I know CURL is open source but my superior ask me if the tool allowed according by CIS benchmark?
I really don't know. To do SFTP file transfer of sensitive files.
Is it okay to trust this tool to SFTP and not doing hidden additional tasks like sending to another hidden server in some mailcious country
Please let me know of your thought on this tool for CIS benchmark and security if deployed with task scheduler in a hardened window server.
Thanks :)
This Open source project is also hosted in GITHUB
seeing the GITHUB security policy as per below may be the code should be safe
https://github.com/security/team Application Security We identify, fix, and prevent security issues across the GitHub platform through security design review, automated and manual code assessment, and developer education.