A GSEC analyst is reviewing the deployment pipeline for a containerized Node.js service. The Dockerfile contains a layer that runs `curl -fsSL https://example.com/install.sh | sh` during the build, before the image is pushed to an internal registry. The registry enforces vulnerability scanning, and the image is deployed to a Kubernetes cluster with a restrictive NetworkPolicy. Which of the following is the primary supply chain risk introduced by this Dockerfile instruction?
Piping a remote script directly into a shell executes whatever the endpoint returns at build time, with no hash or signature check. If the endpoint or DNS is compromised, malicious code becomes part of a legitimate image layer, and later vulnerability scanning may not flag novel or obfuscated payloads, making this the primary supply chain risk.
Why this answer
Fetching and executing a remote script during a Docker build introduces unverified third-party code into the image. Because there is no checksum or signature validation, a compromised endpoint can inject malicious content that becomes part of a trusted image. Registry scanning may not catch bespoke or obfuscated payloads, so the integrity of the supply chain is the primary concern.
Exam trap
The trap here is assuming that registry vulnerability scanning will catch any malicious code introduced during the build, when scanning primarily targets known CVEs in packages, not arbitrary injected scripts.