# Software and Data Integrity Failures — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/s-integrity

> Unsigned code and unsafe deserialisation.

## Verify before you trust

Integrity failures happen when code or data is trusted without verification: auto-updates without signature checks, plugins loaded from untrusted sources, CI/CD pipelines that anyone can modify, CDN scripts without integrity checks, and **insecure deserialisation**, where native object formats (Python pickle, Java serialisation) from untrusted input can execute code. Verify signatures and checksums, use **Subresource Integrity (SRI)** for third-party scripts, protect pipelines with reviews and least privilege, and use safe data formats such as JSON with schema validation.

## Unsafe and safe deserialisation, plus SRI

Python and HTML.

```python
import json, pickle

# VULNERABLE: unpickling attacker data can run arbitrary code
obj = pickle.loads(request.data)

# SAFE: parse a data-only format and validate its structure
payload = json.loads(request.data)
validate(payload, ORDER_SCHEMA)      # e.g. jsonschema or pydantic

# HTML: the browser refuses the script if its hash does not match
# <script src="https://cdn.example.com/lib.min.js"
#         integrity="sha384-<base64 hash>" crossorigin="anonymous"></script>
```

## Treat CI/CD as production

Pipelines hold deployment credentials; protect branches, require reviews and restrict who can change workflows.

**Quiz:** Why is pickle.loads on untrusted data dangerous?

- [ ] It only supports strings
- [ ] It is slow
- [x] Deserialising pickle data can execute arbitrary code
- [ ] It deletes the input

*Answer:* Deserialising pickle data can execute arbitrary code. Use data-only formats for untrusted input.
