crusepartnership / mysqldump-to-s3

MIT License
23 stars 10 forks source link

mysqldump binary is scary #2

Open Akuli opened 6 years ago

Akuli commented 6 years ago

The repo contains a mysqldump executable, and I don't feel comfortable with trusting a random binary that came from GitHub. Can you add some instructions for where to get or how to create the binary?

Akuli commented 6 years ago

For anyone else wondering this, lambda functions seem to run in an environment similar to ec2 instances: https://docs.aws.amazon.com/lambda/latest/dg/current-supported-versions.html

So if you don't want to use the binary that comes with this repository, install mysqldump on an ec2 instance and copy the binary from its /usr/bin/mysqldump.

jpswade commented 4 years ago

Fortunately it doesn't appear to be nefarious:

https://www.virustotal.com/gui/file/f20dc631bb2c96944420e0ae45311332110107f6d9db33977cd5f539a2f582d8/details