{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "GHSA-hgf8-39gv-g3f2", "name": "werkzeug: GHSA-hgf8-39gv-g3f2", "shortDescription": {"text": "werkzeug: GHSA-hgf8-39gv-g3f2"}, "fullDescription": {"text": "Werkzeug safe_join() allows Windows special device names"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-87hc-h4r5-73f7", "name": "werkzeug: GHSA-87hc-h4r5-73f7", "shortDescription": {"text": "werkzeug: GHSA-87hc-h4r5-73f7"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names with compound extensions"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-29vq-49wr-vm6x", "name": "werkzeug: GHSA-29vq-49wr-vm6x", "shortDescription": {"text": "werkzeug: GHSA-29vq-49wr-vm6x"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pq67-6m6q-mj2v", "name": "urllib3: GHSA-pq67-6m6q-mj2v", "shortDescription": {"text": "urllib3: GHSA-pq67-6m6q-mj2v"}, "fullDescription": {"text": "urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-48p4-8xcf-vxj5", "name": "urllib3: GHSA-48p4-8xcf-vxj5", "shortDescription": {"text": "urllib3: GHSA-48p4-8xcf-vxj5"}, "fullDescription": {"text": "urllib3 does not control redirects in browsers and Node.js"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-rcv9-qm8p-9p6j", "name": "transformers: GHSA-rcv9-qm8p-9p6j", "shortDescription": {"text": "transformers: GHSA-rcv9-qm8p-9p6j"}, "fullDescription": {"text": "Hugging Face Transformers library has Regular Expression Denial of Service"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q2wp-rjmx-x6x9", "name": "transformers: GHSA-q2wp-rjmx-x6x9", "shortDescription": {"text": "transformers: GHSA-q2wp-rjmx-x6x9"}, "fullDescription": {"text": "Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jjph-296x-mrcr", "name": "transformers: GHSA-jjph-296x-mrcr", "shortDescription": {"text": "transformers: GHSA-jjph-296x-mrcr"}, "fullDescription": {"text": "Transformers vulnerable to ReDoS attack through its get_imports() function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fpwr-67px-3qhx", "name": "transformers: GHSA-fpwr-67px-3qhx", "shortDescription": {"text": "transformers: GHSA-fpwr-67px-3qhx"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9356-575x-2w9m", "name": "transformers: GHSA-9356-575x-2w9m", "shortDescription": {"text": "transformers: GHSA-9356-575x-2w9m"}, "fullDescription": {"text": "Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6rvg-6v2m-4j46", "name": "transformers: GHSA-6rvg-6v2m-4j46", "shortDescription": {"text": "transformers: GHSA-6rvg-6v2m-4j46"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-69w3-r845-3855", "name": "transformers: GHSA-69w3-r845-3855", "shortDescription": {"text": "transformers: GHSA-69w3-r845-3855"}, "fullDescription": {"text": "HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-59p9-h35m-wg4g", "name": "transformers: GHSA-59p9-h35m-wg4g", "shortDescription": {"text": "transformers: GHSA-59p9-h35m-wg4g"}, "fullDescription": {"text": "Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4w7r-h757-3r74", "name": "transformers: GHSA-4w7r-h757-3r74", "shortDescription": {"text": "transformers: GHSA-4w7r-h757-3r74"}, "fullDescription": {"text": "Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-37mw-44qp-f5jm", "name": "transformers: GHSA-37mw-44qp-f5jm", "shortDescription": {"text": "transformers: GHSA-37mw-44qp-f5jm"}, "fullDescription": {"text": "Transformers is vulnerable to ReDoS attack through its DonutProcessor class"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pw6j-qg29-8w7f", "name": "tornado: GHSA-pw6j-qg29-8w7f", "shortDescription": {"text": "tornado: GHSA-pw6j-qg29-8w7f"}, "fullDescription": {"text": "Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-78cv-mqj4-43f7", "name": "tornado: GHSA-78cv-mqj4-43f7", "shortDescription": {"text": "tornado: GHSA-78cv-mqj4-43f7"}, "fullDescription": {"text": "Tornado has incomplete validation of cookie attributes"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vgrw-7cvw-pwgx", "name": "torch: GHSA-vgrw-7cvw-pwgx", "shortDescription": {"text": "torch: GHSA-vgrw-7cvw-pwgx"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its unpack_sequence function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f4hp-rmr7-r7v8", "name": "torch: GHSA-f4hp-rmr7-r7v8", "shortDescription": {"text": "torch: GHSA-f4hp-rmr7-r7v8"}, "fullDescription": {"text": "PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-887c-mr87-cxwp", "name": "torch: GHSA-887c-mr87-cxwp", "shortDescription": {"text": "torch: GHSA-887c-mr87-cxwp"}, "fullDescription": {"text": "PyTorch Improper Resource Shutdown or Release vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fxgc-95xx-grvq", "name": "tensorflow: GHSA-fxgc-95xx-grvq", "shortDescription": {"text": "tensorflow: GHSA-fxgc-95xx-grvq"}, "fullDescription": {"text": "TensorFlow Denial of Service vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fqm2-gh8w-gr68", "name": "tensorflow: GHSA-fqm2-gh8w-gr68", "shortDescription": {"text": "tensorflow: GHSA-fqm2-gh8w-gr68"}, "fullDescription": {"text": "TensorFlow vulnerable to segfault when opening multiframe gif"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gc5v-m9x4-r6x2", "name": "requests: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9hjg-9r4m-mvj7", "name": "requests: GHSA-9hjg-9r4m-mvj7", "shortDescription": {"text": "requests: GHSA-9hjg-9r4m-mvj7"}, "fullDescription": {"text": "Requests vulnerable to .netrc credentials leak via malicious URLs"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6w46-j5rx-g56g", "name": "pytest: GHSA-6w46-j5rx-g56g", "shortDescription": {"text": "pytest: GHSA-6w46-j5rx-g56g"}, "fullDescription": {"text": "pytest has vulnerable tmpdir handling"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r73j-pqj5-w3x7", "name": "pillow: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "Pillow has a PDF Parsing Trailer Infinite Loop (DoS)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-rf74-v2fm-23pw", "name": "nltk: GHSA-rf74-v2fm-23pw", "shortDescription": {"text": "nltk: GHSA-rf74-v2fm-23pw"}, "fullDescription": {"text": "Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gfwx-w7gr-fvh7", "name": "nltk: GHSA-gfwx-w7gr-fvh7", "shortDescription": {"text": "nltk: GHSA-gfwx-w7gr-fvh7"}, "fullDescription": {"text": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7jqv-fw35-gmx9", "name": "nbconvert: GHSA-7jqv-fw35-gmx9", "shortDescription": {"text": "nbconvert: GHSA-7jqv-fw35-gmx9"}, "fullDescription": {"text": "nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4c99-qj7h-p3vg", "name": "nbconvert: GHSA-4c99-qj7h-p3vg", "shortDescription": {"text": "nbconvert: GHSA-4c99-qj7h-p3vg"}, "fullDescription": {"text": "nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-v87v-83h2-53w7", "name": "mistune: GHSA-v87v-83h2-53w7", "shortDescription": {"text": "mistune: GHSA-v87v-83h2-53w7"}, "fullDescription": {"text": "Mistune Heading ID Attribute has Injection XSS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8g87-j6q8-g93x", "name": "mistune: GHSA-8g87-j6q8-g93x", "shortDescription": {"text": "mistune: GHSA-8g87-j6q8-g93x"}, "fullDescription": {"text": "Mistune Math Plugin has an XSS Escape Bypass"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mq84-hjqx-cwf2", "name": "keras: GHSA-mq84-hjqx-cwf2", "shortDescription": {"text": "keras: GHSA-mq84-hjqx-cwf2"}, "fullDescription": {"text": "Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vmhf-c436-hxj4", "name": "jupyterlab: GHSA-vmhf-c436-hxj4", "shortDescription": {"text": "jupyterlab: GHSA-vmhf-c436-hxj4"}, "fullDescription": {"text": "JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-cpwx-vrp4-4pq7", "name": "jinja2: GHSA-cpwx-vrp4-4pq7", "shortDescription": {"text": "jinja2: GHSA-cpwx-vrp4-4pq7"}, "fullDescription": {"text": "Jinja2 vulnerable to sandbox breakout through attr filter selecting format method"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-768j-98cg-p3fv", "name": "fonttools: GHSA-768j-98cg-p3fv", "shortDescription": {"text": "fonttools: GHSA-768j-98cg-p3fv"}, "fullDescription": {"text": "fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-w853-jp5j-5j7f", "name": "filelock: GHSA-w853-jp5j-5j7f", "shortDescription": {"text": "filelock: GHSA-w853-jp5j-5j7f"}, "fullDescription": {"text": "filelock has a TOCTOU race condition which allows symlink attacks during lock file creation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qmgc-5h2g-mvrw", "name": "filelock: GHSA-qmgc-5h2g-mvrw", "shortDescription": {"text": "filelock: GHSA-qmgc-5h2g-mvrw"}, "fullDescription": {"text": "filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gj48-438w-jh9v", "name": "bleach: GHSA-gj48-438w-jh9v", "shortDescription": {"text": "bleach: GHSA-gj48-438w-jh9v"}, "fullDescription": {"text": "Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "SEC045", "name": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a latera", "shortDescription": {"text": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a lateral-movement vector after any one credential compromise. Sandboxes (__builtins__ cleared) are escapable: attackers use obj"}, "fullDescription": {"text": "For literal data structures: use ast.literal_eval(text) \u2014 only parses literals, raises on code.\nFor formula evaluation: use asteval or simpleeval (purpose-built sandboxes with allow-lists).\nFor Odoo: use odoo.tools.safe_eval(expr, locals_dict, mode='exec').\nIf you genuinely need to execute admin-stored code: require explicit super-admin permission AND log every execution with a stack trace."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC012", "name": "[SEC012] ZipSlip \u2014 Archive Path Traversal: Archive extraction without path validation allows writing files outside the t", "shortDescription": {"text": "[SEC012] ZipSlip \u2014 Archive Path Traversal: Archive extraction without path validation allows writing files outside the target directory."}, "fullDescription": {"text": "Validate extracted paths with os.path.realpath() and ensure they stay within the target directory."}, "properties": {"scanner": "repobility-threat-engine", "category": "path_traversal", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC127", "name": "[SEC127] AI agent stub \u2014 TODO: implement / pass placeholder body: Function body left as TODO/pass/raise NotImplementedEr", "shortDescription": {"text": "[SEC127] AI agent stub \u2014 TODO: implement / pass placeholder body: Function body left as TODO/pass/raise NotImplementedError after an AI scaffolding pass. The route appears to exist (and may even pass shallow CI), but invoking it crashes or "}, "fullDescription": {"text": "Either implement the body, or fail closed at module-load time so the deploy can't ship a half-built route. A CI gate that fails build on `raise NotImplementedError` in non-abstract code catches this cleanly."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "ERR001", "name": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG ", "shortDescription": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "fullDescription": {"text": "Log the error: `except Exception: logger.debug('cleanup failed', exc_info=True)`. Or handle specific exception types."}, "properties": {"scanner": "repobility-threat-engine", "category": "error_handling", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "AGT015", "name": "Remote install command pipes network code directly to a shell", "shortDescription": {"text": "Remote install command pipes network code directly to a shell"}, "fullDescription": {"text": "Agent helper projects often publish one-line installers. `curl | sh` style commands are convenient, but they bypass review unless the script is pinned, signed, or checksum-verified."}, "properties": {"scanner": "repobility-agent-runtime", "category": "dependency", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "DEPCUR-PY", "name": "Python package `cachetools` is 2 major version(s) behind (5.5.0 -> 7.1.4)", "shortDescription": {"text": "Python package `cachetools` is 2 major version(s) behind (5.5.0 -> 7.1.4)"}, "fullDescription": {"text": "poetry.lock pins `cachetools` at 5.5.0 but the latest stable release on PyPI is 7.1.4 (2 major version(s) behind)."}, "properties": {"scanner": "repobility-dependency-currency", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED109", "name": "Mutable default argument in `forecast` (list)", "shortDescription": {"text": "Mutable default argument in `forecast` (list)"}, "fullDescription": {"text": "`def forecast(... = []/{}/set())` \u2014 Python's default value is constructed ONCE at function definition time and shared across all calls. Mutating it in one call mutates it for every future call too."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED111", "name": "Bare except continues silently", "shortDescription": {"text": "Bare except continues silently"}, "fullDescription": {"text": "Bare `except:` (or `except Exception:`) that runs code without re-raising or logging the exception. Hides real failures and makes bugs hard to diagnose."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "GHSA-phhr-52qp-3mj4", "name": "transformers: GHSA-phhr-52qp-3mj4", "shortDescription": {"text": "transformers: GHSA-phhr-52qp-3mj4"}, "fullDescription": {"text": "Transformers's Improper Input Validation vulnerability can be exploited through username injection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-cx3h-4qpv-8hc9", "name": "tornado: GHSA-cx3h-4qpv-8hc9", "shortDescription": {"text": "tornado: GHSA-cx3h-4qpv-8hc9"}, "fullDescription": {"text": "Tornado has out-of-bounds memory access via C extension"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-x3gm-94wq-g975", "name": "torch: GHSA-x3gm-94wq-g975", "shortDescription": {"text": "torch: GHSA-x3gm-94wq-g975"}, "fullDescription": {"text": "PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-rrmf-rvhw-rf47", "name": "torch: GHSA-rrmf-rvhw-rf47", "shortDescription": {"text": "torch: GHSA-rrmf-rvhw-rf47"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its torch.jit.script function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qfhq-4f3w-5fph", "name": "torch: GHSA-qfhq-4f3w-5fph", "shortDescription": {"text": "torch: GHSA-qfhq-4f3w-5fph"}, "fullDescription": {"text": "PyTorch is vulnerable to memory corruption through its torch.lstm_cell function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-c678-jfcj-6jmf", "name": "torch: GHSA-c678-jfcj-6jmf", "shortDescription": {"text": "torch: GHSA-c678-jfcj-6jmf"}, "fullDescription": {"text": "PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5239-wwwm-4pmq", "name": "pygments: GHSA-5239-wwwm-4pmq", "shortDescription": {"text": "pygments: GHSA-5239-wwwm-4pmq"}, "fullDescription": {"text": "Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vvfj-2jqx-52jm", "name": "jupyterlab: GHSA-vvfj-2jqx-52jm", "shortDescription": {"text": "jupyterlab: GHSA-vvfj-2jqx-52jm"}, "fullDescription": {"text": "JupyterLab LaTeX typesetter links did not enforce `noopener` attribute"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8rfp-98v4-mmr6", "name": "bleach: GHSA-8rfp-98v4-mmr6", "shortDescription": {"text": "bleach: GHSA-8rfp-98v4-mmr6"}, "fullDescription": {"text": "Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "COMP001", "name": "[COMP001] High cognitive complexity: Function `forward` has cognitive complexity 9 (SonarSource scale). Cognitive comple", "shortDescription": {"text": "[COMP001] High cognitive complexity: Function `forward` has cognitive complexity 9 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all we"}, "fullDescription": {"text": "Extract nested branches into named helper functions; flatten early-return / guard clauses; replace long if/elif chains with dispatch dicts or polymorphism. SonarQube's threshold for 'should refactor' is 15 \u2014 yours is 9."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "low", "confidence": 0.95, "cwe": "", "owasp": ""}}, {"id": "MINED115", "name": "Action `actions/setup-python` pinned to mutable ref `@v6`", "shortDescription": {"text": "Action `actions/setup-python` pinned to mutable ref `@v6`"}, "fullDescription": {"text": "`uses: actions/setup-python@v6` resolves at workflow-run time. Tags and branches can be re-pushed by the action owner; that made the tj-actions/changed-files compromise (2025) instantly affect many repos. Treat official first-party action tags as lower risk, but pin security-sensitive third-party actions to a 40-char commit SHA + lock with Dependabot or renovate."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "low", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "AIC003", "name": "Duplicated implementation block across source files", "shortDescription": {"text": "Duplicated implementation block across source files"}, "fullDescription": {"text": "Duplicated blocks are a common artifact when generated code is pasted or recreated instead of reused. They increase maintenance cost because every future bug fix must be found in multiple locations."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.86, "cwe": "", "owasp": ""}}, {"id": "SEC011", "name": "[SEC011] Unsafe PyTorch Model Loading: torch.load() uses pickle internally and can execute arbitrary code from untrusted", "shortDescription": {"text": "[SEC011] Unsafe PyTorch Model Loading: torch.load() uses pickle internally and can execute arbitrary code from untrusted model files."}, "fullDescription": {"text": "Use torch.load(..., weights_only=True) or use safetensors format."}, "properties": {"scanner": "repobility-threat-engine", "category": "deserialization", "severity": "info", "confidence": 0.1, "cwe": "", "owasp": ""}}, {"id": "MINED057", "name": "[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness \u2014 left for later but never resolve", "shortDescription": {"text": "[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness \u2014 left for later but never resolved."}, "fullDescription": {"text": "Review and fix per the pattern semantics."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED050", "name": "[MINED050] Stub Only Function (and 1 more): Same pattern found in 1 additional files. Review if needed.", "shortDescription": {"text": "[MINED050] Stub Only Function (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-1188 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "GHSA-8rrh-rw8j-w5fx", "name": "wheel: GHSA-8rrh-rw8j-w5fx", "shortDescription": {"text": "wheel: GHSA-8rrh-rw8j-w5fx"}, "fullDescription": {"text": "Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gm62-xv2j-4w53", "name": "urllib3: GHSA-gm62-xv2j-4w53", "shortDescription": {"text": "urllib3: GHSA-gm62-xv2j-4w53"}, "fullDescription": {"text": "urllib3 allows an unbounded number of links in the decompression chain"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-38jv-5279-wg99", "name": "urllib3: GHSA-38jv-5279-wg99", "shortDescription": {"text": "urllib3: GHSA-38jv-5279-wg99"}, "fullDescription": {"text": "Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-2xpw-w6gg-jr37", "name": "urllib3: GHSA-2xpw-w6gg-jr37", "shortDescription": {"text": "urllib3: GHSA-2xpw-w6gg-jr37"}, "fullDescription": {"text": "urllib3 streaming API improperly handles highly compressed data"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-141", "name": "urllib3: PYSEC-2026-141", "shortDescription": {"text": "urllib3: PYSEC-2026-141"}, "fullDescription": {"text": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-40", "name": "transformers: PYSEC-2025-40", "shortDescription": {"text": "transformers: PYSEC-2025-40"}, "fullDescription": {"text": "A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-218", "name": "transformers: PYSEC-2025-218", "shortDescription": {"text": "transformers: PYSEC-2025-218"}, "fullDescription": {"text": "Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of weights. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28309."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-217", "name": "transformers: PYSEC-2025-217", "shortDescription": {"text": "transformers: PYSEC-2025-217"}, "fullDescription": {"text": "Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-216", "name": "transformers: PYSEC-2025-216", "shortDescription": {"text": "transformers: PYSEC-2025-216"}, "fullDescription": {"text": "Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.\n\nThe specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-28253."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-215", "name": "transformers: PYSEC-2025-215", "shortDescription": {"text": "transformers: PYSEC-2025-215"}, "fullDescription": {"text": "Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.\n\nThe specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.\n\n. Was ZDI-CAN-28252."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-214", "name": "transformers: PYSEC-2025-214", "shortDescription": {"text": "transformers: PYSEC-2025-214"}, "fullDescription": {"text": "Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.\n\nThe specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-28251."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-213", "name": "transformers: PYSEC-2025-213", "shortDescription": {"text": "transformers: PYSEC-2025-213"}, "fullDescription": {"text": "Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27984."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-212", "name": "transformers: PYSEC-2025-212", "shortDescription": {"text": "transformers: PYSEC-2025-212"}, "fullDescription": {"text": "Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25424."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-211", "name": "transformers: PYSEC-2025-211", "shortDescription": {"text": "transformers: PYSEC-2025-211"}, "fullDescription": {"text": "Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25423."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2024-229", "name": "transformers: PYSEC-2024-229", "shortDescription": {"text": "transformers: PYSEC-2024-229"}, "fullDescription": {"text": "Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25012."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2024-228", "name": "transformers: PYSEC-2024-228", "shortDescription": {"text": "transformers: PYSEC-2024-228"}, "fullDescription": {"text": "Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25191."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2024-227", "name": "transformers: PYSEC-2024-227", "shortDescription": {"text": "transformers: PYSEC-2024-227"}, "fullDescription": {"text": "Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-24322."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mgf9-4vpg-hj56", "name": "tornado: GHSA-mgf9-4vpg-hj56", "shortDescription": {"text": "tornado: GHSA-mgf9-4vpg-hj56"}, "fullDescription": {"text": "tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fqwm-6jpj-5wxc", "name": "tornado: GHSA-fqwm-6jpj-5wxc", "shortDescription": {"text": "tornado: GHSA-fqwm-6jpj-5wxc"}, "fullDescription": {"text": "Tornado has cookie attribute injection via .RequestHandler.set_cookie"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7cx3-6m66-7c5m", "name": "tornado: GHSA-7cx3-6m66-7c5m", "shortDescription": {"text": "tornado: GHSA-7cx3-6m66-7c5m"}, "fullDescription": {"text": "Tornado vulnerable to excessive logging caused by malformed multipart form data"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3x9g-8vmp-wqvf", "name": "tornado: GHSA-3x9g-8vmp-wqvf", "shortDescription": {"text": "tornado: GHSA-3x9g-8vmp-wqvf"}, "fullDescription": {"text": "Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-140", "name": "tornado: PYSEC-2026-140", "shortDescription": {"text": "tornado: PYSEC-2026-140"}, "fullDescription": {"text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-139", "name": "torch: PYSEC-2026-139", "shortDescription": {"text": "torch: PYSEC-2026-139"}, "fullDescription": {"text": "A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-209", "name": "torch: PYSEC-2025-209", "shortDescription": {"text": "torch: PYSEC-2025-209"}, "fullDescription": {"text": "An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-208", "name": "torch: PYSEC-2025-208", "shortDescription": {"text": "torch: PYSEC-2025-208"}, "fullDescription": {"text": "A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-207", "name": "torch: PYSEC-2025-207", "shortDescription": {"text": "torch: PYSEC-2025-207"}, "fullDescription": {"text": "A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-206", "name": "torch: PYSEC-2025-206", "shortDescription": {"text": "torch: PYSEC-2025-206"}, "fullDescription": {"text": "pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long()."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-205", "name": "torch: PYSEC-2025-205", "shortDescription": {"text": "torch: PYSEC-2025-205"}, "fullDescription": {"text": "A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-204", "name": "torch: PYSEC-2025-204", "shortDescription": {"text": "torch: PYSEC-2025-204"}, "fullDescription": {"text": "pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-203", "name": "torch: PYSEC-2025-203", "shortDescription": {"text": "torch: PYSEC-2025-203"}, "fullDescription": {"text": "An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-198", "name": "torch: PYSEC-2025-198", "shortDescription": {"text": "torch: PYSEC-2025-198"}, "fullDescription": {"text": "In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-191", "name": "torch: PYSEC-2025-191", "shortDescription": {"text": "torch: PYSEC-2025-191"}, "fullDescription": {"text": "A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2024-259", "name": "torch: PYSEC-2024-259", "shortDescription": {"text": "torch: PYSEC-2024-259"}, "fullDescription": {"text": "In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-rcf8-g8jv-vg6p", "name": "tensorflow: GHSA-rcf8-g8jv-vg6p", "shortDescription": {"text": "tensorflow: GHSA-rcf8-g8jv-vg6p"}, "fullDescription": {"text": "TensorFlow has Floating Point Exception in AvgPoolGrad with XLA"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qjqc-vqcf-5qvj", "name": "tensorflow: GHSA-qjqc-vqcf-5qvj", "shortDescription": {"text": "tensorflow: GHSA-qjqc-vqcf-5qvj"}, "fullDescription": {"text": "TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-j5w9-hmfh-4cr6", "name": "tensorflow: GHSA-j5w9-hmfh-4cr6", "shortDescription": {"text": "tensorflow: GHSA-j5w9-hmfh-4cr6"}, "fullDescription": {"text": "TensorFlow has segmentation fault in tfg-translate "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gjh7-xx4r-x345", "name": "tensorflow: GHSA-gjh7-xx4r-x345", "shortDescription": {"text": "tensorflow: GHSA-gjh7-xx4r-x345"}, "fullDescription": {"text": "TensorFlow has segfault in array_ops.upper_bound"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gf97-q72m-7579", "name": "tensorflow: GHSA-gf97-q72m-7579", "shortDescription": {"text": "tensorflow: GHSA-gf97-q72m-7579"}, "fullDescription": {"text": "TensorFlow has Null Pointer Error in RandomShuffle with XLA enable "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f637-vh3r-vfh2", "name": "tensorflow: GHSA-f637-vh3r-vfh2", "shortDescription": {"text": "tensorflow: GHSA-f637-vh3r-vfh2"}, "fullDescription": {"text": "TensorFlow has Floating Point Exception in AudioSpectrogram "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f49c-87jh-g47q", "name": "tensorflow: GHSA-f49c-87jh-g47q", "shortDescription": {"text": "tensorflow: GHSA-f49c-87jh-g47q"}, "fullDescription": {"text": "TensorFlow has double free in Fractional(Max/Avg)Pool"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-94mm-g2mv-8p7r", "name": "tensorflow: GHSA-94mm-g2mv-8p7r", "shortDescription": {"text": "tensorflow: GHSA-94mm-g2mv-8p7r"}, "fullDescription": {"text": "TensorFlow has Null Pointer Error in LookupTableImportV2"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-93vr-9q9m-pj8p", "name": "tensorflow: GHSA-93vr-9q9m-pj8p", "shortDescription": {"text": "tensorflow: GHSA-93vr-9q9m-pj8p"}, "fullDescription": {"text": "TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7x4v-9gxg-9hwj", "name": "tensorflow: GHSA-7x4v-9gxg-9hwj", "shortDescription": {"text": "tensorflow: GHSA-7x4v-9gxg-9hwj"}, "fullDescription": {"text": "TensorFlow has Segfault in Bincount with XLA"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7jvm-xxmr-v5cw", "name": "tensorflow: GHSA-7jvm-xxmr-v5cw", "shortDescription": {"text": "tensorflow: GHSA-7jvm-xxmr-v5cw"}, "fullDescription": {"text": "TensorFlow vulnerable to integer overflow in EditDistance"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6wfh-89q8-44jq", "name": "tensorflow: GHSA-6wfh-89q8-44jq", "shortDescription": {"text": "tensorflow: GHSA-6wfh-89q8-44jq"}, "fullDescription": {"text": "TensorFlow has null dereference on ParallelConcat with XLA"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6hg6-5c2q-7rcr", "name": "tensorflow: GHSA-6hg6-5c2q-7rcr", "shortDescription": {"text": "tensorflow: GHSA-6hg6-5c2q-7rcr"}, "fullDescription": {"text": "TensorFlow has Heap-buffer-overflow in AvgPoolGrad "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-68v3-g9cm-rmm6", "name": "tensorflow: GHSA-68v3-g9cm-rmm6", "shortDescription": {"text": "tensorflow: GHSA-68v3-g9cm-rmm6"}, "fullDescription": {"text": "TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-64jg-wjww-7c5w", "name": "tensorflow: GHSA-64jg-wjww-7c5w", "shortDescription": {"text": "tensorflow: GHSA-64jg-wjww-7c5w"}, "fullDescription": {"text": "TensorFlow has Null Pointer Error in TensorArrayConcatV2"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-647v-r7qq-24fh", "name": "tensorflow: GHSA-647v-r7qq-24fh", "shortDescription": {"text": "tensorflow: GHSA-647v-r7qq-24fh"}, "fullDescription": {"text": "TensorFlow has Floating Point Exception in TensorListSplit with XLA "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5w96-866f-6rm8", "name": "tensorflow: GHSA-5w96-866f-6rm8", "shortDescription": {"text": "tensorflow: GHSA-5w96-866f-6rm8"}, "fullDescription": {"text": "TensorFlow has Floating Point Exception in TFLite in conv kernel"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-558h-mq8x-7q9g", "name": "tensorflow: GHSA-558h-mq8x-7q9g", "shortDescription": {"text": "tensorflow: GHSA-558h-mq8x-7q9g"}, "fullDescription": {"text": "TensorFlow has Null Pointer Error in SparseSparseMaximum"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-49rq-hwc3-x77w", "name": "tensorflow: GHSA-49rq-hwc3-x77w", "shortDescription": {"text": "tensorflow: GHSA-49rq-hwc3-x77w"}, "fullDescription": {"text": "TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-49", "name": "setuptools: PYSEC-2025-49", "shortDescription": {"text": "setuptools: PYSEC-2025-49"}, "fullDescription": {"text": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-38vq-g6vr-w8wf", "name": "sentencepiece: GHSA-38vq-g6vr-w8wf", "shortDescription": {"text": "sentencepiece: GHSA-38vq-g6vr-w8wf"}, "fullDescription": {"text": "Sentencepiece has a a heap overflow issue"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jr27-m4p2-rc6r", "name": "pyasn1: GHSA-jr27-m4p2-rc6r", "shortDescription": {"text": "pyasn1: GHSA-jr27-m4p2-rc6r"}, "fullDescription": {"text": "Denial of Service in pyasn1 via Unbounded Recursion"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-63vm-454h-vhhq", "name": "pyasn1: GHSA-63vm-454h-vhhq", "shortDescription": {"text": "pyasn1: GHSA-63vm-454h-vhhq"}, "fullDescription": {"text": "pyasn1 has a DoS vulnerability in decoder"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8qvm-5x2c-j2w7", "name": "protobuf: GHSA-8qvm-5x2c-j2w7", "shortDescription": {"text": "protobuf: GHSA-8qvm-5x2c-j2w7"}, "fullDescription": {"text": "protobuf-python has a potential Denial of Service issue"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7gcm-g887-7qv7", "name": "protobuf: GHSA-7gcm-g887-7qv7", "shortDescription": {"text": "protobuf: GHSA-7gcm-g887-7qv7"}, "fullDescription": {"text": "protobuf affected by a JSON recursion depth bypass"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-whj4-6x5x-4v2j", "name": "pillow: GHSA-whj4-6x5x-4v2j", "shortDescription": {"text": "pillow: GHSA-whj4-6x5x-4v2j"}, "fullDescription": {"text": "FITS GZIP decompression bomb in Pillow"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pwv6-vv43-88gr", "name": "pillow: GHSA-pwv6-vv43-88gr", "shortDescription": {"text": "pillow: GHSA-pwv6-vv43-88gr"}, "fullDescription": {"text": "Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-cfh3-3jmp-rvhc", "name": "pillow: GHSA-cfh3-3jmp-rvhc", "shortDescription": {"text": "pillow: GHSA-cfh3-3jmp-rvhc"}, "fullDescription": {"text": "Pillow affected by out-of-bounds write when loading PSD images"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-165", "name": "pillow: PYSEC-2026-165", "shortDescription": {"text": "pillow: PYSEC-2026-165"}, "fullDescription": {"text": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-rch3-82jr-f9w9", "name": "notebook: GHSA-rch3-82jr-f9w9", "shortDescription": {"text": "notebook: GHSA-rch3-82jr-f9w9"}, "fullDescription": {"text": "Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mqcg-5x36-vfcg", "name": "notebook: GHSA-mqcg-5x36-vfcg", "shortDescription": {"text": "notebook: GHSA-mqcg-5x36-vfcg"}, "fullDescription": {"text": "JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-p4gq-832x-fm9v", "name": "nltk: GHSA-p4gq-832x-fm9v", "shortDescription": {"text": "nltk: GHSA-p4gq-832x-fm9v"}, "fullDescription": {"text": "Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jm6w-m3j8-898g", "name": "nltk: GHSA-jm6w-m3j8-898g", "shortDescription": {"text": "nltk: GHSA-jm6w-m3j8-898g"}, "fullDescription": {"text": "Unauthenticated remote shutdown in nltk.app.wordnet_app"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-469j-vmhf-r6v7", "name": "nltk: GHSA-469j-vmhf-r6v7", "shortDescription": {"text": "nltk: GHSA-469j-vmhf-r6v7"}, "fullDescription": {"text": "NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-99", "name": "nltk: PYSEC-2026-99", "shortDescription": {"text": "nltk: PYSEC-2026-99"}, "fullDescription": {"text": "NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-98", "name": "nltk: PYSEC-2026-98", "shortDescription": {"text": "nltk: PYSEC-2026-98"}, "fullDescription": {"text": "A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly critical in scenarios where user-controlled file inputs are processed, such as in machine learning APIs, chatbots, or NLP pipelines. Exploitation of this vulnerability can lead to unauthorized access to sensitive files, including system files, SSH private keys, and API tokens, and may potentially escalate to remote code execution when combined with other vulnerabilities."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-97", "name": "nltk: PYSEC-2026-97", "shortDescription": {"text": "nltk: PYSEC-2026-97"}, "fullDescription": {"text": "A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xm59-rqc7-hhvf", "name": "nbconvert: GHSA-xm59-rqc7-hhvf", "shortDescription": {"text": "nbconvert: GHSA-xm59-rqc7-hhvf"}, "fullDescription": {"text": "nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6v7p-g79w-8964", "name": "msgpack: GHSA-6v7p-g79w-8964", "shortDescription": {"text": "msgpack: GHSA-6v7p-g79w-8964"}, "fullDescription": {"text": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8mp2-v27r-99xp", "name": "mistune: GHSA-8mp2-v27r-99xp", "shortDescription": {"text": "mistune: GHSA-8mp2-v27r-99xp"}, "fullDescription": {"text": "Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-168", "name": "mistune: PYSEC-2026-168", "shortDescription": {"text": "mistune: PYSEC-2026-168"}, "fullDescription": {"text": "Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-89", "name": "markdown: PYSEC-2026-89", "shortDescription": {"text": "markdown: PYSEC-2026-89"}, "fullDescription": {"text": "Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-87", "name": "lxml: PYSEC-2026-87", "shortDescription": {"text": "lxml: PYSEC-2026-87"}, "fullDescription": {"text": "lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hjqc-jx6g-rwp9", "name": "keras: GHSA-hjqc-jx6g-rwp9", "shortDescription": {"text": "keras: GHSA-hjqc-jx6g-rwp9"}, "fullDescription": {"text": "Keras Directory Traversal Vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4f3f-g24h-fr8m", "name": "keras: GHSA-4f3f-g24h-fr8m", "shortDescription": {"text": "keras: GHSA-4f3f-g24h-fr8m"}, "fullDescription": {"text": "Keras has an untrusted deserialization vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-36fq-jgmw-4r9c", "name": "keras: GHSA-36fq-jgmw-4r9c", "shortDescription": {"text": "keras: GHSA-36fq-jgmw-4r9c"}, "fullDescription": {"text": "Keras is vulnerable to Deserialization of Untrusted Data"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-121", "name": "keras: PYSEC-2025-121", "shortDescription": {"text": "keras: PYSEC-2025-121"}, "fullDescription": {"text": "An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-164", "name": "jupyterlab: PYSEC-2026-164", "shortDescription": {"text": "jupyterlab: PYSEC-2026-164"}, "fullDescription": {"text": "JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-24qx-w28j-9m6p", "name": "jupyter-server: GHSA-24qx-w28j-9m6p", "shortDescription": {"text": "jupyter-server: GHSA-24qx-w28j-9m6p"}, "fullDescription": {"text": "Jupyter Server has a  CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-69", "name": "jupyter-server: PYSEC-2026-69", "shortDescription": {"text": "jupyter-server: PYSEC-2026-69"}, "fullDescription": {"text": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-68", "name": "jupyter-server: PYSEC-2026-68", "shortDescription": {"text": "jupyter-server: PYSEC-2026-68"}, "fullDescription": {"text": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named \"test\", the API permits access to a sibling directory named \"testtest\" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can read, write, and delete files in affected sibling directories. Multi-tenant deployments using predictable naming schemes are particularly at risk, as a user with a directory named \"user1\" could access directories for user10 through user19 and beyond. A user who can choose a single-character folder name could gain access to a significant number of sibling directories. \n\nVersion 2.18.0 contains a fix. As a workaround, ensure folder names do not share a common prefix with any sibling directory."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-67", "name": "jupyter-server: PYSEC-2026-67", "shortDescription": {"text": "jupyter-server: PYSEC-2026-67"}, "fullDescription": {"text": "Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-33p9-3p43-82vq", "name": "jupyter-core: GHSA-33p9-3p43-82vq", "shortDescription": {"text": "jupyter-core: GHSA-33p9-3p43-82vq"}, "fullDescription": {"text": "Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-215", "name": "idna: PYSEC-2026-215", "shortDescription": {"text": "idna: PYSEC-2026-215"}, "fullDescription": {"text": "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If thi"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-x2qx-6953-8485", "name": "gitpython: GHSA-x2qx-6953-8485", "shortDescription": {"text": "gitpython: GHSA-x2qx-6953-8485"}, "fullDescription": {"text": "GitPython: Unsafe option check validates multi_options before shlex.split transformation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-v87r-6q3f-2j67", "name": "gitpython: GHSA-v87r-6q3f-2j67", "shortDescription": {"text": "gitpython: GHSA-v87r-6q3f-2j67"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mv93-w799-cj2w", "name": "gitpython: GHSA-mv93-w799-cj2w", "shortDescription": {"text": "gitpython: GHSA-mv93-w799-cj2w"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7545-fcxq-7j24", "name": "gitpython: GHSA-7545-fcxq-7j24", "shortDescription": {"text": "gitpython: GHSA-7545-fcxq-7j24"}, "fullDescription": {"text": "GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "MINED001", "name": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInt", "shortDescription": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-755 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED106", "name": "Phantom test coverage: test_df", "shortDescription": {"text": "Phantom test coverage: test_df"}, "fullDescription": {"text": "Test function `test_df` runs code but contains no assert / expect / should call \u2014 it passes regardless of behaviour. Adds line coverage without verifying anything."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED108", "name": "`self.model_p` used but never assigned in __init__", "shortDescription": {"text": "`self.model_p` used but never assigned in __init__"}, "fullDescription": {"text": "Method `load_from_checkpoint` of class `TimesFmJax` reads `self.model_p`, but no assignment to it exists in __init__ (and no class-level fallback). This raises AttributeError the first time the method runs against an instance."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "GHSA-53q9-r3pm-6pq6", "name": "torch: GHSA-53q9-r3pm-6pq6", "shortDescription": {"text": "torch: GHSA-53q9-r3pm-6pq6"}, "fullDescription": {"text": "PyTorch: `torch.load` with `weights_only=True` leads to remote code execution"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gw97-ff7c-9v96", "name": "tensorflow: GHSA-gw97-ff7c-9v96", "shortDescription": {"text": "tensorflow: GHSA-gw97-ff7c-9v96"}, "fullDescription": {"text": "TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7p94-766c-hgjp", "name": "nltk: GHSA-7p94-766c-hgjp", "shortDescription": {"text": "nltk: GHSA-7p94-766c-hgjp"}, "fullDescription": {"text": "NLTK has a Zip Slip Vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-x4wf-678h-2pmq", "name": "keras: GHSA-x4wf-678h-2pmq", "shortDescription": {"text": "keras: GHSA-x4wf-678h-2pmq"}, "fullDescription": {"text": "Keras code injection vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fcw5-x6j4-ccmp", "name": "jupyter-server: GHSA-fcw5-x6j4-ccmp", "shortDescription": {"text": "jupyter-server: GHSA-fcw5-x6j4-ccmp"}, "fullDescription": {"text": "Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vqfr-h8mv-ghfj", "name": "h11: GHSA-vqfr-h8mv-ghfj", "shortDescription": {"text": "h11: GHSA-vqfr-h8mv-ghfj"}, "fullDescription": {"text": "h11 accepts some malformed Chunked-Encoding bodies"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "MINED107", "name": "Missing import: `stat` used but not imported", "shortDescription": {"text": "Missing import: `stat` used but not imported"}, "fullDescription": {"text": "The file uses `stat.something(...)` but never imports `stat`. This raises NameError at runtime the first time the line executes."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "critical", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "scanner-7df3594de8cc900b", "name": "Possibly dead Python function: train_step", "shortDescription": {"text": "Possibly dead Python function: train_step"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da72af9cd4033f74", "name": "Possibly dead Python function: eval_step", "shortDescription": {"text": "Possibly dead Python function: eval_step"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f36d94d2d16c6e2", "name": "Possibly dead Python function: load_adapter_checkpoint", "shortDescription": {"text": "Possibly dead Python function: load_adapter_checkpoint"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b71aa8cd115d609", "name": "Possibly dead Python function: setup_process", "shortDescription": {"text": "Possibly dead Python function: setup_process"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0ef42c9e7fb53dd", "name": "Possibly dead Python function: shift_row", "shortDescription": {"text": "Possibly dead Python function: shift_row"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87aef4dd05079e9e", "name": "Possibly dead Python function: compute_predictions", "shortDescription": {"text": "Possibly dead Python function: compute_predictions"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c107af86428755e", "name": "Possibly dead Python function: compute_loss", "shortDescription": {"text": "Possibly dead Python function: compute_loss"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-222b152ee4f5c376", "name": "Possibly dead Python function: forecast_with_covariates", "shortDescription": {"text": "Possibly dead Python function: forecast_with_covariates"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76e094a098db4ad8", "name": "Possibly dead Python function: apply_mask_to_logits", "shortDescription": {"text": "Possibly dead Python function: apply_mask_to_logits"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28fce836053b755c", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50ef2a48425110cf", "name": "Possibly dead Python function: cross_validation", "shortDescription": {"text": "Possibly dead Python function: cross_validation"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7aaf64cc1e22ba12", "name": "Possibly dead Python function: parallel_transform", "shortDescription": {"text": "Possibly dead Python function: parallel_transform"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d681765b1cb937e7", "name": "Possibly dead Python function: save_results", "shortDescription": {"text": "Possibly dead Python function: save_results"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-088e7eb6f1ddea80", "name": "Possibly dead Python function: evaluate_models", "shortDescription": {"text": "Possibly dead Python function: evaluate_models"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e34785475171e0c7", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56f770233f5053c8", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a26ac96ee385c857", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26f453677d5dd3ec", "name": "Possibly dead Python function: scan_along_axis", "shortDescription": {"text": "Possibly dead Python function: scan_along_axis"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5232df71255e1f87", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42986388389a64a3", "name": "Possibly dead Python function: forecast_with_covariates", "shortDescription": {"text": "Possibly dead Python function: forecast_with_covariates"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fb8c38d0921783a", "name": "eval detected \u2014 v1/experiments/long_horizon_benchmarks/run_eval.py:238", "shortDescription": {"text": "eval detected \u2014 v1/experiments/long_horizon_benchmarks/run_eval.py:238"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff1c2606dbebc21d", "name": "CVE-2025-68146: filelock 3.19.1 \u2014 requirements.txt", "shortDescription": {"text": "CVE-2025-68146: filelock 3.19.1 \u2014 requirements.txt"}, "fullDescription": {"text": "filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation\n\nfilelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow\n\nPackage: filelock\nInstalled: 3.19.1\nFixed in: 3.20.1\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2eba7a0e1868876e", "name": "CVE-2026-22701: filelock 3.19.1 \u2014 requirements.txt", "shortDescription": {"text": "CVE-2026-22701: filelock 3.19.1 \u2014 requirements.txt"}, "fullDescription": {"text": "filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock\n\nfilelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission c\n\nPackage: filelock\nInstalled: 3.19.1\nFixed in: 3.20.3\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc35d3a43c2ac75c", "name": "CVE-2026-45409: idna 3.10 \u2014 requirements.txt", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 requirements.txt"}, "fullDescription": {"text": "Internationalized Domain Names in Applications (IDNA) for Python provi ...\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec730f875f7d02a5", "name": "GHSA-gj48-438w-jh9v: bleach 6.2.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-gj48-438w-jh9v: bleach 6.2.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes\n\n### Summary\n\nBleach `clean()` / `Cleaner()` fails to sanitize dangerous URI schemes in allowed `formaction` attributes.\n\nBleach applies URI protocol sanitization only to attributes listed in `attr_val_is_uri`. While URI-bearing attributes such as `action`, `href`, `src`, and `poster` are included in that set, `formaction` is not. As a result, if a downstream application explicitly allows `formaction` on submit-capable controls in untrusted HTML, Bleach preserves dangerous values such as `javascr\n\nPackage: bleach\nInstalled: 6.2.0\nFixed in: 6.4.0\nSeverity: MEDIUM\nFix: Upgrade bleach to 6.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d6a08778003f95c2", "name": "GHSA-8rfp-98v4-mmr6: bleach 6.2.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-8rfp-98v4-mmr6: bleach 6.2.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output\n\n### Impact\n\nA possible XSS bypass affects users calling `bleach.clean` with all of:\n\n* `a` in the allowed tags\n* `href` in allowed attributes\n\nThe `bleach.clean` sanitizer outputs URIs containing disallowed scheme patterns that it should be stripping. However, because the inserted Unicode characters make the scheme invalid per RFC 3986, modern browsers do not execute these as javascript: URIs. The practical security impact is limited to:\n\n- Bleach's output contains URI values that violate the ca\n\nPackage: bleach\nInstalled: 6.2.0\nFixed in: 6.4.0\nSeverity: LOW\nFix: Upgrade bleach to 6.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b80ca85e5888f65", "name": "CVE-2025-68146: filelock 3.16.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-68146: filelock 3.16.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation\n\nfilelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow\n\nPackage: filelock\nInstalled: 3.16.1\nFixed in: 3.20.1\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dddf5504846ce23a", "name": "CVE-2026-22701: filelock 3.16.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-22701: filelock 3.16.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock\n\nfilelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission c\n\nPackage: filelock\nInstalled: 3.16.1\nFixed in: 3.20.3\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d43142ff27679603", "name": "CVE-2025-66034: fonttools 4.55.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-66034: fonttools 4.55.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file\n\nfontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a malicious .designspace file is processed. The vulnerability affects the main() code path of fontTools.varLib, used by the fonttools varLib CLI and any code that invokes fontTools.varLib.main(). This issue has been patched in version 4.60.2.\n\nPackage: fonttools\nInstalled: 4.55.3\nFixed in: 4.60.2\nSeverity: MEDIUM\nFix: Upgrade fonttools to 4.60.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-110d9d4104433a53", "name": "CVE-2026-42215: gitpython 3.1.43 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42215: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at it\n\nPackage: gitpython\nInstalled: 3.1.43\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e8c1c3d8301bd06", "name": "CVE-2026-42284: gitpython 3.1.43 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42284: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(\" \".join(multi_options)). A string like \"--branch main --config core.hooksPath=/x\" passes validation (starts with --branch), but after split becomes [\"--branch\", \"main\", \"--config\", \"core.hooksPath=/x\"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.\n\nPackage: gitpython\nInstalled: 3.1.43\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a26e4272c4f25f6e", "name": "CVE-2026-44243: gitpython 3.1.43 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44243: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository\u2019s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.\n\nPackage: gitpython\nInstalled: 3.1.43\nFixed in: 3.1.48\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.48"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f98b3a1e68232c1", "name": "CVE-2026-44244: gitpython 3.1.43 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44244: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \\n becomes \\n\\t), but Git still accepts an indented [core] stanza as a section header \u2014 so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout)\n\nPackage: gitpython\nInstalled: 3.1.43\nFixed in: 3.1.49\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.49"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ff355d8c032d630", "name": "GHSA-mv93-w799-cj2w: gitpython 3.1.43 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath\n\nSummary\n\nThe patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \\n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.\n\nDetails\n\nFile: git/config.py \u2014 \n\nPackage: gitpython\nInstalled: 3.1.43\nFixed in: 3.1.50\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.50"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0538493fd71233f5", "name": "CVE-2025-43859: h11 0.14.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "h11: h11 accepts some malformed Chunked-Encoding bodies\n\nh11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.\n\nPackage: h11\nInstalled: 0.14.0\nFixed in: 0.16.0\nSeverity: CRITICAL\nFix: Upgrade h11 to 0.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-42c9109efc772f64", "name": "CVE-2026-45409: idna 3.10 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Internationalized Domain Names in Applications (IDNA) for Python provi ...\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eae311993e2633b5", "name": "CVE-2025-27516: jinja2 3.1.5 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-27516: jinja2 3.1.5 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jinja2: Jinja sandbox breakout through attr filter selecting format method\n\nJinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates. Jinja's sandbox does c\n\nPackage: jinja2\nInstalled: 3.1.5\nFixed in: 3.1.6\nSeverity: MEDIUM\nFix: Upgrade jinja2 to 3.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-39b281082204636e", "name": "CVE-2025-30167: jupyter-core 5.7.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-30167: jupyter-core 5.7.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability\n\nJupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to recei\n\nPackage: jupyter-core\nInstalled: 5.7.2\nFixed in: 5.8.1\nSeverity: HIGH\nFix: Upgrade jupyter-core to 5.8.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cf1bdc96861f491", "name": "CVE-2026-44727: jupyter-server 2.15.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44727: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP \n\nThe nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their `Content-Security-Policy`. \n\nCombined with `nbconvert.HTMLExporter`'s default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE.\n\n### Impact\n\nAn authenticated victim who navigates to `/nbconvert/html/<path>` containing attacker-authored output\n\nPackage: jupyter-server\nInstalled: 2.15.0\nFixed in: 2.20.0\nSeverity: CRITICAL\nFix: Upgrade jupyter-server to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-3a5ac536b350e96d", "name": "CVE-2026-35397: jupyter-server 2.15.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-35397: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Jupyter Server is the backend for Jupyter web applications. In version ...\n\nJupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named \"test\", the API permits access to a sibling directory named \"testtest\" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can re\n\nPackage: jupyter-server\nInstalled: 2.15.0\nFixed in: 2.18.0\nSeverity: HIGH\nFix: Upgrade jupyter-server to 2.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cd0984c5897a9d58", "name": "CVE-2026-40110: jupyter-server 2.15.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-40110: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation\n\nJupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.e\n\nPackage: jupyter-server\nInstalled: 2.15.0\nFixed in: 2.18.0\nSeverity: HIGH\nFix: Upgrade jupyter-server to 2.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a096a062b809bba0", "name": "CVE-2026-40934: jupyter-server 2.15.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-40934: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyter-server: Jupyter Server: Authentication bypass due to unrotated cookie secret\n\nJupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any \n\nPackage: jupyter-server\nInstalled: 2.15.0\nFixed in: 2.18.0\nSeverity: HIGH\nFix: Upgrade jupyter-server to 2.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e7f7b69fcb20d34", "name": "CVE-2025-61669: jupyter-server 2.15.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-61669: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyter_server: Jupyter Server: Redirects to arbitrary external domains via insufficient validation of login parameter\n\nJupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.\n\nPackage: jupyter-server\nInstalled: 2.15.0\nFixed in: 2.18.0\nSeverity: MEDIUM\nFix: Upgrade jupyter-server to 2.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e77611419a94e88e", "name": "CVE-2026-40171: jupyterlab 4.3.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-40171: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions  ...\n\nIn Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate contr\n\nPackage: jupyterlab\nInstalled: 4.3.4\nFixed in: 4.5.7\nSeverity: HIGH\nFix: Upgrade jupyterlab to 4.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4691a31a042b9d67", "name": "CVE-2026-42266: jupyterlab 4.3.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42266: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "JupyterLab is an extensible environment for interactive and reproducib ...\n\nJupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.\n\nPackage: jupyterlab\nInstalled: 4.3.4\nFixed in: 4.5.7\nSeverity: HIGH\nFix: Upgrade jupyterlab to 4.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e72c86118dd080d4", "name": "CVE-2026-42557: jupyterlab 4.3.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42557: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output\n\njupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button \n\nPackage: jupyterlab\nInstalled: 4.3.4\nFixed in: 4.5.7\nSeverity: HIGH\nFix: Upgrade jupyterlab to 4.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f5951d4ddaa8ac3", "name": "GHSA-vmhf-c436-hxj4: jupyterlab 4.3.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-vmhf-c436-hxj4: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol\n\nA malicious PyPI package can place a `javascript:` URL in its `[project.urls]` metadata. JupyterLab's Extension Manager renders this as the extension's home-page link without validating the protocol, so a user who clicks the extension name executes attacker-controlled JavaScript in the JupyterLab origin.\n\n### Details\n\nOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the `homepage_url` rendered by the frontend in packages/extensionmanager/src/widget.tsx#L77-L8\n\nPackage: jupyterlab\nInstalled: 4.3.4\nFixed in: 4.5.9\nSeverity: MEDIUM\nFix: Upgrade jupyterlab to 4.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c14de822a03e7086", "name": "CVE-2025-59842: jupyterlab 4.3.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-59842: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyterlab: JupyterLab LaTeX typesetter links did not enforce `noopener` attribute\n\njupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the noopener attribute. This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if links \n\nPackage: jupyterlab\nInstalled: 4.3.4\nFixed in: 4.4.8\nSeverity: LOW\nFix: Upgrade jupyterlab to 4.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15a602c47cf46236", "name": "CVE-2024-3660: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-3660: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A arbitrary code injection vulnerability in TensorFlow's Keras framewo ...\n\nA arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.\n\nPackage: keras\nInstalled: 2.9.0\nFixed in: 2.13.1rc0\nSeverity: CRITICAL\nFix: Upgrade keras to 2.13.1rc0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-fad1d165e8847b13", "name": "CVE-2025-12060: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-12060: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "keras: Keras Path Traversal Vulnerability\n\nThe keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter=\"data\" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python \n\nPackage: keras\nInstalled: 2.9.0\nFixed in: 3.12.0\nSeverity: HIGH\nFix: Upgrade keras to 3.12.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-31f8995083b20304", "name": "CVE-2025-9906: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-9906: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "keras: Arbitrary Code execution in Keras Safe Mode\n\nThe Keras Model.load_model\u00a0method can be exploited to achieve arbitrary code execution, even with safe_mode=True.\n\nOne can create a specially crafted .keras\u00a0model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved by crafting a special config.json\u00a0(a file within the .keras\u00a0archive) that will invoke keras.config.enable_unsafe_deserialization()\u00a0to disable safe mode. Once safe mode is disable, one can use the Lambda\u00a0layer feature of keras, w\n\nPackage: keras\nInstalled: 2.9.0\nFixed in: 3.11.0\nSeverity: HIGH\nFix: Upgrade keras to 3.11.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-475114b64805007d", "name": "CVE-2026-1462: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-1462: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode\n\nA vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file path\n\nPackage: keras\nInstalled: 2.9.0\nFixed in: 3.13.2\nSeverity: HIGH\nFix: Upgrade keras to 3.13.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26d67a8d91e266a4", "name": "CVE-2024-55459: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-55459: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "keras: arbitrary file write via get_file function\n\nAn issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.\n\nPackage: keras\nInstalled: 2.9.0\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-386a65c7092e6ab9", "name": "CVE-2025-12058: keras 2.9.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-12058: keras 2.9.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "keras: Keras Model.load_model Arbitrary Local File Loading and SSRF\n\nThe Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF).\n\n\nThis vulnerability stems from the way the StringLookup layer is handled during model loading from a specially crafted .keras archive. The constructor for the StringLookup layer accepts a vocabulary argument that can specify a local file path or a remote file path.\n\n  *  Arbitrary Local File Read: A\n\nPackage: keras\nInstalled: 2.9.0\nFixed in: 3.12.0\nSeverity: MEDIUM\nFix: Upgrade keras to 3.12.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58876f81eea9da01", "name": "CVE-2026-41066: lxml 5.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-41066: lxml 5.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read\n\nlxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.\n\nPackage: lxml\nInstalled: 5.3.0\nFixed in: 6.1.0\nSeverity: HIGH\nFix: Upgrade lxml to 6.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a9ea17a5bad8514", "name": "CVE-2025-69534: markdown 3.7 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-69534: markdown 3.7 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "python-markdown: denial of service via malformed HTML-like sequences\n\nPython-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged\n\nPackage: markdown\nInstalled: 3.7\nFixed in: 3.8.1\nSeverity: MEDIUM\nFix: Upgrade markdown to 3.8.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8834e404efb654a", "name": "CVE-2026-33079: mistune 3.1.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-33079: mistune 3.1.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input\n\nIn versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastrophic backtracking. In both the double-quoted and single-quoted branches, a backslash followed by punctuation can be matched either as an escaped punctuation sequence \n\nPackage: mistune\nInstalled: 3.1.0\nFixed in: 3.2.1\nSeverity: HIGH\nFix: Upgrade mistune to 3.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6eaa415d738eb898", "name": "CVE-2026-44708: mistune 3.1.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44708: mistune 3.1.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "python-mistune: Mistune: Cross-Site Scripting via improper HTML escaping in math plugin\n\nMistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied content directly into the HTML output without any HTML escaping. This occurs even when the parser is explicitly created with escape=True, which is supposed to guarantee that all user-controlled text is sanitised before reaching the DOM. This vulnerability is fixed in 3.2.1.\n\nPackage: mistune\nInstalled: 3.1.0\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2f61bafae433dac", "name": "CVE-2026-44896: mistune 3.1.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44896: mistune 3.1.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Mistune is a Python Markdown parser with renderers and plugins. In 3.2 ...\n\nMistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.\n\nPackage: mistune\nInstalled: 3.1.0\nFixed in: 3.2.1\nSeverity: MEDIUM\nFix: Upgrade mistune to 3.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd4be3e8e9b87b37", "name": "CVE-2026-44897: mistune 3.1.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44897: mistune 3.1.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "mistune: Mistune: Cross-site scripting (XSS) via improper sanitization of HTML heading ID attribute\n\nMistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTML \u2014 with no call to escape(), safe_entity(), or any other sanitisation function. A double-quote character \" in the id value terminates the attribute, allowing an attacker to inject arbitrary additional attributes (event handlers, src=, href=, etc.) into the heading element. This vulnerability is fixe\n\nPackage: mistune\nInstalled: 3.1.0\nFixed in: 3.2.1\nSeverity: MEDIUM\nFix: Upgrade mistune to 3.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4edb95a2c0a7b5e", "name": "CVE-2025-53000: nbconvert 7.16.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-53000: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nbconvert: nbconvert: Arbitrary code execution via malicious SVG to PDF conversion on Windows\n\nThe nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and including 7.16.6 on Windows have a vulnerability in which converting a notebook containing SVG output to a PDF results in unauthorized code execution. Specifically, a third party can create a `inkscape.bat` file that defines a Windows batch script, capable of arbitrary code execution. When a user runs `jupyter nbconvert --to pdf` on a notebook containing\n\nPackage: nbconvert\nInstalled: 7.16.4\nFixed in: 7.17.0\nSeverity: HIGH\nFix: Upgrade nbconvert to 7.17.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2542516ebc45e1ef", "name": "CVE-2026-39377: nbconvert 7.16.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-39377: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nbconvert: nbconvert: Arbitrary file write via crafted Jupyter notebook cell attachment filenames\n\nThe nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `ExtractAttachmentsPreprocessor` passes attachment filenames directly to the filesystem without sanitization, enabling path traversal attacks. This vulnerability provides complete control over both the des\n\nPackage: nbconvert\nInstalled: 7.16.4\nFixed in: 7.17.1\nSeverity: MEDIUM\nFix: Upgrade nbconvert to 7.17.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d5d6f0b75f2a5da", "name": "CVE-2026-39378: nbconvert 7.16.4 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-39378: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nbconvert: nbconvert: Sensitive file exfiltration via path traversal in image references\n\nThe nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML. nbconvert 7.17.1 contains a fix. As a workaround, do not enable `HTMLExporter.embed_i\n\nPackage: nbconvert\nInstalled: 7.16.4\nFixed in: 7.17.1\nSeverity: MEDIUM\nFix: Upgrade nbconvert to 7.17.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b0b10871bf6a0e8", "name": "CVE-2025-14009: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-14009: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: Zip Slip Vulnerability in nltk Leading to Code Execution\n\nA critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip packages that, when downloaded and extracted by NLTK, can execute arbitrary code. The vulnerability arises because NLTK assumes all downloaded packages are trusted and extracts them without validation. If a malicious package\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.3\nSeverity: CRITICAL\nFix: Upgrade nltk to 3.9.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-0eb8755aaadd6ef6", "name": "CVE-2026-0846: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-0846: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function\n\nA vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept u\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.3\nSeverity: HIGH\nFix: Upgrade nltk to 3.9.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-988004a24fc6bff6", "name": "CVE-2026-0847: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-0847: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file read via path traversal vulnerability\n\nA vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly critical in scenarios where user-controlled file inputs are processed, such as in machine learning APIs\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce123a1ee8d502c9", "name": "CVE-2026-33231: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-33231: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: NLTK: Denial of Service via unauthenticated remote shutdown\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.4\nSeverity: HIGH\nFix: Upgrade nltk to 3.9.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ea2396f55f31f22", "name": "CVE-2026-33236: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-33236: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processing remote XML index files. Attackers can control a remote XML index server to provide malicious values containing path traversal sequences (such as `../`), which can lead to arbitrary directory creation, arbitrary file c\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-848bfd84523185c0", "name": "CVE-2026-54293: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-54293: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read\n\n### Summary\nnltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments when using the nltk: URL scheme. The unsafe-path regex check is performed before url2pathname() decodes the %xx sequences (a classic decode-after-check / TOCTOU-style flaw), allowing an attacker to bypass the protection documented in NLTK's SECURITY.md and read arbitrary files from the filesystem.\nWhile literal traversal strings such as ../../../etc/passwd are correctly blo\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f67e17cbebf1ead4", "name": "CVE-2026-33230: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-33230: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "nltk: NLTK: Script execution via reflected cross-site scripting in WordNet Browser\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A crafted `lookup_<payload>` URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled `word` data is reflected into HTML without escaping. This impacts users running the l\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.4\nSeverity: MEDIUM\nFix: Upgrade nltk to 3.9.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0fac83d0f315b0b8", "name": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS\n\n### Summary\n`JSONTaggedDecoder.decode_obj()` in `nltk/jsontags.py` calls itself \nrecursively without any depth limit. A deeply nested JSON structure \nexceeding `sys.getrecursionlimit()` (default: 1000) will raise an \nunhandled `RecursionError`, crashing the Python process.\n\n### Affected code\nFile: `nltk/jsontags.py`, lines 47\u201352\n```python\n@classmethod\ndef decode_obj(cls, obj):\n    if isinstance(obj, dict):\n        obj = {key: cls.decode_obj(val) for (key, val) in obj.items()}\n    elif isinstance\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dddabd5dff039808", "name": "CVE-2026-40171: notebook 7.3.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-40171: notebook 7.3.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions  ...\n\nIn Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate contr\n\nPackage: notebook\nInstalled: 7.3.2\nFixed in: 7.5.6\nSeverity: HIGH\nFix: Upgrade notebook to 7.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-418e7d85afe72da3", "name": "CVE-2026-42557: notebook 7.3.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42557: notebook 7.3.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output\n\njupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button \n\nPackage: notebook\nInstalled: 7.3.2\nFixed in: 7.5.6\nSeverity: HIGH\nFix: Upgrade notebook to 7.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b9e912733651081", "name": "CVE-2026-25990: pillow 11.0.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-25990: pillow 11.0.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 11.0.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af8638507e384106", "name": "CVE-2026-40192: pillow 11.0.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-40192: pillow 11.0.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-824e18a949761323", "name": "CVE-2026-42311: pillow 11.0.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42311: pillow 11.0.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Pillow is a Python imaging library. From version 10.3.0 to before vers ...\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a14591c92827a925", "name": "CVE-2026-42308: pillow 11.0.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42308: pillow 11.0.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31cb5400987a41e5", "name": "CVE-2026-42310: pillow 11.0.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-42310: pillow 11.0.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5427e02aadb98844", "name": "CVE-2025-4565: protobuf 3.19.6 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-4565: protobuf 3.19.6 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "python-protobuf: Unbounded recursion in Python Protobuf\n\nAny project that uses Protobuf Pure-Python backend\u00a0to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP\u00a0tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit\u00a017838beda2943d08b8a9d4df5b68f5f04f26d901\n\nPackage: protobuf\nInstalled: 3.19.6\nFixed in: 4.25.8, 5.29.5, 6.31.1\nSeverity: HIGH\nFix: Upgrade protobuf to 4.25.8, 5.29.5, 6.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aeb578abb70e4e74", "name": "CVE-2026-0994: protobuf 3.19.6 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-0994: protobuf 3.19.6 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "python: protobuf: Protobuf: Denial of Service due to recursion depth bypass\n\nA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python\u2019s recursion stack and causing a RecursionError.\n\nPackage: protobuf\nInstalled: 3.19.6\nFixed in: 6.33.5, 5.29.6\nSeverity: HIGH\nFix: Upgrade protobuf to 6.33.5, 5.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bb1a9065faf94332", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3932dd3e079edadb", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7a52be80d54ce216", "name": "CVE-2026-4539: pygments 2.18.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-4539: pygments 2.18.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.18.0\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dfba8434ad46938", "name": "CVE-2024-47081: requests 2.32.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31d3ec140e04bcf0", "name": "CVE-2026-25645: requests 2.32.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30606b52a1e4127f", "name": "CVE-2026-1260: sentencepiece 0.1.99 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-1260: sentencepiece 0.1.99 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "sentencepiece: Sentencepiece: Invalid memory access leading to potential arbitrary code execution via a crafted model file.\n\nInvalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.\n\nPackage: sentencepiece\nInstalled: 0.1.99\nFixed in: 0.2.1\nSeverity: HIGH\nFix: Upgrade sentencepiece to 0.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f2442c63b95ed8b3", "name": "CVE-2025-47273: setuptools 75.6.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-47273: setuptools 75.6.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.\n\nPackage: setuptools\nInstalled: 75.6.0\nFixed in: 78.1.1\nSeverity: HIGH\nFix: Upgrade setuptools to 78.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-543b78eb467b16da", "name": "CVE-2023-25668: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25668: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: CRITICAL\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-d0aa1cc52b3e9ef2", "name": "CVE-2023-25658: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25658: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-730bc7eab7e7bf8a", "name": "CVE-2023-25659: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25659: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-17f78c000b28a32d", "name": "CVE-2023-25660: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25660: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A fix is included in TensorFlow version 2.12 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e08c1be2c27386ad", "name": "CVE-2023-25662: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25662: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25662 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1577115ba886234f", "name": "CVE-2023-25663: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25663: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28bc439177f9e5d0", "name": "CVE-2023-25664: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25664: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf714390d1c3fa0e", "name": "CVE-2023-25665: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25665: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25665 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaximum` is given invalid sparse tensors as inputs, it can give a null pointer error. A fix is included in TensorFlow version 2.12 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c961e7448b46903", "name": "CVE-2023-25666: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25666: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d866a51890a86c02", "name": "CVE-2023-25669: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25669: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25669 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6086cc1d48ecdd09", "name": "CVE-2023-25670: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25670: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-206e917c776795fa", "name": "CVE-2023-25671: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25671: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c71d95778961e6b1", "name": "CVE-2023-25672: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25672: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25672 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c04675bbe3852498", "name": "CVE-2023-25673: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25673: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cde483787af19d92", "name": "CVE-2023-25674: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25674: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e86d3e1df75db6ad", "name": "CVE-2023-25675: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25675: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25675 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eaf32f0b4b0ee169", "name": "CVE-2023-25676: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25676: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25676 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. A fix is available in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6dbd94aad0e78da9", "name": "CVE-2023-25801: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25801: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A fix is included in TensorFlow 2.12.0 and 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ddfb59e680931c75", "name": "CVE-2023-27579: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-27579: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix commit on TensorFlow 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-caf34f269203821f", "name": "CVE-2023-33976: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-33976: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-33976 affecting package tensorflow for versions less than 2.11.1-2\n\nTensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.12.1\nSeverity: HIGH\nFix: Upgrade tensorflow to 2.12.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58286366d26b6fac", "name": "CVE-2023-25661: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25661: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25661 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with the `Convolution3DTranspose` function. This Convolution3DTranspose layer is a very common API in modern neural networks. The ML models containing such vulnerable components could be deployed in ML applications or as cloud services. This failure coul\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: MEDIUM\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b94fb4132b8b2f16", "name": "CVE-2023-25667: tensorflow 2.9.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2023-25667: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "CVE-2023-25667 affecting package tensorflow for versions less than 2.11.1-1\n\nTensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at least 346 frames. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.\n\nPackage: tensorflow\nInstalled: 2.9.3\nFixed in: 2.11.1\nSeverity: MEDIUM\nFix: Upgrade tensorflow to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da709aa9160d6bde", "name": "CVE-2025-32434: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-32434: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "PyTorch is a Python package that provides tensor computation with stro ...\n\nPyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: 2.6.0\nSeverity: CRITICAL\nFix: Upgrade torch to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-8b8b48cbe5104e30", "name": "CVE-2025-2998: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2998: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been declared as cr ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5aacaec15ecec758", "name": "CVE-2025-2999: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2999: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: 2.9.1\nSeverity: MEDIUM\nFix: Upgrade torch to 2.9.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73ec09856b52eba4", "name": "CVE-2025-3730: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3730: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability, which was classified as problematic, was found in PyT ...\n\nA vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a pa\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: 2.8.0\nSeverity: MEDIUM\nFix: Upgrade torch to 2.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed5d9f970373af2a", "name": "CVE-2025-2148: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2148: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared ...\n\nA vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-742d4f0a9f3dfd0f", "name": "CVE-2025-2149: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2149: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as ...\n\nA vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d22bcd8582937b9d", "name": "CVE-2025-2953: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2953: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "torch: PyTorch torch.mkldnn_max_pool2d denial of service\n\nA vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: 2.7.1-rc1\nSeverity: LOW\nFix: Upgrade torch to 2.7.1-rc1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0941d8c03bb1d46b", "name": "CVE-2025-3000: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3000: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90674d052e5bb5e2", "name": "CVE-2025-3001: torch 2.3.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3001: torch 2.3.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...\n\nA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.3.1\nFixed in: 2.10.0\nSeverity: LOW\nFix: Upgrade torch to 2.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f88456f9af31cecd", "name": "CVE-2025-47287: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-47287: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "tornado: Tornado Multipart Form-Data Denial of Service\n\nTornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upg\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02ea0143580dc3ab", "name": "CVE-2026-31958: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-31958: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "tornado-python: Tornado: Denial of Service via large multipart bodies\n\nTornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-44f01b6437162c3f", "name": "CVE-2026-35536: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-35536: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments\n\nIn Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c532cd21270d66c", "name": "CVE-2026-49853: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-49853: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient\n\n## Summary\n\nWhen SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.\n\nAs a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.\n\nBeginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matche\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e96f81f98b196e9", "name": "CVE-2026-49855: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-49855: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)\n\nTornado's gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.\n\nThis bug is\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a94dce111c0aea0", "name": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Tornado has incomplete validation of cookie attributes\n\nValues passed to the `domain`, `path`, and `samesite` arguments of `RequestHandler.set_cookie` were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: MEDIUM\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3bf19a2942f3229e", "name": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse\n\n# CurlAsyncHTTPClient leaks per-request credentials on handle reuse\n\n## Summary\n\n`CurlAsyncHTTPClient` pools and reuses `pycurl` handles across requests but does\nnot reset them between requests, and several per-request options are applied with\nno clearing branch. As a result, sensitive state set by one request persists onto\na later request on the same client that does not set it. Two credential vectors\nare demonstrated below \u2014 a client TLS certificate (`SSLCERT`/`SSLKEY`) and proxy\nbasic-auth cr\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.7\nSeverity: MEDIUM\nFix: Upgrade tornado to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c431028d08ffaee0", "name": "CVE-2026-49854: tornado 6.4.2 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-49854: tornado 6.4.2 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Tornado has out-of-bounds memory access via C extension\n\n### Summary\n\nTornado's optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.\n\nThe behavior is reachable from Tornado's XSRF token decoder when `xsrf_cookies=True` and the native extension is active. \n\n### Mitiga\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: LOW\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b1f7a1bbe2b0eb8", "name": "CVE-2024-11392: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-11392: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-sup\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-459135fdc7f50e4e", "name": "CVE-2024-11393: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-11393: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplie\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-679ba6436192b8b9", "name": "CVE-2024-11394: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-11394: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied dat\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4232853603e9648c", "name": "CVE-2024-12720: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2024-12720: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from the regex exhibiting exponential time complexity under certain conditions, leading to excessive backtracking. This can result in significantly high CPU usage and potential applicatio\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.48.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3240e2f1f3e4d625", "name": "CVE-2025-1194: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-1194: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and pote\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.50.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.50.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3397c275d7da3f88", "name": "CVE-2025-2099: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-2099: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and \n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.50.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.50.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40c7857468b6d416", "name": "CVE-2025-3263: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3263: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is resolved in version 4.51.0. The vulnerability arises from the use of a regular expression pattern `config\\.(.*)\\.json` that can be exploited to cause excessive CPU consumption through crafted input strings, leading to catas\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.51.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.51.