Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to verify integrity of package #9

Closed
lewismc opened this issue Jan 18, 2022 · 3 comments
Closed

Unable to verify integrity of package #9

lewismc opened this issue Jan 18, 2022 · 3 comments

Comments

@lewismc
Copy link

lewismc commented Jan 18, 2022

Hi @kei6u , we tried out this package and it works very well. Thanks for putting it together.
When we install it via krew it states the following in bright red

WARNING: You installed plugin "secretdata" from the krew-index plugin repository.
These plugins are not audited for security by the Krew maintainers.
Run them at your own risk.

This is a problem for us. I wonder if there is any way to begin performing security auditing on the plugin? This way more people may have confidence in using it...

Again, thanks for putting the project together. Please don't take this as a criticism. It is just a concern when we are dealing with sensitive data.

@keisku
Copy link
Owner

keisku commented Jan 19, 2022

@lewismc
Thank you for reporting!
I will look into it to solve the warning.

@keisku
Copy link
Owner

keisku commented Jan 19, 2022

@lewismc

Investigation:
The warning when installing this plugin via krew also occur in other plugin installation due to kubernetes-sigs/krew#576.

The reason we added this is because users must understand that they are downloading potentially unvetted binaries.

This pr added the feature to output the warning message.

Conclusion:
Every plugin installation via krew outputs the warning and there is no way to prevent it currently.

@keisku keisku closed this as completed Jan 27, 2022
@lewismc
Copy link
Author

lewismc commented Feb 2, 2022

Thank you for doing the investigation @kei6u and apologies for my late response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants