Commit eab58c6
fix(ci): add sha256 checksum verification for binary downloads
gitleaks 8.21.2 and osv-scanner 1.8.5 downloads now verified against
official release checksums before execution.
SR-1 resolution: addresses Low finding from CTO security review.
Co-Authored-By: Paperclip <noreply@paperclip.ing>1 parent 8028d92 commit eab58c6
1 file changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
33 | 34 | | |
34 | 35 | | |
35 | 36 | | |
| 37 | + | |
36 | 38 | | |
37 | 39 | | |
38 | 40 | | |
| |||
55 | 57 | | |
56 | 58 | | |
57 | 59 | | |
| 60 | + | |
58 | 61 | | |
59 | 62 | | |
60 | 63 | | |
| 64 | + | |
61 | 65 | | |
62 | 66 | | |
63 | 67 | | |
0 commit comments