{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "GHSA-gc5v-m9x4-r6x2", "name": "requests: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9wx4-h78v-vm56", "name": "requests: GHSA-9wx4-h78v-vm56", "shortDescription": {"text": "requests: GHSA-9wx4-h78v-vm56"}, "fullDescription": {"text": "Requests `Session` object does not verify requests after making first request with verify=False"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9hjg-9r4m-mvj7", "name": "requests: GHSA-9hjg-9r4m-mvj7", "shortDescription": {"text": "requests: GHSA-9hjg-9r4m-mvj7"}, "fullDescription": {"text": "Requests vulnerable to .netrc credentials leak via malicious URLs"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-w853-jp5j-5j7f", "name": "filelock: GHSA-w853-jp5j-5j7f", "shortDescription": {"text": "filelock: GHSA-w853-jp5j-5j7f"}, "fullDescription": {"text": "filelock has a TOCTOU race condition which allows symlink attacks during lock file creation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qmgc-5h2g-mvrw", "name": "filelock: GHSA-qmgc-5h2g-mvrw", "shortDescription": {"text": "filelock: GHSA-qmgc-5h2g-mvrw"}, "fullDescription": {"text": "filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-69w3-r845-3855", "name": "transformers: GHSA-69w3-r845-3855", "shortDescription": {"text": "transformers: GHSA-69w3-r845-3855"}, "fullDescription": {"text": "HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vgrw-7cvw-pwgx", "name": "torch: GHSA-vgrw-7cvw-pwgx", "shortDescription": {"text": "torch: GHSA-vgrw-7cvw-pwgx"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its unpack_sequence function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-887c-mr87-cxwp", "name": "torch: GHSA-887c-mr87-cxwp", "shortDescription": {"text": "torch: GHSA-887c-mr87-cxwp"}, "fullDescription": {"text": "PyTorch Improper Resource Shutdown or Release vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r73j-pqj5-w3x7", "name": "pillow: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "Pillow has a PDF Parsing Trailer Infinite Loop (DoS)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pr7r-676h-xcf6", "name": "undici: GHSA-pr7r-676h-xcf6", "shortDescription": {"text": "undici: GHSA-pr7r-676h-xcf6"}, "fullDescription": {"text": "undici vulnerable to cross-user information disclosure via shared cache whitespace bypass"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-p88m-4jfj-68fv", "name": "undici: GHSA-p88m-4jfj-68fv", "shortDescription": {"text": "undici: GHSA-p88m-4jfj-68fv"}, "fullDescription": {"text": "undici vulnerable to HTTP header injection via Set-Cookie percent-decoding"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "MINED124", "name": "requirements.txt: `protobuf` has no version pin", "shortDescription": {"text": "requirements.txt: `protobuf` has no version pin"}, "fullDescription": {"text": "Unpinned pip requirement means every fresh install may resolve a different version. Newer releases can introduce malicious code (typosquats, account compromises). Reproducible installs need exact pins."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "GHSA-rrmf-rvhw-rf47", "name": "torch: GHSA-rrmf-rvhw-rf47", "shortDescription": {"text": "torch: GHSA-rrmf-rvhw-rf47"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its torch.jit.script function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qfhq-4f3w-5fph", "name": "torch: GHSA-qfhq-4f3w-5fph", "shortDescription": {"text": "torch: GHSA-qfhq-4f3w-5fph"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its torch.lstm_cell function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3749-ghw9-m3mg", "name": "torch: GHSA-3749-ghw9-m3mg", "shortDescription": {"text": "torch: GHSA-3749-ghw9-m3mg"}, "fullDescription": {"text": "PyTorch susceptible to local Denial of Service"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-g8m3-5g58-fq7m", "name": "undici: GHSA-g8m3-5g58-fq7m", "shortDescription": {"text": "undici: GHSA-g8m3-5g58-fq7m"}, "fullDescription": {"text": "undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-35p6-xmwp-9g52", "name": "undici: GHSA-35p6-xmwp-9g52", "shortDescription": {"text": "undici: GHSA-35p6-xmwp-9g52"}, "fullDescription": {"text": "undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "DEPCUR-PY", "name": "Python package `torch` is minor version(s) behind (2.7.0 -> 2.12.1)", "shortDescription": {"text": "Python package `torch` is minor version(s) behind (2.7.0 -> 2.12.1)"}, "fullDescription": {"text": "`torch==2.7.0` is minor version(s) behind the latest stable release on PyPI (2.12.1). Pinned-but-stale Python dependencies drift away from upstream security and bugfix releases. This is the version-currency signal Dependabot raises."}, "properties": {"scanner": "repobility-dependency-currency", "category": "dependency", "severity": "low", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED115", "name": "Action `actions/cache` pinned to mutable ref `@v4`", "shortDescription": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "fullDescription": {"text": "`uses: actions/cache@v4` resolves at workflow-run time. Tags and branches can be re-pushed by the action owner; that made the tj-actions/changed-files compromise (2025) instantly affect many repos. Treat official first-party action tags as lower risk, but pin security-sensitive third-party actions to a 40-char commit SHA + lock with Dependabot or renovate."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "low", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "AIC003", "name": "Duplicated implementation block across source files", "shortDescription": {"text": "Duplicated implementation block across source files"}, "fullDescription": {"text": "Duplicated blocks are a common artifact when generated code is pasted or recreated instead of reused. They increase maintenance cost because every future bug fix must be found in multiple locations."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.86, "cwe": "", "owasp": ""}}, {"id": "SEC045", "name": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a latera", "shortDescription": {"text": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a lateral-movement vector after any one credential compromise. Sandboxes (__builtins__ cleared) are escapable: attackers use obj"}, "fullDescription": {"text": "For literal data structures: use ast.literal_eval(text) \u2014 only parses literals, raises on code.\nFor formula evaluation: use asteval or simpleeval (purpose-built sandboxes with allow-lists).\nFor Odoo: use odoo.tools.safe_eval(expr, locals_dict, mode='exec').\nIf you genuinely need to execute admin-stored code: require explicit super-admin permission AND log every execution with a stack trace."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "info", "confidence": 0.1, "cwe": "", "owasp": ""}}, {"id": "SEC020", "name": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequen", "shortDescription": {"text": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequent AI-assisted coding failure: the helper exposes the exact value needed for troubleshooting."}, "fullDescription": {"text": "Log only redacted, hashed, or last-four-style metadata. Rotate any secret that may have reached logs."}, "properties": {"scanner": "repobility-threat-engine", "category": "credential_exposure", "severity": "info", "confidence": 0.1, "cwe": "", "owasp": ""}}, {"id": "SEC128", "name": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 2 more): Same pattern found in 2 addit", "shortDescription": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 2 more): Same pattern found in 2 additional files. Review if needed."}, "fullDescription": {"text": "Add `await` before each async call, or chain with `.then`. If you intentionally want fire-and-forget, prefix with `void` (TS) or assign to `_` (Python with `asyncio.create_task`) to make the intent explicit and survive lint."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2023-74", "name": "requests: PYSEC-2023-74", "shortDescription": {"text": "requests: PYSEC-2023-74"}, "fullDescription": {"text": "Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the `Proxy-Authorization` header must be sent in the CONNECT request as the proxy has no visibility into the tunneled request. This results in Requests forwarding proxy credentials to the destination server unintentionally, allowing a malicious actor to potentially exfiltrate sensitive information. This issue has been patched in version 2.31.0.\n\n"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2018-28", "name": "requests: PYSEC-2018-28", "shortDescription": {"text": "requests: PYSEC-2018-28"}, "fullDescription": {"text": "The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-217", "name": "transformers: PYSEC-2025-217", "shortDescription": {"text": "transformers: PYSEC-2025-217"}, "fullDescription": {"text": "Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-139", "name": "torch: PYSEC-2026-139", "shortDescription": {"text": "torch: PYSEC-2026-139"}, "fullDescription": {"text": "A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-209", "name": "torch: PYSEC-2025-209", "shortDescription": {"text": "torch: PYSEC-2025-209"}, "fullDescription": {"text": "An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-208", "name": "torch: PYSEC-2025-208", "shortDescription": {"text": "torch: PYSEC-2025-208"}, "fullDescription": {"text": "A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-207", "name": "torch: PYSEC-2025-207", "shortDescription": {"text": "torch: PYSEC-2025-207"}, "fullDescription": {"text": "A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-206", "name": "torch: PYSEC-2025-206", "shortDescription": {"text": "torch: PYSEC-2025-206"}, "fullDescription": {"text": "pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long()."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-205", "name": "torch: PYSEC-2025-205", "shortDescription": {"text": "torch: PYSEC-2025-205"}, "fullDescription": {"text": "A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-204", "name": "torch: PYSEC-2025-204", "shortDescription": {"text": "torch: PYSEC-2025-204"}, "fullDescription": {"text": "pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-203", "name": "torch: PYSEC-2025-203", "shortDescription": {"text": "torch: PYSEC-2025-203"}, "fullDescription": {"text": "An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-44wm-f244-xhp3", "name": "pillow: GHSA-44wm-f244-xhp3", "shortDescription": {"text": "pillow: GHSA-44wm-f244-xhp3"}, "fullDescription": {"text": "Pillow buffer overflow vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-165", "name": "pillow: PYSEC-2026-165", "shortDescription": {"text": "pillow: PYSEC-2026-165"}, "fullDescription": {"text": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2023-227", "name": "pillow: PYSEC-2023-227", "shortDescription": {"text": "pillow: PYSEC-2023-227"}, "fullDescription": {"text": "An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2023-175", "name": "pillow: PYSEC-2023-175", "shortDescription": {"text": "pillow: PYSEC-2023-175"}, "fullDescription": {"text": "Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vxpw-j846-p89q", "name": "undici: GHSA-vxpw-j846-p89q", "shortDescription": {"text": "undici: GHSA-vxpw-j846-p89q"}, "fullDescription": {"text": "undici WebSocket client vulnerable to denial of service via fragment count bypass"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vmh5-mc38-953g", "name": "undici: GHSA-vmh5-mc38-953g", "shortDescription": {"text": "undici: GHSA-vmh5-mc38-953g"}, "fullDescription": {"text": "undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hm92-r4w5-c3mj", "name": "undici: GHSA-hm92-r4w5-c3mj", "shortDescription": {"text": "undici: GHSA-hm92-r4w5-c3mj"}, "fullDescription": {"text": "undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "MINED008", "name": "[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let.", "shortDescription": {"text": "[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-476 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "GHSA-3f63-hfp8-52jq", "name": "pillow: GHSA-3f63-hfp8-52jq", "shortDescription": {"text": "pillow: GHSA-3f63-hfp8-52jq"}, "fullDescription": {"text": "Arbitrary Code Execution in Pillow"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "scanner-e4f835c0d8792216", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf2915580029c5b2", "name": "CVE-2026-28980: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved", "shortDescription": {"text": "CVE-2026-28980: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "fullDescription": {"text": "SwiftNIO NIOHTTP1:  HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS\n\n### Summary\n\nThe `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or on the number of header fields per message. A remote peer can submit an arbitrary number of small, valid headers in a single request and have them all accumulated into the resulting `HTTPHeaders` value before any application code runs. This can be used to exhaust memory, or \u2014 for consumers that subsequently convert headers into `swift-http-types`' `HTTPFields` \u2014 to crash the pr\n\nPackage: github.com/apple/swift-nio\nInstalled: 2.97.1\nFixed in: 2.100.0\nSeverity: HIGH\nFix: Upgrade github.com/apple/swift-nio to 2.100.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7bbbe903df2701ba", "name": "CVE-2026-43671: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved", "shortDescription": {"text": "CVE-2026-43671: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "fullDescription": {"text": "SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow\n\n### Summary\n\nA program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index or length values exceeding `UInt32.max` are passed to some `ByteBuffer` methods. This affects all swift-nio versions from 1.0.0 to 2.99.0. It is fixed in 2.100.0 and later releases.\n\n### Details\n\n`ByteBuffer` internally stores indices and capacities as `UInt32` values. The internal helper functions `_toIndex` and `_toCapacity`, which convert from `Int` to `UInt32`, used `UInt32(\n\nPackage: github.com/apple/swift-nio\nInstalled: 2.97.1\nFixed in: 2.100.0\nSeverity: HIGH\nFix: Upgrade github.com/apple/swift-nio to 2.100.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ef4afabd81bdd34", "name": "CVE-2026-28970: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved", "shortDescription": {"text": "CVE-2026-28970: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "fullDescription": {"text": "SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator\n\nPrograms using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insufficient validation of outbound HTTP/1.1 request and response start line components.\n\nThis vulnerability affects all swift-nio versions from 2.0.0 to 2.99.0. It is fixed in 2.100.0 and later releases.                                                                                         \n                  \nThis vulnerability is caused by the `NIOHTTPRequestHeadersValidator` and `N\n\nPackage: github.com/apple/swift-nio\nInstalled: 2.97.1\nFixed in: 2.100.0\nSeverity: MEDIUM\nFix: Upgrade github.com/apple/swift-nio to 2.100.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-451dcc53742b6ad6", "name": "CVE-2026-47121: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved", "shortDescription": {"text": "CVE-2026-47121: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved"}, "fullDescription": {"text": "Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta\n\n## Summary\n\nBinary delta apply intermediate-symlink traversal in malicious .delta\n\n`Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@\"..\"` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks deeper in the relative path. `Autoupdate/SPUSparkleDeltaArchive.m`'s `extractItem:` will create symlinks in the destination tree from archive content (no `..` check on the symlink target), and a subsequent `Extract`\n\nPackage: github.com/sparkle-project/Sparkle\nInstalled: 2.9.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb45bb569ffb54ff", "name": "CVE-2026-47122: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved", "shortDescription": {"text": "CVE-2026-47122: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved"}, "fullDescription": {"text": "Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection\n\n## Summary\n\nAppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection.\n\n## Details\n\n`Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach service `<bundleId>-spki` are accepted from any local process without team-ID or code-signing checks.\n\nThe following chain of event\n\nPackage: github.com/sparkle-project/Sparkle\nInstalled: 2.9.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24aae76241cdb498", "name": "CVE-2026-12151: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-12151: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames\n\nImpact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\nAffected applications are those using the undici WebSocket client \n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fff412b42960a92e", "name": "CVE-2026-6734: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-6734: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing\n\nImpact:\nWhen using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination.\nThis causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HTT\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 7.28.0, 8.2.0\nSeverity: HIGH\nFix: Upgrade undici to 7.28.0, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d96e2d27f8dc82f", "name": "CVE-2026-9697: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-9697: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy\n\nImpact:\nundici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.\nApplications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed b\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a03091c57e3f64b8", "name": "CVE-2026-9678: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-9678: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: Undici: Information disclosure due to improper cache-control header parsing\n\nImpact:\nUndici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=\" authorization\" or no-cache=\"\\tauthorization\". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored.\nIn shared-cache mode, this allows a response containing one user's authenticated data to be served\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72075e5cd920e43c", "name": "CVE-2026-9679: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-9679: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding\n\nImpact:\nundici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 \u00a75.4 does not specify any decoding and browsers do not decode either.\nApplications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inje\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b72e722e5849e9c1", "name": "CVE-2026-11525: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-11525: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n\nImpact:\nWhen undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict).\nAffected applications are those that consume Set-Cookie headers\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9dc225f8b6e52209", "name": "CVE-2026-6733: undici 7.25.0 \u2014 mcpb/server/package-lock.json", "shortDescription": {"text": "CVE-2026-6733: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "fullDescription": {"text": "undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.\n\nImpact:\nUndici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.\nThis requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-aliv\n\nPackage: undici\nInstalled: 7.25.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9daab76003af9a35", "name": "CVE-2025-2999: torch 2.7.0 \u2014 models/siglip2/requirements.txt", "shortDescription": {"text": "CVE-2025-2999: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.7.0\nFixed in: 2.9.1\nSeverity: MEDIUM\nFix: Upgrade torch to 2.9.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e73bccbc503a2691", "name": "CVE-2025-3730: torch 2.7.0 \u2014 models/siglip2/requirements.txt", "shortDescription": {"text": "CVE-2025-3730: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "fullDescription": {"text": "A vulnerability, which was classified as problematic, was found in PyT ...\n\nA vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a pa\n\nPackage: torch\nInstalled: 2.7.0\nFixed in: 2.8.0\nSeverity: MEDIUM\nFix: Upgrade torch to 2.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-47a3e497e54e1d26", "name": "CVE-2025-2953: torch 2.7.0 \u2014 models/siglip2/requirements.txt", "shortDescription": {"text": "CVE-2025-2953: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "fullDescription": {"text": "torch: PyTorch torch.mkldnn_max_pool2d denial of service\n\nA vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.\n\nPackage: torch\nInstalled: 2.7.0\nFixed in: 2.7.1-rc1\nSeverity: LOW\nFix: Upgrade torch to 2.7.1-rc1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ceada123302793b", "name": "CVE-2025-3000: torch 2.7.0 \u2014 models/siglip2/requirements.txt", "shortDescription": {"text": "CVE-2025-3000: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.7.0\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff4b0c1381b146d1", "name": "CVE-2025-3001: torch 2.7.0 \u2014 models/siglip2/requirements.txt", "shortDescription": {"text": "CVE-2025-3001: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...\n\nA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.7.0\nFixed in: 2.10.0\nSeverity: LOW\nFix: Upgrade torch to 2.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/cache@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 3 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 12 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nmodels/siglip2/convert.py:forward, models/siglip2/convert.py:forward\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30729"}, "properties": {"repository": "palmier-io/palmier-pro", "repoUrl": "https://github.com/palmier-io/palmier-pro", "branch": "main"}, "results": [{"ruleId": "GHSA-gc5v-m9x4-r6x2", "level": "warning", "message": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": 468532, "scanner": "osv-scanner", "fingerprint": "30e44ca8f27db0dc665d9631e4a970e6539616499d94db91336203b2e23aa192", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-25645"], "package": "requests", "rule_id": "GHSA-gc5v-m9x4-r6x2", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2026-25645|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9wx4-h78v-vm56", "level": "warning", "message": {"text": "requests: GHSA-9wx4-h78v-vm56"}, "properties": {"repobilityId": 468531, "scanner": "osv-scanner", "fingerprint": "03340853ea08971cab3248567aad8fb747f102f1e18191fd1f012fea6cc44e69", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2024-35195"], "package": "requests", "rule_id": "GHSA-9wx4-h78v-vm56", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2024-35195|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9hjg-9r4m-mvj7", "level": "warning", "message": {"text": "requests: GHSA-9hjg-9r4m-mvj7"}, "properties": {"repobilityId": 468530, "scanner": "osv-scanner", "fingerprint": "5d0b7338ab6ad79eeff32694a30cf6ba51e39b62a465dfa202f50224fbc7eb1e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2024-47081"], "package": "requests", "rule_id": "GHSA-9hjg-9r4m-mvj7", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2024-47081|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w853-jp5j-5j7f", "level": "warning", "message": {"text": "filelock: GHSA-w853-jp5j-5j7f"}, "properties": {"repobilityId": 468527, "scanner": "osv-scanner", "fingerprint": "12c52e88ea1f29d0ad80033ee00dbc11fa27d3fc76a4951d2a9c9f170fb4a72d", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-68146"], "package": "filelock", "rule_id": "GHSA-w853-jp5j-5j7f", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2025-68146|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qmgc-5h2g-mvrw", "level": "warning", "message": {"text": "filelock: GHSA-qmgc-5h2g-mvrw"}, "properties": {"repobilityId": 468526, "scanner": "osv-scanner", "fingerprint": "5b2c5afbc5e65138d90349ff1838caa19fb65f864de126e4c6629c872224ca98", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-22701"], "package": "filelock", "rule_id": "GHSA-qmgc-5h2g-mvrw", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2026-22701|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-69w3-r845-3855", "level": "warning", "message": {"text": "transformers: GHSA-69w3-r845-3855"}, "properties": {"repobilityId": 468525, "scanner": "osv-scanner", "fingerprint": "5580ef7d2aacc716eeed65a24e9500c4900677deda1a08f3ef97225f27f652cd", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-1839"], "package": "transformers", "rule_id": "GHSA-69w3-r845-3855", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2026-1839|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vgrw-7cvw-pwgx", "level": "warning", "message": {"text": "torch: GHSA-vgrw-7cvw-pwgx"}, "properties": {"repobilityId": 468523, "scanner": "osv-scanner", "fingerprint": "0af22581e2e5f7cd593cee50939afde140717862695fa4d9e71284df31f0791c", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2999", "CVE-2025-2999", "PYSEC-2025-193"], "package": "torch", "rule_id": "GHSA-vgrw-7cvw-pwgx", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2999|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-887c-mr87-cxwp", "level": "warning", "message": {"text": "torch: GHSA-887c-mr87-cxwp"}, "properties": {"repobilityId": 468520, "scanner": "osv-scanner", "fingerprint": "72e0c43705c140a76d790fc6dad429f4aece061c03d5838a7837525b1aa8f3c1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3730", "CVE-2025-3730"], "package": "torch", "rule_id": "GHSA-887c-mr87-cxwp", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3730|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r73j-pqj5-w3x7", "level": "warning", "message": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": 468510, "scanner": "osv-scanner", "fingerprint": "200cae6961acaaaa89ccea6de9ef0b7739d383a5b8871cc289bfcd6d40a69f57", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42310", "CVE-2026-42310"], "package": "pillow", "rule_id": "GHSA-r73j-pqj5-w3x7", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42310|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pr7r-676h-xcf6", "level": "warning", "message": {"text": "undici: GHSA-pr7r-676h-xcf6"}, "properties": {"repobilityId": 468502, "scanner": "osv-scanner", "fingerprint": "30f6ec27575497a433e8da770828200eec177b9758da57a0c753237d9a4694b9", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-9678"], "package": "undici", "rule_id": "GHSA-pr7r-676h-xcf6", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-9678|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-p88m-4jfj-68fv", "level": "warning", "message": {"text": "undici: GHSA-p88m-4jfj-68fv"}, "properties": {"repobilityId": 468501, "scanner": "osv-scanner", "fingerprint": "3f576426a9782ce7059a9a205f8212aaae47cfee15230c46aa9451d681d287b1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-9679"], "package": "undici", "rule_id": "GHSA-p88m-4jfj-68fv", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-9679|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED124", "level": "warning", "message": {"text": "requirements.txt: `protobuf` has no version pin"}, "properties": {"repobilityId": 468487, "scanner": "repobility-supply-chain", "fingerprint": "7c5d38a66158cefe8063ebbf537e148ffe175eb99eb323925f177285906e4138", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "unpinned-pip-requirement", "owasp": null, "cwe_ids": ["CWE-1357"], "languages": ["python"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|7c5d38a66158cefe8063ebbf537e148ffe175eb99eb323925f177285906e4138"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 10}}}]}, {"ruleId": "MINED124", "level": "warning", "message": {"text": "requirements.txt: `sentencepiece` has no version pin"}, "properties": {"repobilityId": 468486, "scanner": "repobility-supply-chain", "fingerprint": "2ec9532acd980733efe64634b031304631b0b3b3269086e47e53304ae11cb574", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "unpinned-pip-requirement", "owasp": null, "cwe_ids": ["CWE-1357"], "languages": ["python"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|2ec9532acd980733efe64634b031304631b0b3b3269086e47e53304ae11cb574"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 9}}}]}, {"ruleId": "MINED124", "level": "warning", "message": {"text": "requirements.txt: `scikit-learn` has no version pin"}, "properties": {"repobilityId": 468485, "scanner": "repobility-supply-chain", "fingerprint": "6bf0c2f87b8eede5154f4bfbb9a13c1e127486c5d515e4a5f5e794533ab44d6b", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "unpinned-pip-requirement", "owasp": null, "cwe_ids": ["CWE-1357"], "languages": ["python"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|6bf0c2f87b8eede5154f4bfbb9a13c1e127486c5d515e4a5f5e794533ab44d6b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 8}}}]}, {"ruleId": "MINED124", "level": "warning", "message": {"text": "requirements.txt: `numpy<2` has no version pin"}, "properties": {"repobilityId": 