Fix Alpine minirootfs download and verification #122
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
0482d84022f52df1c4e7cd43293acd0907d9495a
Natanael Copa <[email protected]>
I've noticed that the
chroot_build.shscript was downloading both the Alpine minirootfs tarball and its sha256 sum over HTTP (no HSTS). Verifying the tarball using the checksum that has also been downloaded over a non-TLS connection at the same time doesn't achieve anything security-wise.type2-runtime/scripts/chroot/chroot_build.sh
Lines 39 to 41 in 2df896e
This PR therefore adds the PGP signing pub-key of Alpine releases (
0482d84022f52df1c4e7cd43293acd0907d9495a) to the repo, downloads the PGP signature instead of the sha256 sum and verifies the tarball using that.