BWA indices are being transferred to the user over FTP. The significance of this was reported in CVE-2019-10269. Because of the difficulty in producing these indices by the user, bwa.kit downloads them directly from NCBI from
Without checksums there is no guarantee that the indices are correctly delivered. These checksums are provided by NCBI here: ftp://ftp.ncbi.nlm.nih.gov/genomes/all/GCA/000/001/405/GCA_000001405.15_GRCh38/seqs_for_alignment_pipelines.ucsc_ids/md5checksums.txt
There should be checks for these indices coded into run-gen-ref or the software should notify the user that the indices have not been checked.
BWA indices are being transferred to the user over FTP. The significance of this was reported in CVE-2019-10269. Because of the difficulty in producing these indices by the user, bwa.kit downloads them directly from NCBI from
run-gen-ref executes this url here:
Without checksums there is no guarantee that the indices are correctly delivered. These checksums are provided by NCBI here: ftp://ftp.ncbi.nlm.nih.gov/genomes/all/GCA/000/001/405/GCA_000001405.15_GRCh38/seqs_for_alignment_pipelines.ucsc_ids/md5checksums.txt
There should be checks for these indices coded into run-gen-ref or the software should notify the user that the indices have not been checked.