468484, "scanner": "repobility-supply-chain", "fingerprint": "81c15e8ea71b28b6f5bae58e97d46c51d44a0f65699bcbafeb1cc6c206143046", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "unpinned-pip-requirement", "owasp": null, "cwe_ids": ["CWE-1357"], "languages": ["python"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|81c15e8ea71b28b6f5bae58e97d46c51d44a0f65699bcbafeb1cc6c206143046"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 6}}}]}, {"ruleId": "MINED124", "level": "warning", "message": {"text": "requirements.txt: `pillow` has no version pin"}, "properties": {"repobilityId": 468483, "scanner": "repobility-supply-chain", "fingerprint": "5527f1509da7206116c6eb3d1755f241a030f6e361363d26c5bcc249da50fc57", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "unpinned-pip-requirement", "owasp": null, "cwe_ids": ["CWE-1357"], "languages": ["python"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|5527f1509da7206116c6eb3d1755f241a030f6e361363d26c5bcc249da50fc57"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 4}}}]}, {"ruleId": "GHSA-rrmf-rvhw-rf47", "level": "note", "message": {"text": "torch: GHSA-rrmf-rvhw-rf47"}, "properties": {"repobilityId": 468522, "scanner": "osv-scanner", "fingerprint": "0dff0f7a98d94f01deb5f497664c21da74af0c79f38466b2b367634bc3b2004b", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3000", "CVE-2025-3000", "PYSEC-2025-194"], "package": "torch", "rule_id": "GHSA-rrmf-rvhw-rf47", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3000|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qfhq-4f3w-5fph", "level": "note", "message": {"text": "torch: GHSA-qfhq-4f3w-5fph"}, "properties": {"repobilityId": 468521, "scanner": "osv-scanner", "fingerprint": "5371b43e960984b93d7086c5f46abdec15b47db818efbae8a5900bcb4c0aa3b8", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3001", "CVE-2025-3001", "PYSEC-2025-195"], "package": "torch", "rule_id": "GHSA-qfhq-4f3w-5fph", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3001|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3749-ghw9-m3mg", "level": "note", "message": {"text": "torch: GHSA-3749-ghw9-m3mg"}, "properties": {"repobilityId": 468519, "scanner": "osv-scanner", "fingerprint": "5d74f4ab1e8e6310d8a25d99ec3ac1d471fd7dfa25b99f6d697ef19a6ca43282", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2953", "CVE-2025-2953", "PYSEC-2025-191"], "package": "torch", "rule_id": "GHSA-3749-ghw9-m3mg", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2953|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-g8m3-5g58-fq7m", "level": "note", "message": {"text": "undici: GHSA-g8m3-5g58-fq7m"}, "properties": {"repobilityId": 468499, "scanner": "osv-scanner", "fingerprint": "e4f6562bb46223bb83033d26dd5ec834dd3b444eaf6467070e2d50163f0a5a60", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-11525"], "package": "undici", "rule_id": "GHSA-g8m3-5g58-fq7m", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-11525|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-35p6-xmwp-9g52", "level": "note", "message": {"text": "undici: GHSA-35p6-xmwp-9g52"}, "properties": {"repobilityId": 468498, "scanner": "osv-scanner", "fingerprint": "9e42c5474165c41a5d5c7ef7c7a96ddf013766252aadd4b581fc8e37c3ccea54", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-6733"], "package": "undici", "rule_id": "GHSA-35p6-xmwp-9g52", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-6733|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `torch` is minor version(s) behind (2.7.0 -> 2.12.1)"}, "properties": {"repobilityId": 468490, "scanner": "repobility-dependency-currency", "fingerprint": "9a72022bfa7da45b5c9ebaf4a5b125e3885fbd2ea015970e9d3ee02ede62ca0b", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "torch", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.12.1", "correlation_key": "fp|9a72022bfa7da45b5c9ebaf4a5b125e3885fbd2ea015970e9d3ee02ede62ca0b", "current_version": "2.7.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 468489, "scanner": "repobility-supply-chain", "fingerprint": "cee5a52b667e72b083c7d74a326ccd6cfde7a4c39e7556396c09b1ad91efd74c", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|cee5a52b667e72b083c7d74a326ccd6cfde7a4c39e7556396c09b1ad91efd74c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 468488, "scanner": "repobility-supply-chain", "fingerprint": "76bd6164d0a7c17fa02ee6f928d43667d989ad4a75753c09e4af6aae9918b86e", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|76bd6164d0a7c17fa02ee6f928d43667d989ad4a75753c09e4af6aae9918b86e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468482, "scanner": "repobility-ai-code-hygiene", "fingerprint": "044b718525cb3e77a02477ae4d495a46e7c124e2cf4c34319c5ee580b942b370", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Tests/PalmierProTests/Timeline/RippleDeleteRangesTests.swift", "duplicate_line": 1, "correlation_key": "fp|044b718525cb3e77a02477ae4d495a46e7c124e2cf4c34319c5ee580b942b370"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Tests/PalmierProTests/Timeline/RippleGapDeleteTests.swift"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468481, "scanner": "repobility-ai-code-hygiene", "fingerprint": "50159c4753f17fd88699393805c71aeb9d2e69aafe1c8a32e9312e3964620088", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Help/HelpView.swift", "duplicate_line": 92, "correlation_key": "fp|50159c4753f17fd88699393805c71aeb9d2e69aafe1c8a32e9312e3964620088"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Settings/SettingsView.swift"}, "region": {"startLine": 159}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468480, "scanner": "repobility-ai-code-hygiene", "fingerprint": "d95b02bc6e82fc24d81b395eb85ae98548054d22b02cb8b1c2eae1c83fcad347", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Project/UpdateOverlay.swift", "duplicate_line": 46, "correlation_key": "fp|d95b02bc6e82fc24d81b395eb85ae98548054d22b02cb8b1c2eae1c83fcad347"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Project/WelcomeOverlay.swift"}, "region": {"startLine": 48}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468479, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b70a8ce84f64bdf50c09f3ddf7d065b849750a631cec1623c6c2f71b54553f8d", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Project/HomeView.swift", "duplicate_line": 116, "correlation_key": "fp|b70a8ce84f64bdf50c09f3ddf7d065b849750a631cec1623c6c2f71b54553f8d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Project/ProjectCard.swift"}, "region": {"startLine": 78}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468478, "scanner": "repobility-ai-code-hygiene", "fingerprint": "69312ca3ce2c3fdca9235dd5e44735d123a75bff9abeed5b4907a5b0c514ddc2", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Preview/CropOverlayView.swift", "duplicate_line": 182, "correlation_key": "fp|69312ca3ce2c3fdca9235dd5e44735d123a75bff9abeed5b4907a5b0c514ddc2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Preview/TransformOverlayView.swift"}, "region": {"startLine": 218}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468477, "scanner": "repobility-ai-code-hygiene", "fingerprint": "a9ca1496a5fde63356d112c2847d18080941c78bde20532e8fbf95fbc9af7d8c", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/MediaPanel/CaptionsTab/CaptionTab.swift", "duplicate_line": 222, "correlation_key": "fp|a9ca1496a5fde63356d112c2847d18080941c78bde20532e8fbf95fbc9af7d8c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/MediaPanel/MusicTab.swift"}, "region": {"startLine": 