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-063cb0fa9a6e6eb0", "name": "CVE-2025-3264: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3264: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression pattern `\\s*try\\s*:.*?except.*?:` used to filter out try/except blocks from Python code, which can be exploited to cause excessive CPU consumption through crafted input strings due to c\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.51.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.51.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-546ae18803e49fa8", "name": "CVE-2025-3933: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3933: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern `<s_(.*?)>` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption,\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.52.1\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eef4258f32f9ab96", "name": "CVE-2025-5197: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-5197: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Transformers ReDoS Vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. The vulnerability affects versions up to 4.51.3 and is fixed in vers\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e86bc73a6a385634", "name": "CVE-2025-6051: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-6051: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impac\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d303fe7171b8df3d", "name": "CVE-2025-6638: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-6638: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ca37ed0f50ed76f", "name": "CVE-2025-6921: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-6921: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nThe huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and exclude_from_weight_decay lists. Malicious regular expressions can cause catastrophic backtracking during the re.search call, leading to 100% CPU utilization and a denial of service. This is\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38dd4012c4153154", "name": "CVE-2026-1839: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-1839: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file\n\nA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 5.0.0rc3\nSeverity: MEDIUM\nFix: Upgrade transformers to 5.0.0rc3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b798d6c660b03c3", "name": "CVE-2025-3777: transformers 4.47.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-3777: transformers 4.47.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "transformers: Improper Input Validation in huggingface/transformers\n\nHugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1\n\nPackage: transformers\nInstalled: 4.47.1\nFixed in: 4.52.1\nSeverity: LOW\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eaed1713eaec6942", "name": "CVE-2025-66418: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-658f35537a56e3a0", "name": "CVE-2025-66471: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ecb04b67a2b4e25", "name": "CVE-2026-21441: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78fc6f96fe07ffa9", "name": "CVE-2026-44431: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b800bf06ea74cca", "name": "CVE-2025-50181: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-50181: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation\n\nurllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09c73185fc35d0b7", "name": "CVE-2025-50182: urllib3 2.3.0 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-50182: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "urllib3: urllib3 does not control redirects in browsers and Node.js\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodi\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1daa02b05bbbd04", "name": "CVE-2025-66221: werkzeug 3.1.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2025-66221: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "Werkzeug: Werkzeug: Denial of service via Windows device names in path segments\n\nWerkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.4\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f205368149e3b947", "name": "CVE-2026-21860: werkzeug 3.1.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-21860: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names with compound extensions\n\nWerkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.5\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94c4b16c2f37b84e", "name": "CVE-2026-27199: werkzeug 3.1.3 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-27199: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names\n\nWerkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported as GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact that safe_join accepts paths with multiple segments, such as example/NUL. The function send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.6\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19a7e502337d9cee", "name": "CVE-2026-24049: wheel 0.45.1 \u2014 v1/poetry.lock", "shortDescription": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 v1/poetry.lock"}, "fullDescription": {"text": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking\n\nwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of c\n\nPackage: wheel\nInstalled: 0.45.1\nFixed in: 0.46.2\nSeverity: HIGH\nFix: Upgrade wheel to 0.46.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb72c7ff8619c129", "name": "SkillSpector AST3 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py", "shortDescription": {"text": "SkillSpector AST3 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py"}, "fullDescription": {"text": "mod = __import__(import_name)\n\nDynamic __import__() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.\n\nSkill: timesfm-forecasting\nRule: AST3  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use standard import statements instead of __import__(). If dynamic loading is needed, use importlib with an allowlist of permitted modules."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-4bd828193dddb420", "name": "SkillSpector AST4 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py"}, "fullDescription": {"text": "result = subprocess.run(\n                [\"sysctl\", \"-n\", \"hw.memsize\"],\n                capture_output=True,\n                text=True,\n                check=True,\n            )\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: timesfm-forecasting\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-c933cc54cd6d3611", "name": "SkillSpector LP3 (mcp-least-priv) in timesfm-forecasting/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in timesfm-forecasting/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: timesfm-forecasting\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e8473e5186e0dbdf", "name": "SkillSpector EA4 (excessive-agency) in timesfm-forecasting/examples/global-temperature/generate_gif.py", "shortDescription": {"text": "SkillSpector EA4 (excessive-agency) in timesfm-forecasting/examples/global-temperature/generate_gif.py"}, "fullDescription": {"text": "Loop forever\n\nSkill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.\n\nSkill: timesfm-forecasting\nRule: EA4  Category: excessive-agency\nSeverity: MEDIUM  Confidence: 0.75\n\nRemediation: Set explicit rate limits, timeouts, and resource quotas for API calls, file operations, and compute. Implement circuit breakers for runaway loops."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-a73c6fc796a6b2cf", "name": "SkillSpector OH1 (output-handling) in timesfm-forecasting/scripts/check_system.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in timesfm-forecasting/scripts/check_system.py"}, "fullDescription": {"text": "subprocess.run(\n                [\"sysctl\", \"-n\", \"hw.memsize\"],\n                capture_output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: timesfm-forecasting\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-e92e28bc852e45e5", "name": "SkillSpector SC6 (supply-chain) in timesfm-forecasting/references/system_requirements.md", "shortDescription": {"text": "SkillSpector SC6 (supply-chain) in timesfm-forecasting/references/system_requirements.md"}, "fullDescription": {"text": "import\n\nPackage name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.\n\nSkill: timesfm-forecasting\nRule: SC6  Category: supply-chain\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-a943cdefbb0a95ff", "name": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/anomaly-detection/output/anomaly_detection.png", "shortDescription": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/anomaly-detection/output/anomaly_detection.png"}, "fullDescription": {"text": "rM\\0\\0\\0\\0\\0\\0\\0\u0014FFF\ufffd>\ufffd\ufffd\u0013\ufffd\ufffd\ufffd\ufffd\ufffd=\ufffd\ufffd\u0003\\0\ufffd\ufffd\ufffdf\\+\u000b\ufffd\ufffd\ufffd-\ufffd\ufffd\ufffd\ufffdP\ufffd\ufffd\u0019\ufffd\u007f\\0\\0\\0\\0\\0\\0\\0(Ev\ufffd]\u02d7/\n\nTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).\n\nSkill: timesfm-forecasting\nRule: TM1  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-893abace1e43f248", "name": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png", "shortDescription": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "fullDescription": {"text": "rM\ufffd\ufffd\ufffd\ufffd\ufffd\ufffds\ufffd\ufffd\u0010\ufffd\ufffd\ufffd\ufffd\ufffd}\ufffd\ufffd\u0017X\ufffdh\ufffd\ufffd\ufffd\u0017/\n\nTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).\n\nSkill: timesfm-forecasting\nRule: TM1  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-5a077ab375871ef6", "name": "SkillSpector TM2 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png", "shortDescription": {"text": "SkillSpector TM2 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "fullDescription": {"text": "|Su\n\nTool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.\n\nSkill: timesfm-forecasting\nRule: TM2  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.75\n\nRemediation: Limit tool chaining depth and validate the output of each tool before passing it to the next. Require explicit user approval for multi-step chains."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7cc71d3b6de8d7d2", "name": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif", "shortDescription": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "fullDescription": {"text": "RM\ufffdG\ufffd%\ufffd\\1\ufffdI\ufffdd\ufffd\ufffd\ufffd\ufffd\ufffd,\ufffd\ufffd/\n\nTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).\n\nSkill: timesfm-forecasting\nRule: TM1  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-42a46725d4cf9146", "name": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_visualization.png", "shortDescription": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_visualization.png"}, "fullDescription": {"text": "Rm\u06b4\ufffd\ufffd\ufffd\ufffd%I\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\u07bd{\u0015\u0015\u0015\ufffd\u0253'\ufffd\ufffd\u001e\u04e6M\ufffd\ufffd\ufffd\ufffd/\ufffd;\ufffd\u0233\ufffd\ufffd!C\ufffd\ufffdc\ufffdE\ufffd\ufffdT\ufffd\ufffd\u0002\ufffd\ufffdZ\ufffdn\ufffd\ufffd_\u007f=\ufffd\ufffd/\n\nTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).\n\nSkill: timesfm-forecasting\nRule: TM1  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-6962a2c713a7a100", "name": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/scripts/forecast_csv.py", "shortDescription": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/scripts/forecast_csv.py"}, "fullDescription": {"text": "--skip-check\n\nTool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).\n\nSkill: timesfm-forecasting\nRule: TM1  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.80\n\nRemediation: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7999999999999999}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan timesfm-forecasting --format sarif --ou"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d7e834080dbebed", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba465e5a103a61e1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "8 tests / 49 src (ratio 0.16)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 201 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c71125b1d464b26f", "name": "Legacy-named symbol `test_replace_creates_independent_copy` in tests/test_configs.py:73", "shortDescription": {"text": "Legacy-named symbol `test_replace_creates_independent_copy` in tests/test_configs.py:73"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a79e576eb7aafa2", "name": "Legacy-named symbol `context_dict_v2` in v1/experiments/extended_benchmarks/run_timesfm.py:58", "shortDescription": {"text": "Legacy-named symbol `context_dict_v2` in v1/experiments/extended_benchmarks/run_timesfm.py:58"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0c38d0f551b7418", "name": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/scripts/check_system.py:138", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/scripts/check_system.py:138"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad13e05a5afd8d91", "name": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/examples/covariates-forecasting/demo_covaria", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/examples/covariates-forecasting/demo_covariates.py:22"}, "fullDescription": {"text": "`urllib.request.urlretrieve(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1aeca319ac7a8120", "name": "Commented-code block (7 lines) in src/timesfm/utils/xreg_lib.py:480", "shortDescription": {"text": "Commented-code block (7 lines) in src/timesfm/utils/xreg_lib.py:480"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-33a6b62e30ce7ab4", "name": "Near-duplicate function bodies in 6 places", "shortDescription": {"text": "Near-duplicate function bodies in 6 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nv1/src/adapter/dora_layers.py:setup, v1/src/adapter/dora_layers.py:setup, v1/src/adapter/dora_layers.py:setup, v1/src/adapter/lora_layers.py:setup\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nv1/src/finetuning/finetuning_torch.py:log_metrics, v1/src/finetuning/finetuning_torch.py:log_metrics\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nv1/src/timesfm/xreg_lib.py:fit, v1/src/timesfm/xreg_lib.py:fit, src/timesfm/utils/xreg_lib.py:fit, src/timesfm/utils/xreg_lib.py:fit\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nv1/src/timesfm/patched_decoder.py:setup, v1/src/timesfm/patched_decoder.py:setup, v1/src/timesfm/patched_decoder.py:setup\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76a2f6818267a9a8", "name": "Near-duplicate function bodies in 8 places", "shortDescription": {"text": "Near-duplicate function bodies in 8 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nv1/src/timesfm/pytorch_patched_decoder.py:forward, v1/src/timesfm/pytorch_patched_decoder.py:forward, v1/src/timesfm/pytorch_patched_decoder.py:forward, v1/src/timesfm/pytorch_patched_decoder.py:forward\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30728"}, "properties": {"repository": "google-research/timesfm", "repoUrl": "https://github.com/google-research/timesfm.git", "branch": "master"}, "results": [{"ruleId": "GHSA-hgf8-39gv-g3f2", "level": "warning", "message": {"text": "werkzeug: GHSA-hgf8-39gv-g3f2"}, "properties": {"repobilityId": 468473, "scanner": "osv-scanner", "fingerprint": "50a2cd2f5c4beb0aca36cdb77aa55f773dd18490ad7525481fc446bafd5fb80b", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-66221"], "package": "werkzeug", "rule_id": "GHSA-hgf8-39gv-g3f2", "scanner": "osv-scanner", "correlation_key": "vuln|werkzeug|CVE-2025-66221|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-87hc-h4r5-73f7", "level": "warning", "message": {"text": "werkzeug: GHSA-87hc-h4r5-73f7"}, "properties": {"repobilityId": 468472, "scanner": "osv-scanner", "fingerprint": "0a69029b321e21a0cb2f111027669832c65c1c32f39c742b85a5371e63964f25", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-21860"], "package": "werkzeug", "rule_id": "GHSA-87hc-h4r5-73f7", "scanner": "osv-scanner", "correlation_key": "vuln|werkzeug|CVE-2026-21860|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-29vq-49wr-vm6x", "level": "warning", "message": {"text": "werkzeug: GHSA-29vq-49wr-vm6x"}, "properties": {"repobilityId": 468471, "scanner": "osv-scanner", "fingerprint": "ebf93b38c0fa0a9a1b7120ec15aaaab38064ee62082690cf72fb75e7f0a610a3", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27199"], "package": "werkzeug", "rule_id": "GHSA-29vq-49wr-vm6x", "scanner": "osv-scanner", "correlation_key": "vuln|werkzeug|CVE-2026-27199|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pq67-6m6q-mj2v", "level": "warning", "message": {"text": "urllib3: GHSA-pq67-6m6q-mj2v"}, "properties": {"repobilityId": 468470, "scanner": "osv-scanner", "fingerprint": "3ff82176243ac0d74dacff63f3eb3e608b95f050db323e9ae75a0c562641a878", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-50181"], "package": "urllib3", "rule_id": "GHSA-pq67-6m6q-mj2v", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2025-50181|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-48p4-8xcf-vxj5", "level": "warning", "message": {"text": "urllib3: GHSA-48p4-8xcf-vxj5"}, "properties": {"repobilityId": 468468, "scanner": "osv-scanner", "fingerprint": "64d66347949e0130f5a8e32dde0a4a65c9027c90fb2c30557e47cd31fbeb3b75", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-50182"], "package": "urllib3", "rule_id": "GHSA-48p4-8xcf-vxj5", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2025-50182|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rcv9-qm8p-9p6j", "level": "warning", "message": {"text": "transformers: GHSA-rcv9-qm8p-9p6j"}, "properties": {"repobilityId": 468464, "scanner": "osv-scanner", "fingerprint": "078d0393a8015f3444041978a6ed337d148cac3e8041d2278cc9232c231b4435", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-6051"], "package": "transformers", "rule_id": "GHSA-rcv9-qm8p-9p6j", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-6051|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q2wp-rjmx-x6x9", "level": "warning", "message": {"text": "transformers: