erlef / erlef/setup-beam

Verify downloaded toolchain archives against sha256 checksums

Aperta
#456 7 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
JavaScript
Stelle
454
Fork
88
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

## Context

`erlef/setup-beam` downloads OTP, Elixir, Gleam, and rebar3 via `tc.downloadTool` without verifying checksums. Flagged during ASF allowlist review for an Apache incubating project:

- INFRA: https://issues.apache.org/jira/browse/INFRA-27826
- ASF PR: https://github.com/apache/infrastructure-actions/pull/751

ASF maintainers agreed to allow the current SHA conditional on raising this issue.

## Proposal

Two options:

**A. Fetch-at-install.** At download time, fetch the checksum upstream publishes (`builds.txt` for hex.pm, `.sha256` sibling for Gleam) and verify. Same-origin, so doesn't beat a fully-compromised mirror, but catches corruption and partial tampering. Covers OTP linux + Elixir + Gleam (3 of 6 paths). Darwin can be covered with sig-store potentially. No ongoing maintenance.

**B. Pinned `KNOWN_CHECKSUMS`** (à la [`astral-sh/setup-uv`](https://github.com/astral-sh/setup-uv/blob/main/src/download/checksum/known-checksums.ts)). Pin hashes in source via a committed map + weekly regeneration workflow. Cross-origin, covers all 6 paths. ~300 entries for supported versions.

## Questions

- Which direction fits the project?
- Concerns about maintenance for option B?

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.