3 ms·
Building the entire backbone of a CI product based on `bash <(curl` script. Honestly. This is more like Play stupid games, win stupid prizes. Did someone even a
by rdsubhas 5y ago
Building the entire backbone of a CI product based on `bash <(curl` script. Honestly. This is more like Play stupid games, win stupid prizes. Did someone even attempt to google "don't run random scripts from the internet" here?
There is a world of a difference between offering a "bash <(curl" for one-off development/laptop use vs. giving official instructions to put it in a automation scripts. If someone is uploading code coverage reports for some language – they have way better, safer options. Maven packages, `go run`, npm packages, deb packages, etc. All of these have better security and checksumming built in.
From what's seen in the report, even all their other products (github app, etc) were built on top of this bash uploader script, and even their own hosted solutions did not validate their checksum. Looks like they were pretty seriously pushing "just source a script from internet" as an official principle. Of course the CI was backdoored. Facepalm.
- whydoyoucare 5y ago"bash <(curl" is the new cool. Mind-boggling number of projects pull this sh*, look at https://brew.sh/ https://brew.sh/ for instance.