devcontainers / devcontainers/features
Avoid piping curl'ed scripts into bash
- Vorherrschende Sprache
- Shell
- Sterne
- 1.5k
- Forks
- 621
- Ø Merge
- 6 T. 53 Min.
- Gemergte PRs (30 T.)
- 9
Beschreibung
In 3 installers (java, node, ruby), the install.sh script includes a step where a script is curl'ed and piped into bash:
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/java/install.sh#L155
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/node/install.sh#L121
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/ruby/install.sh#L211
Those could be entrypoints for supply chain attacks. I think it would be preferable if these tools could be installed using a step that does checksum verification on the bash scripts before running them.
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.