Data or code is accepted without verifying it really came from the expected source.
Upgrade and verify signatures/checksums on the affected data.
Verify signatures and integrity hashes on anything you download or trust.
Stateward flags Insufficient Verification of Data Authenticity in your own code and dependencies on every pull request.
Scan my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.