devcontainers / devcontainers/features

Avoid piping curl'ed scripts into bash

Open
#412 3 comments 0 reactions 1 assignee Claimed by @samruddhikhandale View on GitHub
Dominant language
Shell
Stars
1.5k
Forks
621
Avg merge
2d 11h
Merged PRs (30d)
4

Description

In 3 installers (java, node, ruby), the install.sh script includes a step where a script is curl'ed and piped into bash:
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/java/install.sh#L155
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/node/install.sh#L121
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/ruby/install.sh#L211

Those could be entrypoints for supply chain attacks. I think it would be preferable if these tools could be installed using a step that does checksum verification on the bash scripts before running them.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.