Search code examples
securitycurlserversftpbatch-processing

How safe is using CURL to do SFTP file transfer of sensitive files?


I know CURL is open source but my superior ask me if the tool allowed according by CIS benchmark?

I really don't know. To do SFTP file transfer of sensitive files.

Is it okay to trust this tool to SFTP and not doing hidden additional tasks like sending to another hidden server in some mailcious country

Please let me know of your thought on this tool for CIS benchmark and security if deployed with task scheduler in a hardened window server.

Thanks :)


Solution

  • This Open source project is also hosted in GITHUB

    seeing the GITHUB security policy as per below may be the code should be safe

    https://github.com/security/team Application Security We identify, fix, and prevent security issues across the GitHub platform through security design review, automated and manual code assessment, and developer education.