-
Notifications
You must be signed in to change notification settings - Fork 453
Supply-chain hardening for build and install dependencies #1138
Copy link
Copy link
Open
Labels
bugSomething isn't workingSomething isn't workingbuildFor issues related to compilation/buildingFor issues related to compilation/buildingdockerRelating to docker and docker-compose as used by MalcolmRelating to docker and docker-compose as used by MalcolmsecurityRelated to issues with bearing on the security of Malcolm itselfRelated to issues with bearing on the security of Malcolm itself
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingbuildFor issues related to compilation/buildingFor issues related to compilation/buildingdockerRelating to docker and docker-compose as used by MalcolmRelating to docker and docker-compose as used by MalcolmsecurityRelated to issues with bearing on the security of Malcolm itselfRelated to issues with bearing on the security of Malcolm itself
Type
Fields
No fields configured for Task.
Projects
- StatusShow more project fieldsNo status
Malcolm's Dockerfiles and setup scripts download external images, source,
and binaries, some by mutable reference (tags like
latest, branch URLs, or"latest release" lookups) and without checksum verification. This issue
tracks reducing that exposure. It was prompted by an external report, which
was closed in favor of tracking the work here.
Planned work, roughly in priority order:
with
ghcr.io/mmguero/qemu-live-iso:latestin themalcolm-isoandhedgehog-raspiDockerfilesInstallUserLocalBinariesto a specific version and verify itsSHA-256 against a hash stored in the repository before installing it.
Install the expected executable by name rather than the first
executable found in the archive
sha256sum -cverification for versioned binary downloads in theDockerfiles, starting with those installed into runtime images
versions and checksums current through automated PRs
tags
Checksums should be stored in this repository rather than fetched from the
same location as the artifact, since a compromised release could replace
both.
Users who need hardened, verified builds today can use Malcolm's Iron Bank
images.