Travis Response to Meltdown Attack
blog.travis-ci.com
blog.travis-ci.com
* They use 32-bit id to retrieve an OpenPGP key (meaning that anybody can get their key added to the APT keyring):
https://github.com/travis-ci/travis-build/pull/1269
* Here they are identifying OpenPGP keys with HTTP URLs (sometimes with 32-bit id, too):
https://github.com/travis-ci/apt-source-whitelist/blob/maste...
* But none of the above matters much, because they use APT with the --force-yes, which among other things, disables package authentication:
https://github.com/travis-ci/travis-build/commit/c4d15425f7b...
[I reported the --force-yes bug to the security team in October 2017, but AFAICS nothing changed nice then.]
* https://github.com/travis-ci/apt-package-whitelist is just bizarre. They try to to detect "malicious or goofy bits" with grep. What.
And these are just things I stumbled upon randomly...
If you're using Travis CI only for testing stuff, you should be fine. If you're using it for deployment, you're doing it wrong.