installer: no integrity pin for curl|bash of install.sh #534
Labels
No labels
backend
bug
chore
duplication
effort:complex
effort:medium
effort:trivial
enhancement
follow-up
frontend
fullstack
priority:high
ready-for-agent
refactor
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
dries/ocman#534
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found during review of PR #524 (feat: add one-line installer and service manager). Needs a maintainer decision on posture.
The documented one-liner fetches
install.shfrom themainbranch over HTTPS with no tag or checksum pin. Anyone (or any CI state) that can movemainchanges what users execute; there is also no way to reproduce "the installer as of release X".Options, in increasing weight:
.../raw/tag/vX.Y.Z/install.sh) and bump it in the README as part of the release flow.The script itself already fails closed (
set -euo pipefail, quoted, HTTPS-only default, no sudo), so this is purely about pinning the entry point.