4 ms·
Not only could it, downloading additional code is often the entire point. Additionally, it's common for the installer to include things like version numbers, w
by DanielDent 12y ago
Not only could it, downloading additional code is often the entire point.
Additionally, it's common for the installer to include things like version numbers, which means the hash will change with each release.
Meteor suffers from the "|sh" install pattern. Creating a Docker packaging of it that felt safe required a lot of extra work as a result:
1) Transforming the installer file into a canonical form free of version numbers. This verifies if the assumptions made about the installer are still valid. It also enables a "latest" tag which installs whatever MDG has currently published.
2) The installer is patched so it checksums the tarball it downloads.
(To be clear, I'm aware of areas both upstream and downstream in the process where unverified code could sneak in easily. But at least I can feel good about the part I'm responsible for.)