lackdaz / saddle

Import files into raspbian images
0 stars 1 forks source link

security: pishrink.sh possibly supply chain attack vector #1

Open mdegans opened 3 years ago

mdegans commented 3 years ago

https://github.com/lackdaz/saddle/blob/fbc58a1efa37a2f4ce4c2b6588596c21feaf650a/saddle.sh#L17

A specific commit should probably be referenced and signature(s) of pishrink itself checked.

mdegans commented 3 years ago

Have addressed this. Will submit PR shortly.