Skip to content

Supply-chain hardening for build and install dependencies #1138

Description

@mmguero

Malcolm's Dockerfiles and setup scripts download external images, source,
and binaries, some by mutable reference (tags like latest, branch URLs, or
"latest release" lookups) and without checksum verification. This issue
tracks reducing that exposure. It was prompted by an external report, which
was closed in favor of tracking the work here.

Planned work, roughly in priority order:

  • Pin mutable references to images and repositories we control, starting
    with ghcr.io/mmguero/qemu-live-iso:latest in the malcolm-iso and
    hedgehog-raspi Dockerfiles
  • In the AWS AMI setup script, pin each binary installed by
    InstallUserLocalBinaries to a specific version and verify its
    SHA-256 against a hash stored in the repository before installing it.
    Install the expected executable by name rather than the first
    executable found in the archive
  • Add sha256sum -c verification for versioned binary downloads in the
    Dockerfiles, starting with those installed into runtime images
  • Evaluate Renovate or Dependabot to pin base images by digest and keep
    versions and checksums current through automated PRs
  • Replace remaining raw-branch downloads with pinned commits or release
    tags

Checksums should be stored in this repository rather than fetched from the
same location as the artifact, since a compromised release could replace
both.

Users who need hardened, verified builds today can use Malcolm's Iron Bank
images
.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingbuildFor issues related to compilation/buildingdockerRelating to docker and docker-compose as used by MalcolmsecurityRelated to issues with bearing on the security of Malcolm itself

Type

Fields

No fields configured for Task.

Projects

  • Status
    No status

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions