Natural-Language Policy Violations
Medium
- Confidence
- 97% confidence
- Finding
- The lockfile pins package downloads to a locale-specific mirror over plain HTTP, which removes transport-layer authenticity and allows a network attacker or compromised mirror to tamper with package tarballs in transit. Although npm integrity hashes provide some protection, using insecure transport and a hard-coded third-party mirror still weakens supply-chain trust, creates reliability/governance risk, and may enable downgrade or substitution attacks if integrity handling is bypassed or inconsistently enforced in tooling.
