Skip to content

fix: add SHA-256 checksum verification for geoipupdate deb package#133

Open
atelal wants to merge 1 commit into19.0from
fix/geoip-checksum
Open

fix: add SHA-256 checksum verification for geoipupdate deb package#133
atelal wants to merge 1 commit into19.0from
fix/geoip-checksum

Conversation

@atelal
Copy link
Contributor

@atelal atelal commented Mar 23, 2026

Summary

  • Add SHA-256 checksum verification for the geoipupdate .deb package download in the Dockerfile, mirroring the existing pattern used for wkhtmltopdf
  • Prevents potential supply chain attacks by validating package integrity before installation

Closes #63

Test plan

  • Build Docker image for amd64: docker build --platform linux/amd64 -f docker/Dockerfile -t openspp:test .
  • Build Docker image for arm64: docker build --platform linux/arm64 -f docker/Dockerfile -t openspp:test .
  • Verify build fails if checksum is tampered with

🤖 Generated with Claude Code

Closes #63

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@gemini-code-assist
Copy link

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the security posture of the Docker image build process by introducing SHA-256 checksum verification for the geoipupdate Debian package. By validating the integrity of this critical dependency, the changes mitigate risks associated with compromised packages and ensure that only trusted binaries are installed, thereby strengthening the overall supply chain security.

Highlights

  • Enhanced Security: Implemented SHA-256 checksum verification for the geoipupdate Debian package download within the Dockerfile. This prevents potential supply chain attacks by validating package integrity before installation.
  • Architecture-Specific Checksums: Added distinct SHA-256 checksums for both amd64 and arm64 architectures, ensuring robust verification across different build environments.
  • Consistent Verification Pattern: Mirrored the existing checksum verification pattern used for wkhtmltopdf, standardizing security practices for third-party package downloads.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request enhances security by adding SHA-256 checksum verification for the geoipupdate package download in the Dockerfile. The implementation correctly mirrors the existing pattern for wkhtmltopdf and prevents potential supply chain attacks. The changes also include a subtle but important fix to the filename variable, which improves caching behavior. I have one suggestion to make the download command more robust.

Comment on lines 232 to 233
curl -sSL -o "$GEOIP_DEB" \
"https://github.com/maxmind/geoipupdate/releases/download/v${GEOIP_UPDATER_VERSION}/geoipupdate_${GEOIP_UPDATER_VERSION}_linux_${TARGETARCH}.deb"; \

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

It's a good practice to use the -f (--fail) flag with curl in scripts. This flag causes curl to exit with a non-zero status code (22) on server errors (like 404 Not Found), which will be immediately caught by set -e. Without it, curl might download an HTML error page and exit successfully, causing the build to fail later at the checksum verification step with a less direct error message.

        curl -sSLf -o "$GEOIP_DEB" \
            "https://github.com/maxmind/geoipupdate/releases/download/v${GEOIP_UPDATER_VERSION}/geoipupdate_${GEOIP_UPDATER_VERSION}_linux_${TARGETARCH}.deb"; \

@codecov
Copy link

codecov bot commented Mar 23, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 69.96%. Comparing base (a8efe28) to head (79c4961).
⚠️ Report is 1 commits behind head on 19.0.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             19.0     #133      +/-   ##
==========================================
- Coverage   69.96%   69.96%   -0.01%     
==========================================
  Files         832      832              
  Lines       48813    48768      -45     
==========================================
- Hits        34154    34121      -33     
+ Misses      14659    14647      -12     
Flag Coverage Δ
spp_base_common 90.26% <ø> (ø)
spp_programs 45.51% <ø> (ø)
spp_security 66.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 11 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Docker image: Add at least SHA-256 hash check for GeoIP deb package

1 participant