Libraries and Device Descriptions
Safeguard your own repositories and check the contents
Target group: End users, system administrators
Description: Compiled libraries (*.compiled-library-v3) and device descriptions, which are sourced from your own or customer-specific repositories, form a separate supply chain that is beyond the control of CODESYS. The internal audit processes, with which CODESYS safeguards its own packages and extensions, do not apply to this content. CODESYS 4 uses a cryptographic hash (SHA-384) in the Libraries.lock.json file to safeguard resolved artifacts against subsequent changes and copies them to the working directory.
Action: Safeguard your library repository and device repository against unauthorized modification via file system permissions and only add contents from trusted sources.
Reasoning: A manipulated library or device description can inject malicious code into compiled projects, which can then be distributed to the controllers.