239}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468476, "scanner": "repobility-ai-code-hygiene", "fingerprint": "f3e1ab6e7cf6224b2b7d1ac812034c094a8d01a4c282cb5782b5f6801c6068b4", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Agent/Clients/AnthropicClient.swift", "duplicate_line": 29, "correlation_key": "fp|f3e1ab6e7cf6224b2b7d1ac812034c094a8d01a4c282cb5782b5f6801c6068b4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Agent/Clients/PalmierClient.swift"}, "region": {"startLine": 6}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468475, "scanner": "repobility-ai-code-hygiene", "fingerprint": "5af452bf64da675ec402618d63f0a9d6b9dd76d5f1ff60c39178bd43e2a0310c", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "Sources/PalmierPro/Account/AccountPopoverCard.swift", "duplicate_line": 31, "correlation_key": "fp|5af452bf64da675ec402618d63f0a9d6b9dd76d5f1ff60c39178bd43e2a0310c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Account/IdentityViews.swift"}, "region": {"startLine": 96}}}]}, {"ruleId": "SEC045", "level": "none", "message": {"text": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a lateral-movement vector after any one credential compromise. Sandboxes (__builtins__ cleared) are escapable: attackers use object introspection (().__class__.__mro__[-1].__subclasses__()) to reach os.system. CWE-95 (eval injection)."}, "properties": {"repobilityId": 468497, "scanner": "repobility-threat-engine", "fingerprint": "1af2818dad5b4511f749d8250dfa2c28a47281605c0a995d0d7261e7086f2ffb", "category": "injection", "severity": "info", "confidence": 0.1, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Safe pattern '\\.eval\\(' detected on same line", "evidence": {"match": ".eval(", "reason": "Safe pattern '\\.eval\\(' detected on same line", "rule_id": "SEC045", "scanner": "repobility-threat-engine", "confidence": 0.1, "correlation_key": "code|injection|models/siglip2/convert.py|231|sec045"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/convert.py"}, "region": {"startLine": 231}}}]}, {"ruleId": "SEC020", "level": "none", "message": {"text": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequent AI-assisted coding failure: the helper exposes the exact value needed for troubleshooting."}, "properties": {"repobilityId": 468496, "scanner": "repobility-threat-engine", "fingerprint": "19ed6523434a3a54416c46b316001029ad9eefddbfefbea8a11d2591f48f8165", "category": "credential_exposure", "severity": "info", "confidence": 0.1, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Safe context pattern detected", "evidence": {"match": "print(f\"Pins for SearchIndexConfig.swift in {swift_path} \u2014 paste over the existing `static let manif", "reason": "Safe context pattern detected", "rule_id": "SEC020", "scanner": "repobility-threat-engine", "confidence": 0.1, "correlation_key": "secret|models/siglip2/convert.py|28|print f pins for searchindexconfig.swift in swift_path paste over the existing static let manif"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/convert.py"}, "region": {"startLine": 287}}}]}, {"ruleId": "SEC128", "level": "none", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 2 more): Same pattern found in 2 additional files. Review if needed."}, "properties": {"repobilityId": 468494, "scanner": "repobility-threat-engine", "fingerprint": "2cd220107759c389357ea1e0b2a749255d62455820f15b6cc9e05e77d2c17c58", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 2 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 2 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|2cd220107759c389357ea1e0b2a749255d62455820f15b6cc9e05e77d2c17c58"}}}, {"ruleId": "PYSEC-2023-74", "level": "error", "message": {"text": "requests: PYSEC-2023-74"}, "properties": {"repobilityId": 468529, "scanner": "osv-scanner", "fingerprint": "f5aebf5732b86055406652abe5abe3a6709fe06fb1af53d48ad3f2fbc3d166f3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2023-32681", "GHSA-j8r2-6x86-q33q"], "package": "requests", "rule_id": "PYSEC-2023-74", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2023-32681|token", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-j8r2-6x86-q33q", "PYSEC-2023-74"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["030ab561781b61599b6ecd70613098d2f9b0f7d21b7bceb0ad4db9d392bf367d", "f5aebf5732b86055406652abe5abe3a6709fe06fb1af53d48ad3f2fbc3d166f3"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2018-28", "level": "error", "message": {"text": "requests: PYSEC-2018-28"}, "properties": {"repobilityId": 468528, "scanner": "osv-scanner", "fingerprint": "2c49ad4a2fe9fd761dd88d72b0eca8bdf7732e2ac587f200695925ea5e7172a7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2018-18074", "GHSA-x84v-xcm2-53pg"], "package": "requests", "rule_id": "PYSEC-2018-28", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2018-18074|token", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-x84v-xcm2-53pg", "PYSEC-2018-28"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["2c49ad4a2fe9fd761dd88d72b0eca8bdf7732e2ac587f200695925ea5e7172a7", "6c178c059a7e1d21edb70398076d261a54b48b74533d2af0953920d7e6e1cfa3"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-217", "level": "error", "message": {"text": "transformers: PYSEC-2025-217"}, "properties": {"repobilityId": 468524, "scanner": "osv-scanner", "fingerprint": "662703a7c0fbc49a60a17d63de5aa4e5565b1ef22f7d10f9c513de23db5c9732", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14929"], "package": "transformers", "rule_id": "PYSEC-2025-217", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14929|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-139", "level": "error", "message": {"text": "torch: PYSEC-2026-139"}, "properties": {"repobilityId": 468518, "scanner": "osv-scanner", "fingerprint": "1ba164a80d3d2abe2327ccb1b36e4b2c936daa5df85ddc1b2743e9b6f732a81b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2026-4538", "CVE-2026-4538"], "package": "torch", "rule_id": "PYSEC-2026-139", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2026-4538|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-209", "level": "error", "message": {"text": "torch: PYSEC-2025-209"}, "properties": {"repobilityId": 468517, "scanner": "osv-scanner", "fingerprint": "22be9be66c97d6230f73c69d1ea1684b7454fcf42f02a97c806ba1b56e2ccbec", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55560", "CVE-2025-55560"], "package": "torch", "rule_id": "PYSEC-2025-209", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55560|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-208", "level": "error", "message": {"text": "torch: PYSEC-2025-208"}, "properties": {"repobilityId": 468516, "scanner": "osv-scanner", "fingerprint": "4ecd79501e8fa9f6a357c591ebf3745c99b729b978948e3151bccaf1c6d1b776", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55558", "CVE-2025-55558"], "package": "torch", "rule_id": "PYSEC-2025-208", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55558|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-207", "level": "error", "message": {"text": "torch: PYSEC-2025-207"}, "properties": {"repobilityId": 468515, "scanner": "osv-scanner", "fingerprint": "1c75b481ba1cae9094f2810918b037c4d7434937804c040dc64cc2584b297006", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55557", "CVE-2025-55557"], "package": "torch", "rule_id": "PYSEC-2025-207", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55557|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-206", "level": "error", "message": {"text": "torch: