Prakhar Roy
07/31/2023, 5:09 AMMatt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
Prakhar Roy
07/31/2023, 5:13 AMMatt (pactflow.io / pact-js / pact-go)
Prakhar Roy
07/31/2023, 5:18 AMMatt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
Prakhar Roy
07/31/2023, 5:33 AMTimothy Jones
07/31/2023, 6:18 AMTimothy Jones
07/31/2023, 6:18 AMTimothy Jones
07/31/2023, 6:31 AMnpx -p @pact-foundation/pact-core pact-broker [other args]Matt (pactflow.io / pact-js / pact-go)
“When thinking about the CLI curl install are there approaches you can use to mitigate a supply chain attack?”on this question, I can think of a few, but we could probably think about how we as an ecosystem better guard against these things. I’ll raise at a #C05HCLA3C93 catch up
Matt (pactflow.io / pact-js / pact-go)
Yousaf Nabi (pactflow.io)
“When thinking about the CLI curl install are there approaches you can use to mitigate a supply chain attack?”1. Store a copy within your network. Some companies mirror npm with verdaccio so they have a private proxy 2. Checksum the download file, rather than using the checksum from the repo (as that could change, if say the GH repo or token is comprimised) a. when you download it the file, check it against your own checksum, and if it fails chuck it away 3. You can now use the main install script, to pin to a specific version. You can copy this script to your own codebase, and therefore know you know that the
install.sh can’t be modified
I want to keep the cli inside company network but also don’t want to miss out on any latest updates made to the CLI.
Like some sort of version controlI would assume that with this increased eye on security that would review the contents of each version bump, to ensure that it doesn’t bring in any vulns. Do you do that with other software? What considerations do you security team recommended.
Yousaf Nabi (pactflow.io)
I want to keep the cli inside company network but also don’t want to miss out on any latest updates made to the CLI.
Like some sort of version control
Any suggestions for what I can do here?
switched to the executable but still looking for a way to avoid using curl commands in my gitlab jobThis answer means you avoid needing to use curl each time in a job, and have a fixed, vendored bundle.
you can download the bundle and put it wherever you like
Prakhar Roy
07/31/2023, 2:04 PMTimothy Jones
08/01/2023, 12:52 AMYousaf Nabi (pactflow.io)