GHSA-q2wp-rjmx-x6x9"}, "properties": {"repobilityId": 468463, "scanner": "osv-scanner", "fingerprint": "5c99f7ff2cf8311245235ecba6e8270067b7d2e4bad6f68ec6a33cb4f9cbdd72", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-3263"], "package": "transformers", "rule_id": "GHSA-q2wp-rjmx-x6x9", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-3263|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jjph-296x-mrcr", "level": "warning", "message": {"text": "transformers: GHSA-jjph-296x-mrcr"}, "properties": {"repobilityId": 468461, "scanner": "osv-scanner", "fingerprint": "34d45ba8c9e62ac8d2a4cf3d504ea0469766e224af3abe942ca260f7223f0a96", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-3264"], "package": "transformers", "rule_id": "GHSA-jjph-296x-mrcr", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-3264|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fpwr-67px-3qhx", "level": "warning", "message": {"text": "transformers: GHSA-fpwr-67px-3qhx"}, "properties": {"repobilityId": 468460, "scanner": "osv-scanner", "fingerprint": "be825215564a6b1e2ced0a6d063316d36ad8c71cba023c092ff3c2529f72a07f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-1194"], "package": "transformers", "rule_id": "GHSA-fpwr-67px-3qhx", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-1194|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9356-575x-2w9m", "level": "warning", "message": {"text": "transformers: GHSA-9356-575x-2w9m"}, "properties": {"repobilityId": 468459, "scanner": "osv-scanner", "fingerprint": "ba8600eeea54c6c818959de1c630e5de426745c461fddb12839fbc31beb61554", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-5197"], "package": "transformers", "rule_id": "GHSA-9356-575x-2w9m", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-5197|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6rvg-6v2m-4j46", "level": "warning", "message": {"text": "transformers: GHSA-6rvg-6v2m-4j46"}, "properties": {"repobilityId": 468458, "scanner": "osv-scanner", "fingerprint": "50ee6c79aa034b35b3e2c403bb495470db8fab080e3c780c8fe68924ff955963", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2024-12720"], "package": "transformers", "rule_id": "GHSA-6rvg-6v2m-4j46", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2024-12720|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-69w3-r845-3855", "level": "warning", "message": {"text": "transformers: GHSA-69w3-r845-3855"}, "properties": {"repobilityId": 468457, "scanner": "osv-scanner", "fingerprint": "bf86b4ade3c2cef2bde7bb33cdb8d45e08d54aac021f112b90064e82ea16cd0e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-1839"], "package": "transformers", "rule_id": "GHSA-69w3-r845-3855", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2026-1839|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-59p9-h35m-wg4g", "level": "warning", "message": {"text": "transformers: GHSA-59p9-h35m-wg4g"}, "properties": {"repobilityId": 468456, "scanner": "osv-scanner", "fingerprint": "66eab27617d086d56fe977b0d77a5d96ae6e308c6ac4b3e539eb4db3e970f4cf", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-6638"], "package": "transformers", "rule_id": "GHSA-59p9-h35m-wg4g", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-6638|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4w7r-h757-3r74", "level": "warning", "message": {"text": "transformers: GHSA-4w7r-h757-3r74"}, "properties": {"repobilityId": 468455, "scanner": "osv-scanner", "fingerprint": "a6d044153a11f33c5fc19133d9376546d27035f59d75367a33d1ee9f622d6b9d", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-6921"], "package": "transformers", "rule_id": "GHSA-4w7r-h757-3r74", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-6921|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-37mw-44qp-f5jm", "level": "warning", "message": {"text": "transformers: GHSA-37mw-44qp-f5jm"}, "properties": {"repobilityId": 468454, "scanner": "osv-scanner", "fingerprint": "9a6e2f67959076e729a7ac2ad244e62d5670694527ed3343c9657c10883b1142", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-3933"], "package": "transformers", "rule_id": "GHSA-37mw-44qp-f5jm", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-3933|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pw6j-qg29-8w7f", "level": "warning", "message": {"text": "tornado: GHSA-pw6j-qg29-8w7f"}, "properties": {"repobilityId": 468441, "scanner": "osv-scanner", "fingerprint": "22eb2d379696c907222374b3f51beaefc91c8864288f9928dddad75a88db4102", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "tornado", "rule_id": "GHSA-pw6j-qg29-8w7f", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|GHSA-PW6J-QG29-8W7F|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-78cv-mqj4-43f7", "level": "warning", "message": {"text": "tornado: GHSA-78cv-mqj4-43f7"}, "properties": {"repobilityId": 468436, "scanner": "osv-scanner", "fingerprint": "a2ead8349a6126c2c1a80892c824904db65548ff0b81db98cd126b000de14e3f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "tornado", "rule_id": "GHSA-78cv-mqj4-43f7", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|GHSA-78CV-MQJ4-43F7|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vgrw-7cvw-pwgx", "level": "warning", "message": {"text": "torch: GHSA-vgrw-7cvw-pwgx"}, "properties": {"repobilityId": 468432, "scanner": "osv-scanner", "fingerprint": "a23557d0a7bfea0ca433e74a0f5f6f409411fc55d7c12ab09d2f1d75437c29a5", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2999", "CVE-2025-2999", "PYSEC-2025-193"], "package": "torch", "rule_id": "GHSA-vgrw-7cvw-pwgx", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2999|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f4hp-rmr7-r7v8", "level": "warning", "message": {"text": "torch: GHSA-f4hp-rmr7-r7v8"}, "properties": {"repobilityId": 468429, "scanner": "osv-scanner", "fingerprint": "8b41076c4f74dfcf3a6d18de754260f656c2c8d44807013c25c7dddfcfad1d5f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2998", "CVE-2025-2998", "PYSEC-2025-192"], "package": "torch", "rule_id": "GHSA-f4hp-rmr7-r7v8", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2998|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-887c-mr87-cxwp", "level": "warning", "message": {"text": "torch: GHSA-887c-mr87-cxwp"}, "properties": {"repobilityId": 468427, "scanner": "osv-scanner", "fingerprint": "c0ab6fe111684c0bea81a2aa1f016e92b0132d6c1b180e4b567fe9f2b0aea1a1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3730", "CVE-2025-3730"], "package": "torch", "rule_id": "GHSA-887c-mr87-cxwp", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3730|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fxgc-95xx-grvq", "level": "warning", "message": {"text": "tensorflow: GHSA-fxgc-95xx-grvq"}, "properties": {"repobilityId": 468408, "scanner": "osv-scanner", "fingerprint": "eee297eb4bb79d69405662e02c1be211e03e40903383050c417be054c741caf0", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25661", "CVE-2023-25661"], "package": "tensorflow", "rule_id": "GHSA-fxgc-95xx-grvq", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25661|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fqm2-gh8w-gr68", "level": "warning", "message": {"text": "tensorflow: GHSA-fqm2-gh8w-gr68"}, "properties": {"repobilityId": 468407, "scanner": "osv-scanner", "fingerprint": "19a5c58feb6b06a061b5c6e3fd88ddff6c92b24044c86ec0d74caee335041286", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25667", "CVE-2023-25667"], "package": "tensorflow", "rule_id": "GHSA-fqm2-gh8w-gr68", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25667|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gc5v-m9x4-r6x2", "level": "warning", "message": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": 468390, "scanner": "osv-scanner", "fingerprint": "edee6cd13c2562b395e740a8c9b9c89939e4ea1fceca0ae00c0e5afdd0469a24", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-25645"], "package": "requests", "rule_id": "GHSA-gc5v-m9x4-r6x2", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2026-25645|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9hjg-9r4m-mvj7", "level": "warning", "message": {"text": "requests: GHSA-9hjg-9r4m-mvj7"}, "properties": {"repobilityId": 468389, "scanner": "osv-scanner", "fingerprint": "9286c116d94d888d2682b0b1bea5220f65a8660b14ba9ab14e4ab2028cba83c4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2024-47081"], "package": "requests", "rule_id": "GHSA-9hjg-9r4m-mvj7", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2024-47081|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6w46-j5rx-g56g", "level": "warning", "message": {"text": "pytest: GHSA-6w46-j5rx-g56g"}, "properties": {"repobilityId": 468388, "scanner": "osv-scanner", "fingerprint": "7b39524f5e972102b45bd4addd31402182646fd553038b66fdf8c7d44e6ffe44", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-71176"], "package": "pytest", "rule_id": "GHSA-6w46-j5rx-g56g", "scanner": "osv-scanner", "correlation_key": "vuln|pytest|CVE-2025-71176|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r73j-pqj5-w3x7", "level": "warning", "message": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": 468381, "scanner": "osv-scanner", "fingerprint": "788f3cce329c2c5a16b1bb7693b4118dd90622946d63637f02ad81e541c2645c", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42310", "CVE-2026-42310"], "package": "pillow", "rule_id": "GHSA-r73j-pqj5-w3x7", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42310|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rf74-v2fm-23pw", "level": "warning", "message": {"text": "nltk: GHSA-rf74-v2fm-23pw"}, "properties": {"repobilityId": 468375, "scanner": "osv-scanner", "fingerprint": "c8ecf0d63ae3d65a46d3777acf8c381937efbde67e0de841a37ff35e7138aa8c", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "nltk", "rule_id": "GHSA-rf74-v2fm-23pw", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|GHSA-RF74-V2FM-23PW|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gfwx-w7gr-fvh7", "level": "warning", "message": {"text": "nltk: GHSA-gfwx-w7gr-fvh7"}, "properties": {"repobilityId": 468372, "scanner": "osv-scanner", "fingerprint": "9da7a25d4190b46ae48c53c60ec9e81f7a4ef85328be9f6fd0be664d31d5898e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33230"], "package": "nltk", "rule_id": "GHSA-gfwx-w7gr-fvh7", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-33230|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7jqv-fw35-gmx9", "level": "warning", "message": {"text": "nbconvert: GHSA-7jqv-fw35-gmx9"}, "properties": {"repobilityId": 468365, "scanner": "osv-scanner", "fingerprint": "84028c7fcdad333e8a7c8dcc59b040668e993b9c48820ac20e49c68374e48980", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39378"], "package": "nbconvert", "rule_id": "GHSA-7jqv-fw35-gmx9", "scanner": "osv-scanner", "correlation_key": "vuln|nbconvert|CVE-2026-39378|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4c99-qj7h-p3vg", "level": "warning", "message": {"text": "nbconvert: GHSA-4c99-qj7h-p3vg"}, "properties": {"repobilityId": 468364, "scanner": "osv-scanner", "fingerprint": "e179daafd239efd85b142e6dae7115a8ec196c4e20f552071c9325f1aa2da5e4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39377"], "package": "nbconvert", "rule_id": "GHSA-4c99-qj7h-p3vg", "scanner": "osv-scanner", "correlation_key": "vuln|nbconvert|CVE-2026-39377|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-v87v-83h2-53w7", "level": "warning", "message": {"text": "mistune: GHSA-v87v-83h2-53w7"}, "properties": {"repobilityId": 468362, "scanner": "osv-scanner", "fingerprint": "b3e493cbf283c887ee2ae326cafe6eb67f7f9c5ae8e70c5731b1eaf86b533aa4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44897"], "package": "mistune", "rule_id": "GHSA-v87v-83h2-53w7", "scanner": "osv-scanner", "correlation_key": "vuln|mistune|CVE-2026-44897|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8g87-j6q8-g93x", "level": "warning", "message": {"text": "mistune: GHSA-8g87-j6q8-g93x"}, "properties": {"repobilityId": 468360, "scanner": "osv-scanner", "fingerprint": "2bbfaa58cacef05a12dcb94312a289a40383db6048ee3758a76af4c5aaf37066", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44708"], "package": "mistune", "rule_id": "GHSA-8g87-j6q8-g93x", "scanner": "osv-scanner", "correlation_key": "vuln|mistune|CVE-2026-44708|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mq84-hjqx-cwf2", "level": "warning", "message": {"text": "keras: GHSA-mq84-hjqx-cwf2"}, "properties": {"repobilityId": 468355, "scanner": "osv-scanner", "fingerprint": "373d5f71e56950c03b5520938eba6280c55e826807b6264e82c2a6a46c6f7998", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-12058", "GHSA-qg93-c7p6-gg7f"], "package": "keras", "rule_id": "GHSA-mq84-hjqx-cwf2", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2025-12058|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vmhf-c436-hxj4", "level": "warning", "message": {"text": "jupyterlab: GHSA-vmhf-c436-hxj4"}, "properties": {"repobilityId": 468349, "scanner": "osv-scanner", "fingerprint": "ac0f42f2e707bb567dd011b0882d01f0296823f472a70e3b3c8e6be6a25a33a5", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "jupyterlab", "rule_id": "GHSA-vmhf-c436-hxj4", "scanner": "osv-scanner", "correlation_key": "vuln|jupyterlab|GHSA-VMHF-C436-HXJ4|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-cpwx-vrp4-4pq7", "level": "warning", "message": {"text": "jinja2: GHSA-cpwx-vrp4-4pq7"}, "properties": {"repobilityId": 468339, "scanner": "osv-scanner", "fingerprint": "96689b727346a66061966665e2ac5e2a4898a11bb283747097a59810076105c9", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-27516"], "package": "jinja2", "rule_id": "GHSA-cpwx-vrp4-4pq7", "scanner": "osv-scanner", "correlation_key": "vuln|jinja2|CVE-2025-27516|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-768j-98cg-p3fv", "level": "warning", "message": {"text": "fonttools: GHSA-768j-98cg-p3fv"}, "properties": {"repobilityId": 468332, "scanner": "osv-scanner", "fingerprint": "d6836de835b3046501491f47aa8d7060192a696270e0549c4773cdf6a7ed2b3e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-66034"], "package": "fonttools", "rule_id": "GHSA-768j-98cg-p3fv", "scanner": "osv-scanner", "correlation_key": "vuln|fonttools|CVE-2025-66034|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w853-jp5j-5j7f", "level": "warning", "message": {"text": "filelock: GHSA-w853-jp5j-5j7f"}, "properties": {"repobilityId": 468331, "scanner": "osv-scanner", "fingerprint": "106f60254ec302b2840a768cd2f3a63c8a6b6b4a3087aa6d14245b94b1b37704", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-68146"], "package": "filelock", "rule_id": "GHSA-w853-jp5j-5j7f", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2025-68146|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qmgc-5h2g-mvrw", "level": "warning", "message": {"text": "filelock: GHSA-qmgc-5h2g-mvrw"}, "properties": {"repobilityId": 468330, "scanner": "osv-scanner", "fingerprint": "96ac27d4126e9723c37e86d34f2282b1883aceae39e0d5c2fa266b17cb76683b", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-22701"], "package": "filelock", "rule_id": "GHSA-qmgc-5h2g-mvrw", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2026-22701|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gj48-438w-jh9v", "level": "warning", "message": {"text": "bleach: GHSA-gj48-438w-jh9v"}, "properties": {"repobilityId": 468329, "scanner": "osv-scanner", "fingerprint": "728f6d58055111933c504517cdd44415886efc0ff7b84bb852b4239324cb6726", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "bleach", "rule_id": "GHSA-gj48-438w-jh9v", "scanner": "osv-scanner", "correlation_key": "vuln|bleach|GHSA-GJ48-438W-JH9V|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w853-jp5j-5j7f", "level": "warning", "message": {"text": "filelock: GHSA-w853-jp5j-5j7f"}, "properties": {"repobilityId": 468326, "scanner": "osv-scanner", "fingerprint": "af60cb3ff801be58eaeab276c9f553ec4c9af14034e3f467a0ca1f951c93ea4f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-68146"], "package": "filelock", "rule_id": "GHSA-w853-jp5j-5j7f", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2025-68146|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qmgc-5h2g-mvrw", "level": "warning", "message": {"text": "filelock: GHSA-qmgc-5h2g-mvrw"}, "properties": {"repobilityId": 468325, "scanner": "osv-scanner", "fingerprint": "09bb1212a8470222c60dba3d4dc6272087ef0938fc8a7861d09055faa05863bf", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-22701"], "package": "filelock", "rule_id": "GHSA-qmgc-5h2g-mvrw", "scanner": "osv-scanner", "correlation_key": "vuln|filelock|CVE-2026-22701|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "SEC045", "level": "warning", "message": {"text": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a lateral-movement vector after any one credential compromise. Sandboxes (__builtins__ cleared) are escapable: attackers use object introspection (().__class__.__mro__[-1].__subclasses__()) to reach os.system. CWE-95 (eval injection)."}, "properties": {"repobilityId": 468322, "scanner": "repobility-threat-engine", "fingerprint": "6d80237d63e90cfcb376f8f108c08d40e7f0660f18e66d6001cc3f46cc5f4a01", "category": "injection", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "eval(", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC045", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|injection|token|131|sec045"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/long_horizon_benchmarks/run_eval.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "SEC012", "level": "warning", "message": {"text": "[SEC012] ZipSlip \u2014 Archive Path Traversal: Archive extraction without path validation allows writing files outside the target directory."}, "properties": {"repobilityId": 468321, "scanner": "repobility-threat-engine", "fingerprint": "ba5adb1bbdc57fcf769ebe2721bcd2c55bee1476e93f4489f8c023ae9d205437", "category": "path_traversal", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": ".extractall(", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC012", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|path_traversal|token|121|sec012"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/utils.