PYSEC-2025-206"}, "properties": {"repobilityId": 468514, "scanner": "osv-scanner", "fingerprint": "e526129180b19bf7ad2c98a5ba4ca4df07a48a2b5418f6241c62a72e3ace41da", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55554", "CVE-2025-55554"], "package": "torch", "rule_id": "PYSEC-2025-206", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55554|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-205", "level": "error", "message": {"text": "torch: PYSEC-2025-205"}, "properties": {"repobilityId": 468513, "scanner": "osv-scanner", "fingerprint": "6a50d6a1cbd9980801c4105dc0ee2832f8c4eb2ba3ce0732f6bc1321d4b82bd5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55553", "CVE-2025-55553"], "package": "torch", "rule_id": "PYSEC-2025-205", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55553|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-204", "level": "error", "message": {"text": "torch: PYSEC-2025-204"}, "properties": {"repobilityId": 468512, "scanner": "osv-scanner", "fingerprint": "f8489547a44f9a03463131d40ff1520f9c341a1c567aeeee111c8f1cfb5d1742", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55552", "CVE-2025-55552"], "package": "torch", "rule_id": "PYSEC-2025-204", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55552|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-203", "level": "error", "message": {"text": "torch: PYSEC-2025-203"}, "properties": {"repobilityId": 468511, "scanner": "osv-scanner", "fingerprint": "7ad024c110c1af793c159fae7842f550edb2b71120da192738a1327ac57d85e7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55551", "CVE-2025-55551"], "package": "torch", "rule_id": "PYSEC-2025-203", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55551|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-44wm-f244-xhp3", "level": "error", "message": {"text": "pillow: GHSA-44wm-f244-xhp3"}, "properties": {"repobilityId": 468509, "scanner": "osv-scanner", "fingerprint": "4b2e0093ff1eae38470d92190011ecb441941bf484f1230c5e400a051a9fd225", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2024-28219", "CVE-2024-28219"], "package": "pillow", "rule_id": "GHSA-44wm-f244-xhp3", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2024-28219|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-165", "level": "error", "message": {"text": "pillow: PYSEC-2026-165"}, "properties": {"repobilityId": 468507, "scanner": "osv-scanner", "fingerprint": "932ff8fa08b7c31ac6d99c79715c16d97b52850f21e2fd3217eb4b141262816e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42308", "CVE-2026-42308", "GHSA-wjx4-4jcj-g98j"], "package": "pillow", "rule_id": "PYSEC-2026-165", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42308|token", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-wjx4-4jcj-g98j", "PYSEC-2026-165"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["3a2a88662358ae57f4624fa352deb91c3bde67b0167f4671a8b0b18de66352cb", "932ff8fa08b7c31ac6d99c79715c16d97b52850f21e2fd3217eb4b141262816e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2023-227", "level": "error", "message": {"text": "pillow: PYSEC-2023-227"}, "properties": {"repobilityId": 468506, "scanner": "osv-scanner", "fingerprint": "19d0258db329ce61b66098501850e5a6880c77a941e2c6e2c67a5b4c531092e9", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pillow-2023-44271", "CVE-2023-44271", "GHSA-8ghj-p4vj-mr35"], "package": "pillow", "rule_id": "PYSEC-2023-227", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2023-44271|token", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-8ghj-p4vj-mr35", "PYSEC-2023-227"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["19d0258db329ce61b66098501850e5a6880c77a941e2c6e2c67a5b4c531092e9", "7969dd8b47f66b5a45e43a46d7c149d71810957104742c3db5416fe61ecca75c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2023-175", "level": "error", "message": {"text": "pillow: PYSEC-2023-175"}, "properties": {"repobilityId": 468505, "scanner": "osv-scanner", "fingerprint": "9b1fb61e1cf12b6cd25a05f9c9c10220187b2504e65614e2ec50eb59b4ba2bbb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "package": "pillow", "rule_id": "PYSEC-2023-175", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2023-4863|token", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-j7hp-h8jx-5ppr", "PYSEC-2023-175"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["9b1fb61e1cf12b6cd25a05f9c9c10220187b2504e65614e2ec50eb59b4ba2bbb", "ddb3060a54f15de18f7c42be8fd4698c1d6a2f84253aa680c1cfeae0de85928e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vxpw-j846-p89q", "level": "error", "message": {"text": "undici: GHSA-vxpw-j846-p89q"}, "properties": {"repobilityId": 468504, "scanner": "osv-scanner", "fingerprint": "49e46bc599af296a98fb613a3928fd3b554b117f19b66eda85ebc4fc7f016d3f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-12151"], "package": "undici", "rule_id": "GHSA-vxpw-j846-p89q", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-12151|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vmh5-mc38-953g", "level": "error", "message": {"text": "undici: GHSA-vmh5-mc38-953g"}, "properties": {"repobilityId": 468503, "scanner": "osv-scanner", "fingerprint": "c19cc0a128c18049a6b9882e0d580ea58f87e5887e0acf635cbd2806c55d31a1", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-9697"], "package": "undici", "rule_id": "GHSA-vmh5-mc38-953g", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-9697|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hm92-r4w5-c3mj", "level": "error", "message": {"text": "undici: GHSA-hm92-r4w5-c3mj"}, "properties": {"repobilityId": 468500, "scanner": "osv-scanner", "fingerprint": "bbbfb93644a8a3fa52bc6956a5f3b8660925294a063f0de4a075decca4d0e81f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-6734"], "package": "undici", "rule_id": "GHSA-hm92-r4w5-c3mj", "scanner": "osv-scanner", "correlation_key": "vuln|undici|CVE-2026-6734|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcpb/server/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED008", "level": "error", "message": {"text": "[MINED008] Swift Force Unwrap: optional! crashes on nil. Use guard let or if let."}, "properties": {"repobilityId": 468495, "scanner": "repobility-threat-engine", "fingerprint": "826c66d3a2dcefcca365041950667d978f0f830684b78ba6fa5a6c12bc8b808f", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "swift-force-unwrap", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["swift"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347916+00:00", "triaged_in_corpus": 15, "observations_count": 210453, "ai_coder_pattern_id": 157}, "scanner": "repobility-threat-engine", "correlation_key": "fp|826c66d3a2dcefcca365041950667d978f0f830684b78ba6fa5a6c12bc8b808f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Models/Keyframe.swift"}, "region": {"startLine": 236}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 468493, "scanner": "repobility-threat-engine", "fingerprint": "345d2336e214ed44cb7dd8c6c51027a9db15420bc5adffa56f664abe71e4bf82", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "hasher.update(data: chunk)", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|345d2336e214ed44cb7dd8c6c51027a9db15420bc5adffa56f664abe71e4bf82"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Search/Models/ModelDownloader.swift"}, "region": {"startLine": 151}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 