devcontainers / devcontainers/features

Avoid piping curl'ed scripts into bash

Abierto
#412 3 comentarios 0 reacciones 1 asignado Reclamado por @samruddhikhandale Ver en GitHub
Lenguaje dominante
Shell
Estrellas
1.5k
Forks
621
Merge medio
6 d 53 min
PR fusionados (30 d)
9

Descripción

In 3 installers (java, node, ruby), the install.sh script includes a step where a script is curl'ed and piped into bash:
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/java/install.sh#L155
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/node/install.sh#L121
https://github.com/devcontainers/features/blob/7a3a9c5fcaa59cf4d7dbbcece47094a6d642a9b0/src/ruby/install.sh#L211

Those could be entrypoints for supply chain attacks. I think it would be preferable if these tools could be installed using a step that does checksum verification on the bash scripts before running them.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.