3 ms·
I've been very cautious the last couple of years due to these bad actors when looking at packages that might suit my needs. If there is no online presence of th
by Severian 3y ago
I've been very cautious the last couple of years due to these bad actors when looking at packages that might suit my needs. If there is no online presence of the source code (git anything, zips/gzs, etc), multiple packages submitted in a short time frame, or a greater than normal amount, an/or a derivation/plugin of a popular package it's usually a no-go.
For those that I do possibly trust, I then download the package (pip download) and review it. Doing a quick regex for URLs or exec() calls helps, but I probably should use something like guarddog (https://github.com/DataDog/guarddog https://github.com/DataDog/guarddog)
- woodruffw 3y agoFor what it's worth: `pip download` is capable of running arbitrary package-defined code[1], by design. You shouldn't use it as a security boundary. If you're trying to statically analyze a distribution before doing anything else with it, you should download it directly from the PEP 503[2] simple index. [1]: https://yossarian.net/res/pub/hushcon-west-2022.pdf https://yossarian.net/res/pub/hushcon-west-2022.pdf [2]: https://peps.python.org/pep-0503/ https://peps.python.org/pep-0503/
- Severian 3y agoGood to know, I was not aware of this. Thank you!
- Too 3y ago> If there is no online presence of the source code Could this be utilized the other way around? Any package that was published using official GitHub action X, would automatically be signed as being created from something with source and link to source at given revision. Of course this source could contain bad contents or download even more bad contents, at least it establishes some level of chain of supply, where the first layer of source can be inspected.
- woodruffw 3y ago> Could this be utilized the other way around? Any package that was published using official GitHub action X, would automatically be signed as being created from something with source and link to source at given revision. That's exactly the idea behind Sigstore[1] -- GitHub Actions (or any other CI system with an OIDC credential) can be leveraged for "machine identities", which in turn are bound to ephemeral signing keys. The end result is a scheme where users never have to touch or maintain a signing key while still getting all the benefits of a normal PKI-esque codesigning scheme. [1]: https://www.sigstore.dev/ https://www.sigstore.dev/