. This incredibly limits automated deployments.

Packages downloaded that match the hash in the winget repo should be trusted and unblocked. If there was ever any concern they shouldn't be in the main repo to begin with.

Originally created by @RMMSecurity on GitHub (Jul 3, 2020). <!-- 🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨 I ACKNOWLEDGE THE FOLLOWING BEFORE PROCEEDING: 1. If I delete this entire template and go my own path, the core team may close my issue without further explanation or engagement. 2. If I list multiple bugs/concerns in this one issue, the core team may close my issue without further explanation or engagement. 3. If I write an issue that has many duplicates, the core team may close my issue without further explanation or engagement (and without necessarily spending time to find the exact duplicate ID number). 4. If I leave the title incomplete when filing the issue, the core team may close my issue without further explanation or engagement. 5. If I file something completely blank in the body, the core team may close my issue without further explanation or engagement. All good? Then proceed! --> <!-- This bug tracker is monitored by Windows Terminal development team and other technical folks. **Important: When reporting BSODs or security issues, DO NOT attach memory dumps, logs, or traces to Github issues**. Instead, send dumps/traces to secure@microsoft.com, referencing this GitHub issue. If this is an application crash, please also provide a Feedback Hub submission link so we can find your diagnostic data on the backend. Use the category "Apps > Windows Terminal (Preview)" and choose "Share My Feedback" after submission to get the link. Please use this form and describe your issue, concisely but precisely, with as much detail as possible. --> # Environment ```none Windows build number: 10.0.18363.900 ``` # Steps to reproduce <!-- A description of how to trigger this bug. --> Attempted to install Firefox on the latest build with and without -h for silent installs. `install -h -e --id Mozilla.Firefox` # Expected behavior <!-- A description of what you're expecting, possibly containing screenshots or reference material. --> ``` Found Firefox [Mozilla.Firefox] This application is licensed to you by its owner. Microsoft is not responsible for, nor does it grant any licenses to, third-party packages. Downloading https://download-installer.cdn.mozilla.net/pub/firefox/releases/77.0.1/win64/en-US/Firefox%20Setup%2077.0.1.msi ██████████████████████████████ 50.5 MB / 50.5 MB Successfully verified installer hash Installing ... Successfully installed! ``` # Actual behavior ``` Found Firefox [Mozilla.Firefox] This application is licensed to you by its owner. Microsoft is not responsible for, nor does it grant any licenses to, third-party packages. Downloading https://download-installer.cdn.mozilla.net/pub/firefox/releases/77.0.1/win64/en-US/Firefox%20Setup%2077.0.1.msi ██████████████████████████████ 50.5 MB / 50.5 MB Successfully verified installer hash Installing ... Installer failed with exit code: 1223 ``` <!-- What's actually happening? --> ![image](https://user-images.githubusercontent.com/802527/86418923-bfaf9a80-bc9f-11ea-84f4-dbcbf7af48c7.png) The installer downloads the file then doesn't unblock it which gives the end user a security warning. This doesn't work under a non-interactive session like as LocalSystem. This incredibly limits automated deployments. Packages downloaded that match the hash in the winget repo should be trusted and unblocked. If there was ever any concern they shouldn't be in the main repo to begin with.
claunia added the Needs-TriageNeeds-Tag-Fix labels 2026-01-31 01:53:42 +00:00
Author
Owner

@DHowett commented on GitHub (Jul 3, 2020):

Sorry, you might need to file this at https://github.com/Microsoft/winget-cli

@DHowett commented on GitHub (Jul 3, 2020): Sorry, you might need to file this at https://github.com/Microsoft/winget-cli
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#9408