thii / aws-codebuild-extras

Add extra information of your AWS CodeBuild build via environment variables.
150 stars 115 forks source link

suggestion to fork, as a security precaution? #12

Closed PatNeedham closed 4 years ago

PatNeedham commented 4 years ago

Excellent library, thank you for making the Github branch name available inside CodeBuild! As was noted on a StackOverflow answer, it's potentially dangerous to run curl to obtain the install script in this repo, due to the non-zero chances of an account breach. What do you think about giving mention to that concern in the README, along with a suggestion to fork the repo, so that folks who still want this solution can do so by accessing it from their own repos?

thii commented 4 years ago

Ah yeah. You can also lock the curl command to a known commit. I’ll update the README.