Skip to content

[Aikido] Implement SHA256 digest verification for native binary artifacts - #750

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137924552-nybh
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137924552-nybh

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses the security risk of unverified native release artifacts by implementing mandatory SHA256 digest verification against repository-controlled trusted digests. The fix introduces a centralized binary_digests.txt file containing verified SHA256 hashes for all zen-internals binaries, validation scripts that verify cached binaries before use, and a pre-commit hook to prevent accidental commits of unverified digests. The Makefile has been updated to enforce digest validation during the build process, and helper scripts (compute_binary_digests.py and init_digests_from_upstream.py) enable secure initialization and maintenance of the digest registry. Builds will now fail if binary verification fails or required digests are missing, ensuring supply chain integrity.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811708058
HIGH
make binaries downloads both shared libraries and .sha256sum sidecars, but the Makefile never consumes the sidecars or compares the libraries with repository-controlled digests. check_binaries also treats any existing cache directory as valid, allowing stale or modified artifacts to bypass downloading. make build copies the cache into aikido_zen/libs, Poetry includes that directory in wheels and source distributions, and the runtime passes the selected library to ctypes.CDLL. The publish workflow invokes make build before publishing, establishing a supply-chain path from an unverified upstream artifact to native-code execution in downstream applications.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant