Commit 8fab25f
Verify rustup-init binary with SHA256 checksum instead of curl-pipe-sh
Download the rustup-init binary directly and verify its SHA256 checksum
before execution, instead of piping the shell installer script through sh.
Pin rustup-init to version 1.29.0 with hardcoded SHA256 checksums for
amd64 and arm64, matching the existing cosign verification pattern.
This prevents a compromised server from serving a tampered binary with
a matching checksum.
(cherry picked from commit 1b28933)
Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
1 parent 1a75f9e commit 8fab25f
File tree
4 files changed
+104
-3
lines changed- .github/workflows
- scripts/docker
4 files changed
+104
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| 119 | + | |
| 120 | + | |
119 | 121 | | |
120 | | - | |
| 122 | + | |
121 | 123 | | |
122 | 124 | | |
123 | 125 | | |
| |||
141 | 143 | | |
142 | 144 | | |
143 | 145 | | |
144 | | - | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
122 | 122 | | |
123 | 123 | | |
124 | 124 | | |
| 125 | + | |
| 126 | + | |
125 | 127 | | |
126 | 128 | | |
127 | 129 | | |
| |||
493 | 495 | | |
494 | 496 | | |
495 | 497 | | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
496 | 525 | | |
497 | 526 | | |
498 | 527 | | |
| |||
508 | 537 | | |
509 | 538 | | |
510 | 539 | | |
| 540 | + | |
511 | 541 | | |
512 | 542 | | |
513 | 543 | | |
| |||
1843 | 1873 | | |
1844 | 1874 | | |
1845 | 1875 | | |
| 1876 | + | |
| 1877 | + | |
| 1878 | + | |
| 1879 | + | |
1846 | 1880 | | |
1847 | 1881 | | |
1848 | 1882 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
| 65 | + | |
| 66 | + | |
65 | 67 | | |
66 | 68 | | |
67 | 69 | | |
| |||
433 | 435 | | |
434 | 436 | | |
435 | 437 | | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
436 | 465 | | |
437 | 466 | | |
438 | 467 | | |
| |||
448 | 477 | | |
449 | 478 | | |
450 | 479 | | |
| 480 | + | |
451 | 481 | | |
452 | 482 | | |
453 | 483 | | |
| |||
1646 | 1676 | | |
1647 | 1677 | | |
1648 | 1678 | | |
| 1679 | + | |
| 1680 | + | |
| 1681 | + | |
1649 | 1682 | | |
1650 | 1683 | | |
1651 | 1684 | | |
| |||
1805 | 1838 | | |
1806 | 1839 | | |
1807 | 1840 | | |
1808 | | - | |
| 1841 | + | |
1809 | 1842 | | |
1810 | 1843 | | |
1811 | 1844 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| 31 | + | |
| 32 | + | |
31 | 33 | | |
32 | 34 | | |
33 | 35 | | |
| |||
399 | 401 | | |
400 | 402 | | |
401 | 403 | | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
402 | 431 | | |
403 | 432 | | |
404 | 433 | | |
| |||
414 | 443 | | |
415 | 444 | | |
416 | 445 | | |
| 446 | + | |
417 | 447 | | |
418 | 448 | | |
419 | 449 | | |
| |||
0 commit comments