Skip to content

Harden installer downloads and security ownership paths - #66121

Closed
pelikhan with Copilot wants to merge 3 commits into
mainfrom
copilot/aw-top-10-hardening-install-scripts
Closed

pelikhan with Copilot wants to merge 3 commits into
mainfrom
copilot/aw-top-10-hardening-install-scripts

Conversation

Copilot AI commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Mutable installer downloads and non-deterministic setup steps left supply-chain gaps; compiler and CLI paths also lacked explicit code ownership.

  • Verified installs: Pin gh-aw installer URLs to an immutable commit and verify SHA-256 before execution. Pin sq and uv releases and verify their downloaded packages.
  • Safe temporary files: Use mktemp with cleanup traps for generated installer downloads.
  • Code ownership: Add CODEOWNERS rules for parser, workflow compiler, CLI, and cmd/gh-aw.
  • Token-minting docs: Confirmed the existing references and specs already document this behavior.

Example generated install:

install_script="$(mktemp)"
trap 'rm -f "$install_script"' EXIT
curl -fsSL "$PINNED_URL" -o "$install_script"
printf '%s  %s\n' "$EXPECTED_SHA256" "$install_script" | sha256sum -c -
bash "$install_script"

Copilot AI and others added 2 commits October 6, 2026 12:32
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Harden install scripts and security ownership paths Harden installer downloads and security ownership paths Oct 6, 2026
Copilot AI requested a review from pelikhan October 6, 2026 12:34
@pelikhan pelikhan closed this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 10 Harden install scripts and security ownership paths

2 participants