security-review/checkers/fixtures/dependency-cve/osv-advisories.json
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

23 lines
1.1 KiB
JSON

{
"_comment": "Offline advisory fixture for dependency-cve.sh --canary (and --advisories-file). This stands in for the live OSV querybatch API so the canary is fully offline + deterministic. Each entry is keyed by 'ECOSYSTEM|package|version' (ECOSYSTEM matches OSV ecosystem names: PyPI, npm, NuGet) and carries the fields the checker emits in a finding's proof. These mirror REAL advisories (GHSA/CVE ids + summaries + fixed versions) so the fixture is realistic, but the checker NEVER reaches the network in canary mode — it reads only this file.",
"advisories": {
"PyPI|jinja2|2.11.2": [
{
"id": "GHSA-g3rq-g295-4j3m",
"summary": "Jinja2 ReDoS in the urlize filter via the urlize regex",
"severity": "high",
"cvss": 7.5,
"fixed_version": "2.11.3"
}
],
"npm|lodash|4.17.15": [
{
"id": "GHSA-p6mc-m468-83gw",
"summary": "Prototype pollution in lodash (zipObjectDeep / set / setWith)",
"severity": "high",
"cvss": 7.4,
"fixed_version": "4.17.19"
}
]
}
}