Dockerfile supply chain risks?
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 45/100
研究方向
先檢查將 curl 回應透過管線傳給 bash,或下載 release 封存檔與套件的 Dockerfile 指令。確認目前如何取得每個相依項目,並判斷是否能一致地加入 checksum 驗證;完成的標準是,列出的下載內容在執行或安裝前驗證受信任的 checksum。
由索引模型根據 Issue 內容生成。
描述
I'm seeing this in the Dockerfile:
RUN curl -fsSL https://claude.ai/install.sh | bash
RUN curl -fsSL https://fnm.vercel.app/install | bash -s -- ...
RUN sh -c "$(curl -fsSL https://github.com/deluan/zsh-in-docker/releases/download/v${ZSH_IN_DOCKER_VERSION}/zsh-i
And these:
curl -fsSL "https://github.com/dandavison/delta/releases/download/${GIT_DELTA_VERSION}/git-delta_${GIT_DELTA_VERSION}_${ARCH}.deb" -o /tmp/git-delta.deb
dpkg -i /tmp/git-delta.deb
curl -fsSL "https://github.com/junegunn/fzf/releases/download/v${FZF_VERSION}/fzf-${FZF_VERSION}-${FZF_ARCH}.tar.gz" | t
All of those seem like supply-chain risks. I would love to see this with checksum verification, if feasible. Given that you're security experts, I'm assuming I'm looking at this wrong, but I wanted to raise the issue and be sure. I am not a security expert.
- 主要語言
- Shell
- 星號
- 945
- 分支
- 103
- 平均合併
- 47 分鐘
- 30 天內合併 PR
- 2
環境準備
- 提供 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 沒有貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
trailofbits/claude-code-devcontainer 的其他 Issue
-
難度 5/5 一週以上 新手友好度 25/100
-
難度 3/5 1-2 天 新手友好度 48/100
trailofbits/claude-code-devcontainer#36 · 1 則留言 · 2 個 reaction ·
查看 trailofbits/claude-code-devcontainer 的全部 Issue
相似的 Issue
-
bot-found bug priority: P3
難度 2/5 1-3 小時 新手友好度 84/100
madenvel/KalinkaPlayer#179 ·
-
documentation
難度 2/5 1-3 小時 新手友好度 72/100
-
難度 2/5 1-3 小時 新手友好度 86/100
jbaruch/coding-policy#621 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 90/100
mattpocock/skills#1134 ·
-
area:build bug P3
難度 1/5 1 小時以內 新手友好度 92/100
uttrflow/uttrflow-swift#2506 ·
維護者通常 1 天內回覆