security-review/checkers/fixtures/plan-groomer/sample-reports/dependency-cve/2026-06-17/dependency-cve.json
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

32 lines
1.2 KiB
JSON

{
"checker": "dependency-cve",
"generated": "2026-06-17T03:05:00Z",
"org": "Sea-Haven-Industries",
"advisory_mode": "offline",
"repos_scanned": 2,
"vuln_count": 2,
"repos_with_vulns": 2,
"findings": [
{
"repo": "payments-dashboard",
"id": "payments-dashboard-vuln-jinja2-2-11-2-GHSA-g3rq-g295-4j3m",
"title": "jinja2 2.11.2 is vulnerable (GHSA-g3rq-g295-4j3m)",
"severity": "high",
"category": "other",
"check": "vulnerable-dependency",
"status": "confirmed",
"proof": {"package": "jinja2", "version": "2.11.2", "advisory_id": "GHSA-g3rq-g295-4j3m", "summary": "Jinja2 ReDoS in the urlize filter", "fixed_version": "2.11.3"}
},
{
"repo": "slack-bot",
"id": "slack-bot-vuln-lodash-4-17-15-GHSA-p6mc-m468-83gw",
"title": "lodash 4.17.15 is vulnerable (GHSA-p6mc-m468-83gw)",
"severity": "critical",
"category": "other",
"check": "vulnerable-dependency",
"status": "confirmed",
"proof": {"package": "lodash", "version": "4.17.15", "advisory_id": "GHSA-p6mc-m468-83gw", "summary": "Prototype pollution in lodash", "fixed_version": "4.17.19"}
}
],
"skipped_checks": []
}