docs: improve uv installation and archive security guidance (#104)
This commit is contained in:
@@ -309,3 +309,7 @@ Special thanks to the OLLVM deobfuscation ecosystem contributors and everyone wh
|
||||
This project is intended solely for lawful security research, education, CTF competitions, and testing of systems that you own or have explicit authorization to assess.
|
||||
|
||||
**Unauthorized access, scanning, exploitation, disruption, data acquisition, or any other use against systems without prior permission is strictly prohibited.** Users are solely responsible for complying with applicable laws, regulations, and the authorized scope of testing. The maintainers accept no liability for misuse of this project or for any resulting damage or legal consequences
|
||||
|
||||
## Installation and download security
|
||||
|
||||
See [Installation and Download Security Guidance](docs/UV-AND-DOWNLOAD-SECURITY.md).
|
||||
|
||||
@@ -306,3 +306,7 @@ GitHub Actions 会在 Windows 与 Ubuntu 上执行同一套核心检查。
|
||||
本项目仅限用于合法的安全研究、教育、CTF 竞赛,以及对自有系统或已获得明确授权的目标进行测试。
|
||||
|
||||
**严禁在未经授权的情况下访问、扫描、利用、干扰目标或获取数据。** 使用者须自行确保其行为符合适用法律法规及授权范围;因滥用本项目造成的任何损失或法律责任,均由使用者自行承担,项目维护者不承担相关责任。
|
||||
|
||||
## 安裝與下載安全
|
||||
|
||||
請參閱[安裝與下載安全指引](docs/UV-AND-DOWNLOAD-SECURITY_zh.md)。
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
# Installation and Download Security Guidance
|
||||
|
||||
## Prefer uv for Python environments
|
||||
|
||||
Use `uv tool install <package>` for isolated command-line tools. For project dependencies, create a virtual environment first:
|
||||
|
||||
uv venv
|
||||
uv pip install -r requirements.txt
|
||||
|
||||
Do not mechanically replace every `pip` command. `uv pip` is intended for an existing virtual environment, while `uv tool install` is generally more suitable for standalone CLI tools. Prefer pinned dependency versions or a lock file for reproducible environments.
|
||||
|
||||
## Safe handling of downloaded archives
|
||||
|
||||
Reverse-engineering and security tools may trigger antivirus heuristics because they contain binaries, debuggers, packed files, or security-test data. A warning is not proof that an archive is safe or malicious.
|
||||
|
||||
Do not disable antivirus protection or blindly bypass a warning. Before opening an archive, verify that it came from the intended HTTPS repository or release page, compare its checksum or release digest when one is published, inspect its contents, and scan it with an up-to-date security product. Do not execute unknown binaries, scripts, or installers merely because an archive downloaded successfully.
|
||||
@@ -0,0 +1,16 @@
|
||||
# 安裝與下載安全指引
|
||||
|
||||
## 優先使用 uv 管理 Python 環境
|
||||
|
||||
獨立的命令列工具可使用 `uv tool install <package>` 安裝 。專案依賴則先建立虛擬環境:
|
||||
|
||||
uv venv
|
||||
uv pip install -r requirements.txt
|
||||
|
||||
不要機械式替換所有 `pip` 指令。`uv pip` 適合已建立的虛擬環境,而獨立 CLI 工具通常更適合使用 `uv tool install`。為了提升可重現性,請儘量固定依賴版本或提交 lock file。
|
||||
|
||||
## 安全處理下載的壓縮檔
|
||||
|
||||
逆向工程與安全測試工具可能包含二進位檔、除錯器、封裝檔或安全測試資料,因此容易觸發防毒軟體的啟發式偵測。防毒警告不代表已證明安全,也不代表已證明惡意。
|
||||
|
||||
請勿停用防毒軟體或盲目略過警告。開啟壓縮檔前,請確認檔案來自預期的 HTTPS repository 或 release 頁面;若有 checksum 或 release digest,請先比對;接著檢查壓縮檔內容並使用最新的安全軟體掃描。不要因為檔案能成功下載,就直接執行其中未知的二進位檔、腳本或安裝程式。
|
||||
Reference in New Issue
Block a user