Artifact Integrity Verification Missing
Overview
Downloading binary artifacts, scripts, or packages from URLs without verifying their cryptographic signatures or hashes allows man-in-the-middle attacks or compromised CDN attacks to deliver malicious code.
Remediation
- Always verify SHA256 hash of downloaded artifacts
- Use
--checksumflags where available - Use Subresource Integrity (SRI) hashes for CDN resources in HTML
- Verify GPG signatures for critical software