A03: checksum-verify downloaded toolchain binaries in CI #13

Closed
opened 2026-08-13 09:35:03 +00:00 by nalum · 0 comments
Owner

CI fetches version-pinned binaries over HTTPS with no integrity check:

  • cosign (release.yml:100-104 plus 3 repeats) — the sharpest edge: the binary that signs every release artifact is itself fetched unverified, so a compromise of that download path subverts the whole signing scheme flux trusts
  • timoni (release.yml:297-301)
  • flux (release.yml:356-360)
  • Android cmdline-tools (release.yml:244, android.yml:49)
  • protoc (android.yml:73)

Fix: pin a sha256 alongside each version and verify after download — one echo "<sha> <file>" | sha256sum -c per fetch.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

CI fetches version-pinned binaries over HTTPS with no integrity check: - cosign (`release.yml:100-104` plus 3 repeats) — the sharpest edge: the binary that signs every release artifact is itself fetched unverified, so a compromise of that download path subverts the whole signing scheme flux trusts - timoni (`release.yml:297-301`) - flux (`release.yml:356-360`) - Android cmdline-tools (`release.yml:244`, `android.yml:49`) - protoc (`android.yml:73`) **Fix**: pin a sha256 alongside each version and verify after download — one `echo "<sha> <file>" | sha256sum -c` per fetch. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:39:26 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#13
No description provided.