mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-04 20:42:11 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
32 lines
1.2 KiB
JSON
32 lines
1.2 KiB
JSON
{
|
|
"checker": "dependency-cve",
|
|
"generated": "2026-06-17T03:05:00Z",
|
|
"org": "Sea-Haven-Industries",
|
|
"advisory_mode": "offline",
|
|
"repos_scanned": 2,
|
|
"vuln_count": 2,
|
|
"repos_with_vulns": 2,
|
|
"findings": [
|
|
{
|
|
"repo": "payments-dashboard",
|
|
"id": "payments-dashboard-vuln-jinja2-2-11-2-GHSA-g3rq-g295-4j3m",
|
|
"title": "jinja2 2.11.2 is vulnerable (GHSA-g3rq-g295-4j3m)",
|
|
"severity": "high",
|
|
"category": "other",
|
|
"check": "vulnerable-dependency",
|
|
"status": "confirmed",
|
|
"proof": {"package": "jinja2", "version": "2.11.2", "advisory_id": "GHSA-g3rq-g295-4j3m", "summary": "Jinja2 ReDoS in the urlize filter", "fixed_version": "2.11.3"}
|
|
},
|
|
{
|
|
"repo": "slack-bot",
|
|
"id": "slack-bot-vuln-lodash-4-17-15-GHSA-p6mc-m468-83gw",
|
|
"title": "lodash 4.17.15 is vulnerable (GHSA-p6mc-m468-83gw)",
|
|
"severity": "critical",
|
|
"category": "other",
|
|
"check": "vulnerable-dependency",
|
|
"status": "confirmed",
|
|
"proof": {"package": "lodash", "version": "4.17.15", "advisory_id": "GHSA-p6mc-m468-83gw", "summary": "Prototype pollution in lodash", "fixed_version": "4.17.19"}
|
|
}
|
|
],
|
|
"skipped_checks": []
|
|
}
|