installer: no integrity pin for curl|bash of install.sh #534

Open
opened 2026-08-20 02:55:23 +02:00 by dries · 0 comments
Owner

Found during review of PR #524 (feat: add one-line installer and service manager). Needs a maintainer decision on posture.

The documented one-liner fetches install.sh from the main branch over HTTPS with no tag or checksum pin. Anyone (or any CI state) that can move main changes what users execute; there is also no way to reproduce "the installer as of release X".

Options, in increasing weight:

  1. Pin the curl URL to a release tag (.../raw/tag/vX.Y.Z/install.sh) and bump it in the README as part of the release flow.
  2. Publish a checksum next to the release artifacts and have the README one-liner verify it before piping to bash.
  3. Accept the risk explicitly (self-hosted Forgejo, single maintainer) and note it in the README.

The script itself already fails closed (set -euo pipefail, quoted, HTTPS-only default, no sudo), so this is purely about pinning the entry point.

Found during review of PR #524 (feat: add one-line installer and service manager). Needs a maintainer decision on posture. The documented one-liner fetches `install.sh` from the `main` branch over HTTPS with no tag or checksum pin. Anyone (or any CI state) that can move `main` changes what users execute; there is also no way to reproduce "the installer as of release X". Options, in increasing weight: 1. Pin the curl URL to a release tag (`.../raw/tag/vX.Y.Z/install.sh`) and bump it in the README as part of the release flow. 2. Publish a checksum next to the release artifacts and have the README one-liner verify it before piping to bash. 3. Accept the risk explicitly (self-hosted Forgejo, single maintainer) and note it in the README. The script itself already fails closed (`set -euo pipefail`, quoted, HTTPS-only default, no sudo), so this is purely about pinning the entry point.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dries/ocman#534
No description provided.