468492, "scanner": "repobility-threat-engine", "fingerprint": "28bbf462165ee88873f2af5b42bf70891bad6473bb5039f801e544872ad36dfc", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "ProjectRegistry.shared.delete(entry.url)", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|28bbf462165ee88873f2af5b42bf70891bad6473bb5039f801e544872ad36dfc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Project/ProjectCard.swift"}, "region": {"startLine": 115}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 468491, "scanner": "repobility-threat-engine", "fingerprint": "67fe1e5da27852567cc5fc12a304af5757212981615a80d4f70e9315bb7e71cb", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "KeychainStore.save(key, account: account)", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|67fe1e5da27852567cc5fc12a304af5757212981615a80d4f70e9315bb7e71cb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Sources/PalmierPro/Agent/Clients/AnthropicClient.swift"}, "region": {"startLine": 11}}}]}, {"ruleId": "GHSA-3f63-hfp8-52jq", "level": "error", "message": {"text": "pillow: GHSA-3f63-hfp8-52jq"}, "properties": {"repobilityId": 468508, "scanner": "osv-scanner", "fingerprint": "45e4cd391027d1c948e3c97d62555b293258079ec32be83a644fd4ec50dc79a3", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2023-50447", "CVE-2023-50447"], "package": "pillow", "rule_id": "GHSA-3f63-hfp8-52jq", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2023-50447|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e4f835c0d8792216", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "e4f835c0d8792216", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "models/siglip2/convert.py:73"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf2915580029c5b2", "level": "error", "message": {"text": "CVE-2026-28980: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "properties": {"repobilityId": "30f2521e1ecb1dff", "scanner": "scanner-primary", "fingerprint": "cf2915580029c5b2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28980"]}}, {"ruleId": "scanner-7bbbe903df2701ba", "level": "error", "message": {"text": "CVE-2026-43671: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "properties": {"repobilityId": "565d2640f9a75eac", "scanner": "scanner-primary", "fingerprint": "7bbbe903df2701ba", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-43671"]}}, {"ruleId": "scanner-3ef4afabd81bdd34", "level": "warning", "message": {"text": "CVE-2026-28970: github.com/apple/swift-nio 2.97.1 \u2014 Package.resolved"}, "properties": {"repobilityId": "bf3c8498da265744", "scanner": "scanner-primary", "fingerprint": "3ef4afabd81bdd34", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28970"]}}, {"ruleId": "scanner-451dcc53742b6ad6", "level": "warning", "message": {"text": "CVE-2026-47121: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved"}, "properties": {"repobilityId": "a55fffc282bbabaa", "scanner": "scanner-primary", "fingerprint": "451dcc53742b6ad6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47121"]}}, {"ruleId": "scanner-eb45bb569ffb54ff", "level": "warning", "message": {"text": "CVE-2026-47122: github.com/sparkle-project/Sparkle 2.9.1 \u2014 Package.resolved"}, "properties": {"repobilityId": "0e518f86f771c66d", "scanner": "scanner-primary", "fingerprint": "eb45bb569ffb54ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47122"]}}, {"ruleId": "scanner-24aae76241cdb498", "level": "error", "message": {"text": "CVE-2026-12151: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "d4fb24b726a41b89", "scanner": "scanner-primary", "fingerprint": "24aae76241cdb498", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12151"]}}, {"ruleId": "scanner-fff412b42960a92e", "level": "error", "message": {"text": "CVE-2026-6734: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "bde0c667f6d74a54", "scanner": "scanner-primary", "fingerprint": "fff412b42960a92e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6734"]}}, {"ruleId": "scanner-9d96e2d27f8dc82f", "level": "error", "message": {"text": "CVE-2026-9697: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "6383b6ca9f14c48a", "scanner": "scanner-primary", "fingerprint": "9d96e2d27f8dc82f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9697"]}}, {"ruleId": "scanner-a03091c57e3f64b8", "level": "warning", "message": {"text": "CVE-2026-9678: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "41ac394f6e2f2572", "scanner": "scanner-primary", "fingerprint": "a03091c57e3f64b8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9678"]}}, {"ruleId": "scanner-72075e5cd920e43c", "level": "warning", "message": {"text": "CVE-2026-9679: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "c8be0cffb6ffbd4e", "scanner": "scanner-primary", "fingerprint": "72075e5cd920e43c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9679"]}}, {"ruleId": "scanner-b72e722e5849e9c1", "level": "note", "message": {"text": "CVE-2026-11525: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "aca703baa7369102", "scanner": "scanner-primary", "fingerprint": "b72e722e5849e9c1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-11525"]}}, {"ruleId": "scanner-9dc225f8b6e52209", "level": "note", "message": {"text": "CVE-2026-6733: undici 7.25.0 \u2014 mcpb/server/package-lock.json"}, "properties": {"repobilityId": "ac73453f05577f5b", "scanner": "scanner-primary", "fingerprint": "9dc225f8b6e52209", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6733"]}}, {"ruleId": "scanner-9daab76003af9a35", "level": "warning", "message": {"text": "CVE-2025-2999: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "properties": {"repobilityId": "77c4bbe83d7f559b", "scanner": "scanner-primary", "fingerprint": "9daab76003af9a35", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2999"]}}, {"ruleId": "scanner-e73bccbc503a2691", "level": "warning", "message": {"text": "CVE-2025-3730: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "properties": {"repobilityId": "9e0d1353de401381", "scanner": "scanner-primary", "fingerprint": "e73bccbc503a2691", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3730"]}}, {"ruleId": "scanner-47a3e497e54e1d26", "level": "note", "message": {"text": "CVE-2025-2953: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "properties": {"repobilityId": "fcd240e29b51a3bd", "scanner": "scanner-primary", "fingerprint": "47a3e497e54e1d26", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2953"]}}, {"ruleId": "scanner-8ceada123302793b", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "properties": {"repobilityId": "f0a53f2c433e3a62", "scanner": "scanner-primary", "fingerprint": "8ceada123302793b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-ff4b0c1381b146d1", "level": "note", "message": {"text": "CVE-2025-3001: torch 2.7.0 \u2014 models/siglip2/requirements.txt"}, "properties": {"repobilityId": "80b3e27747fad30e", "scanner": "scanner-primary", "fingerprint": "ff4b0c1381b146d1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3001"]}}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "bb196b2e19da8ac5", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "94d850970cbf796a", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "8d2c381cfb416f1d", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "2205590755c452ab", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "2fb69a6779e51e9d", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "1d0e2acd6cb94afd", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}]}]}