Github Labs
Explore 2 labs in Github.
This vulnerability occurs when build or deployment pipelines fail to verify the authenticity and integrity of artifacts (e.g., binaries, container images, or packages) before promotion or deployment. Attackers may tamper with artifacts in transit or compromise intermediate storage (artifact repositories, registries, caches), leading to execution of malicious code in production. Relying only on filenames, timestamps, or repository trust without cryptographic validation exposes the supply chain to substitution or replay attacks.
Remediation:
Select a language to explore available labs for this vulnerability.
Try adjusting your language filter.
Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.
Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.
Read more