Code or updates are downloaded and executed without verifying integrity, enabling tampering.
Upgrade and verify signatures/hashes before executing downloaded code.
Pin versions and verify cryptographic signatures on all fetched code.
Stateward flags Download of Code Without Integrity Check in your own code and dependencies on every pull request.
Scan my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.