Skip to content

[deep-report] Verify awf install script with checksum in workflow templates #10707

@github-actions

Description

@github-actions

Description
Static analysis reports flagged unverified_script_exec in 128 workflows that install the firewall agent via a remote script without integrity checks. Add checksum verification to the install step in the workflow template(s), then recompile workflows to propagate the fix.

Expected Impact
Mitigates a broad supply chain risk by ensuring the firewall installer script is verified before execution.

Suggested Agent
Static Analysis Report Agent

Estimated Effort
Medium (1-4 hours)

Data Source
DeepReport Intelligence Briefing - 2026-01-19 (workflow run 21142424190) referencing discussion #10694

AI generated by DeepReport - Intelligence Gathering Agent

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions