T08 · Insecure Dependencies
- Location
references/install.md:13- Finding
Downloaded ossutil Executable Is Installed and Run Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
' 'ossutil.zip' | sha256sum --check --strict - unzip ossutil.zip ``` 3. Prefer verification using a vendor-provided cryptographic signature whose public key is obtained through an independently authenticated channel. 4. Do not place the executable in `/usr/local/bin` unless verification succeeds. 5. Extract into a newly created private temporary directory and inspect the expected archive layout before moving any file. 6. Prefer an authenticated, vendor-supported package repository where available, while retaining package signature verification. 7. Document separate pinned checksums for Linux and macOS artifacts and update them through a controlled release process. 8. Where practical, run the version check and initial validation in a restricted environment before granting the binary access to Alibaba Cloud credentials. ]]>
