Skip to content

Security: verify downloaded remediation tools#112

Merged
JayRHa merged 1 commit into
mainfrom
security/verify-downloaded-tools
May 15, 2026
Merged

Security: verify downloaded remediation tools#112
JayRHa merged 1 commit into
mainfrom
security/verify-downloaded-tools

Conversation

@JayRHa
Copy link
Copy Markdown
Owner

@JayRHa JayRHa commented May 14, 2026

Summary

  • add SHA-256 validation for downloaded DelProf and SetACL binaries
  • remove downloaded binaries when hash validation fails
  • call SetACL through an explicit verified path instead of direct path execution

Verification

  • pwsh parse check for updated remediation scripts
  • Invoke-ScriptAnalyzer focused security rules: PSAvoidUsingInvokeExpression, PSAvoidUsingConvertToSecureStringWithPlainText, PSAvoidUsingPlainTextForPassword
  • git diff --check

@JayRHa JayRHa merged commit 66e6801 into main May 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants