All,

A naive question about packages like 1panel-stable-bin. It is not
malicious, but it fetches an install script at build time with
curl | sh — not in source=(), no checksum. I read the script; it is
install-count telemetry, nothing more.

The problem is that reading it proves very little. The content is
unpinned, so what I read is not necessarily what runs on the next
build. Worse, a host can serve one thing to whoever is obviously
reviewing and another to everyone else — reviewing it may actually
be counterproductive, since it tells the server it is being looked
at.

The same package also downloads its binary with curl -k, and then
verifies it against a checksum file fetched from the same host, so
a single attacker controls both halves.

None of that is evidence of bad intent. All of it means the package
cannot be reviewed in any meaningful sense.

How should such packages be treated? Genuinely asking, not
proposing:

- a packaging-guideline violation, to be reported to the
maintainer and fixed
- grounds for removal if unfixed
- acceptable, with the risk left to the user

I ask because I do not know what to write down when I review one. 
"Malicious" is clearly wrong, and "Fine" seems wrong too.

Best and cheers,
Andreas

Reply via email to