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "SEC127", "level": "warning", "message": {"text": "[SEC127] AI agent stub \u2014 TODO: implement / pass placeholder body: Function body left as TODO/pass/raise NotImplementedError after an AI scaffolding pass. The route appears to exist (and may even pass shallow CI), but invoking it crashes or silently no-ops. AI agents consistently emit these when their context window runs out mid-implementation. Production callers hitting these stubs is a classic AI-generated-incident."}, "properties": {"repobilityId": 468320, "scanner": "repobility-threat-engine", "fingerprint": "536cf0663078a37bd210bcabf82fd0922eac56ecac8df984b1a6cdbc045ae3b4", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "def forecast(\n      self,\n      df: pd.DataFrame,\n      h: int,\n      freq: str,\n  ) -> pd.DataFrame", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC127", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|536cf0663078a37bd210bcabf82fd0922eac56ecac8df984b1a6cdbc045ae3b4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/baselines/timegpt_pipeline.py"}, "region": {"startLine": 90}}}]}, {"ruleId": "ERR001", "level": "warning", "message": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "properties": {"repobilityId": 468319, "scanner": "repobility-threat-engine", "fingerprint": "f81ddf5e2bfed1f4b05b0323fd64c64107e1aed8ec000e3b546932ebc842ee08", "category": "error_handling", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "except Exception:\n                pass", "reason": "Pattern matched with no mitigating context found", "rule_id": "ERR001", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|f81ddf5e2bfed1f4b05b0323fd64c64107e1aed8ec000e3b546932ebc842ee08"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/forecast_csv.py"}, "region": {"startLine": 164}}}]}, {"ruleId": "AGT015", "level": "warning", "message": {"text": "Remote install command pipes network code directly to a shell"}, "properties": {"repobilityId": 468307, "scanner": "repobility-agent-runtime", "fingerprint": "9431a6ab5357e76ad4f4d001105e8e6bb5f82c51cf6d5c9094fd4194c15654d7", "category": "dependency", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "File contains a remote download piped directly to a shell without visible checksum or signature verification.", "evidence": {"rule_id": "AGT015", "scanner": "repobility-agent-runtime", "references": [], "correlation_key": "fp|9431a6ab5357e76ad4f4d001105e8e6bb5f82c51cf6d5c9094fd4194c15654d7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/manual_publish.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "AGT015", "level": "warning", "message": {"text": "Remote install command pipes network code directly to a shell"}, "properties": {"repobilityId": 468306, "scanner": "repobility-agent-runtime", "fingerprint": "bbb3e98be99b8211a97582677af96ce109aea632f2237c75d0f41ff27c8cc748", "category": "dependency", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "File contains a remote download piped directly to a shell without visible checksum or signature verification.", "evidence": {"rule_id": "AGT015", "scanner": "repobility-agent-runtime", "references": [], "correlation_key": "fp|bbb3e98be99b8211a97582677af96ce109aea632f2237c75d0f41ff27c8cc748"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 20}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `cachetools` is 2 major version(s) behind (5.5.0 -> 7.1.4)"}, "properties": {"repobilityId": 468305, "scanner": "repobility-dependency-currency", "fingerprint": "9fac5575cdca3d0b22537dbf1a027ba6f8e2b04b999d941e4b1a574a5c3bf4ba", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "2 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "cachetools", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "7.1.4", "correlation_key": "fp|9fac5575cdca3d0b22537dbf1a027ba6f8e2b04b999d941e4b1a574a5c3bf4ba", "current_version": "5.5.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `attrs` is 2 major version(s) behind (24.3.0 -> 26.1.0)"}, "properties": {"repobilityId": 468301, "scanner": "repobility-dependency-currency", "fingerprint": "b8b7da1820fb6b9c34ebbf991d13dd91eacd67e9c91cc8c8cc11a00854bfcb0e", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "2 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "attrs", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "26.1.0", "correlation_key": "fp|b8b7da1820fb6b9c34ebbf991d13dd91eacd67e9c91cc8c8cc11a00854bfcb0e", "current_version": "24.3.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `argon2-cffi-bindings` is 4 major version(s) behind (21.2.0 -> 25.1.0)"}, "properties": {"repobilityId": 468296, "scanner": "repobility-dependency-currency", "fingerprint": "151ee21e474b15256729699f7a8e1350a817e5235ffa4fe15fe54e647f96a76a", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "4 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "argon2-cffi-bindings", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "25.1.0", "correlation_key": "fp|151ee21e474b15256729699f7a8e1350a817e5235ffa4fe15fe54e647f96a76a", "current_version": "21.2.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `argon2-cffi` is 2 major version(s) behind (23.1.0 -> 25.1.0)"}, "properties": {"repobilityId": 468295, "scanner": "repobility-dependency-currency", "fingerprint": "7d5f31abf452f4e432e3532a8b25937e6e64ca98ee217532747b05424985d290", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "2 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "argon2-cffi", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "25.1.0", "correlation_key": "fp|7d5f31abf452f4e432e3532a8b25937e6e64ca98ee217532747b05424985d290", "current_version": "23.1.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `absl-py` is 1 major version(s) behind (1.4.0 -> 2.4.0)"}, "properties": {"repobilityId": 468293, "scanner": "repobility-dependency-currency", "fingerprint": "686f4317a98b4ad119b5c9074d15a1312a4900016940527aa45371edb8433698", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "absl-py", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.4.0", "correlation_key": "fp|686f4317a98b4ad119b5c9074d15a1312a4900016940527aa45371edb8433698", "current_version": "1.4.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `packaging` is 1 major version(s) behind (25.0 -> 26.2)"}, "properties": {"repobilityId": 468289, "scanner": "repobility-dependency-currency", "fingerprint": "71dced7659259f07ef98572780818cf70b5a958eba7fa2727d76147b7c88cfe8", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "packaging", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "26.2", "correlation_key": "fp|71dced7659259f07ef98572780818cf70b5a958eba7fa2727d76147b7c88cfe8", "current_version": "25.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 31}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `fsspec` is 1 major version(s) behind (2025.9.0 -> 2026.6.0)"}, "properties": {"repobilityId": 468285, "scanner": "repobility-dependency-currency", "fingerprint": "8d1e5e04491fcfcdfdaad4738cdde0687d1f5218204c4cd28eccbb27ff83e9cc", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "fsspec", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2026.6.0", "correlation_key": "fp|8d1e5e04491fcfcdfdaad4738cdde0687d1f5218204c4cd28eccbb27ff83e9cc", "current_version": "2025.9.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 13}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `certifi` is 1 major version(s) behind (2025.10.5 -> 2026.6.17)"}, "properties": {"repobilityId": 468282, "scanner": "repobility-dependency-currency", "fingerprint": "0b40bd1f64df4d58a01eae557431c390d8ec34bf8308c64bac375e548515d8ed", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "certifi", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2026.6.17", "correlation_key": "fp|0b40bd1f64df4d58a01eae557431c390d8ec34bf8308c64bac375e548515d8ed", "current_version": "2025.10.5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 5}}}]}, {"ruleId": "MINED109", "level": "warning", "message": {"text": "Mutable default argument in `forecast` (list)"}, "properties": {"repobilityId": 468275, "scanner": "repobility-ast-engine", "fingerprint": "65e19a195349c5d437052321e37da09271e203460c859f1d2ca70046cfdb2be3", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "mutable-default-arg", "owasp": null, "cwe_ids": ["CWE-1023"], "languages": ["python"], "observations_count": 64867}, "scanner": "repobility-ast-engine", "correlation_key": "fp|65e19a195349c5d437052321e37da09271e203460c859f1d2ca70046cfdb2be3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/baselines/timegpt_pipeline.py"}, "region": {"startLine": 184}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 468273, "scanner": "repobility-ast-engine", "fingerprint": "aa07dc2c088efb9e894426f29e86b87029748a00d635ae5cc82ece4329011a97", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|aa07dc2c088efb9e894426f29e86b87029748a00d635ae5cc82ece4329011a97"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/finetuning/finetuning_example.py"}, "region": {"startLine": 395}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 468246, "scanner": "repobility-ast-engine", "fingerprint": "7367de910b2d22873d7b20c9499450f70a5416352cb9fd40ef9e1192e766ad55", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7367de910b2d22873d7b20c9499450f70a5416352cb9fd40ef9e1192e766ad55"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/__init__.py"}, "region": {"startLine": 32}}}]}, {"ruleId": "MINED109", "level": "warning", "message": {"text": "Mutable default argument in `finetune` (list)"}, "properties": {"repobilityId": 468245, "scanner": "repobility-ast-engine", "fingerprint": "3990eb1e287795c7d60efeb35663657a8850c44cb9704e1eadb4f9bdc7d51aee", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "mutable-default-arg", "owasp": null, "cwe_ids": ["CWE-1023"], "languages": ["python"], "observations_count": 64867}, "scanner": "repobility-ast-engine", "correlation_key": "fp|3990eb1e287795c7d60efeb35663657a8850c44cb9704e1eadb4f9bdc7d51aee"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/peft/finetune.py"}, "region": {"startLine": 63}}}]}, {"ruleId": "GHSA-phhr-52qp-3mj4", "level": "note", "message": {"text": "transformers: GHSA-phhr-52qp-3mj4"}, "properties": {"repobilityId": 468462, "scanner": "osv-scanner", "fingerprint": "5e4dda840e23fef824c4cf781ab84fa191f6ee611e51c6b488aff122c2ab797f", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-3777"], "package": "transformers", "rule_id": "GHSA-phhr-52qp-3mj4", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-3777|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-cx3h-4qpv-8hc9", "level": "note", "message": {"text": "tornado: GHSA-cx3h-4qpv-8hc9"}, "properties": {"repobilityId": 468438, "scanner": "osv-scanner", "fingerprint": "7bdd9f37fe114f115077f312ff10f39b1fc53c3e8e4806119265d0e848ccc78a", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49854"], "package": "tornado", "rule_id": "GHSA-cx3h-4qpv-8hc9", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2026-49854|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-x3gm-94wq-g975", "level": "note", "message": {"text": "torch: GHSA-x3gm-94wq-g975"}, "properties": {"repobilityId": 468433, "scanner": "osv-scanner", "fingerprint": "4aa7b3c0a1042353b51e222f8ac44ec1c63b0b725758366f5ad308cbc3d405da", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2149", "CVE-2025-2149", "PYSEC-2025-190"], "package": "torch", "rule_id": "GHSA-x3gm-94wq-g975", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2149|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rrmf-rvhw-rf47", "level": "note", "message": {"text": "torch: GHSA-rrmf-rvhw-rf47"}, "properties": {"repobilityId": 468431, "scanner": "osv-scanner", "fingerprint": "6e5664fe157b1e9e5caf76a6ef65c9f5747844cc53d1f530882009a6b1594dfc", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3000", "CVE-2025-3000", "PYSEC-2025-194"], "package": "torch", "rule_id": "GHSA-rrmf-rvhw-rf47", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3000|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qfhq-4f3w-5fph", "level": "note", "message": {"text": "torch: GHSA-qfhq-4f3w-5fph"}, "properties": {"repobilityId": 468430, "scanner": "osv-scanner", "fingerprint": "e4e78842b1120416313d6614ecb03464ac19d54ac571cc46b1f4872d11d5c775", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-3001", "CVE-2025-3001", "PYSEC-2025-195"], "package": "torch", "rule_id": "GHSA-qfhq-4f3w-5fph", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-3001|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-c678-jfcj-6jmf", "level": "note", "message": {"text": "torch: GHSA-c678-jfcj-6jmf"}, "properties": {"repobilityId": 468428, "scanner": "osv-scanner", "fingerprint": "68611f1bc1d45042ef4c3f3aef48279ba5622030ddb4af44b3f869ac92fcea54", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2148", "CVE-2025-2148", "PYSEC-2025-189"], "package": "torch", "rule_id": "GHSA-c678-jfcj-6jmf", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2148|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5239-wwwm-4pmq", "level": "note", "message": {"text": "pygments: GHSA-5239-wwwm-4pmq"}, "properties": {"repobilityId": 468387, "scanner": "osv-scanner", "fingerprint": "9661faf9e4b6fd6f6ce71c7c441cd05845078bc4627fece0585f34c658406ada", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-4539"], "package": "pygments", "rule_id": "GHSA-5239-wwwm-4pmq", "scanner": "osv-scanner", "correlation_key": "vuln|pygments|CVE-2026-4539|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vvfj-2jqx-52jm", "level": "note", "message": {"text": "jupyterlab: GHSA-vvfj-2jqx-52jm"}, "properties": {"repobilityId": 468350, "scanner": "osv-scanner", "fingerprint": "9f7474172f67c8731c2e52e9e66d032199b7315c8e4b53031cb938b892fbd44b", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-jupyterlab-2025-59842", "CVE-2025-59842"], "package": "jupyterlab", "rule_id": "GHSA-vvfj-2jqx-52jm", "scanner": "osv-scanner", "correlation_key": "vuln|jupyterlab|CVE-2025-59842|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8rfp-98v4-mmr6", "level": "note", "message": {"text": "bleach: GHSA-8rfp-98v4-mmr6"}, "properties": {"repobilityId": 468328, "scanner": "osv-scanner", "fingerprint": "a4d8f08e0c67eff4f7a7820aedf542ce5d0c49409e6e9e4bc060ada5d8a354bf", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "bleach", "rule_id": "GHSA-8rfp-98v4-mmr6", "scanner": "osv-scanner", "correlation_key": "vuln|bleach|GHSA-8RFP-98V4-MMR6|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "COMP001", "level": "note", "message": {"text": "[COMP001] High cognitive complexity: Function `forward` has cognitive complexity 9 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: else=3, if=6."}, "properties": {"repobilityId": 468317, "scanner": "repobility-threat-engine", "fingerprint": "b480868bcfde1106df9f4a09e44d30f0f0049f81efc9c2e77c33174536ce6cde", "category": "quality", "severity": "low", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 9 (severity threshold for low: 8+).", "evidence": {"scanner": "repobility-threat-engine", "function": "forward", "breakdown": {"if": 6, "else": 3}, "complexity": 9, "correlation_key": "fp|b480868bcfde1106df9f4a09e44d30f0f0049f81efc9c2e77c33174536ce6cde"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/torch/transformer.py"}, "region": {"startLine": 224}}}]}, {"ruleId": "COMP001", "level": "note", "message": {"text": "[COMP001] High cognitive complexity: Function `__init__` has cognitive complexity 8 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: elif=2, else=3, if=3."}, "properties": {"repobilityId": 468316, "scanner": "repobility-threat-engine", "fingerprint": "a8b4516e8a341da73dabe08a857f33c1f752b2bd7ffefef264384239a0a61407", "category": "quality", "severity": "low", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 8 (severity threshold for low: 8+).", "evidence": {"scanner": "repobility-threat-engine", "function": "__init__", "breakdown": {"if": 3, "elif": 2, "else": 3}, "complexity": 8, "correlation_key": "fp|a8b4516e8a341da73dabe08a857f33c1f752b2bd7ffefef264384239a0a61407"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/flax/transformer.py"}, "region": {"startLine": 294}}}]}, {"ruleId": "COMP001", "level": "note", "message": {"text": "[COMP001] High cognitive complexity: Function `__call__` has cognitive complexity 11 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: else=2, if=8, ternary=1."}, "properties": {"repobilityId": 468315, "scanner": "repobility-threat-engine", "fingerprint": "80e45869fb520ff320b0a12a34432718ddf7f7ebc263c2c1bf60563cb8398cac", "category": "quality", "severity": "low", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 11 (severity threshold for low: 8+).", "evidence": {"scanner": "repobility-threat-engine", "function": "__call__", "breakdown": {"if": 8, "else": 2, "ternary": 1}, "complexity": 11, "correlation_key": "fp|80e45869fb520ff320b0a12a34432718ddf7f7ebc263c2c1bf60563cb8398cac"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/flax/transformer.py"}, "region": {"startLine": 207}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `bleach` is minor version(s) behind (6.2.0 -> 6.4.0)"}, "properties": {"repobilityId": 468304, "scanner": "repobility-dependency-currency", "fingerprint": "f8329dd3b3c5dda76ba03537184bd1a04613e640133e3a4bbceab9f50ae0b95a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "bleach", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "6.4.0", "correlation_key": "fp|f8329dd3b3c5dda76ba03537184bd1a04613e640133e3a4bbceab9f50ae0b95a", "current_version": "6.2.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `beautifulsoup4` is minor version(s) behind (4.12.3 -> 4.15.0)"}, "properties": {"repobilityId": 468303, "scanner": "repobility-dependency-currency", "fingerprint": "a08d1a7420176972800a8926a4f330e6d770fb2c8036df3bc64142911cf855ad", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "beautifulsoup4", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.15.0", "correlation_key": "fp|a08d1a7420176972800a8926a4f330e6d770fb2c8036df3bc64142911cf855ad", "current_version": "4.12.3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `babel` is minor version(s) behind (2.16.0 -> 2.18.0)"}, "properties": {"repobilityId": 468302, "scanner": "repobility-dependency-currency", "fingerprint": "165244011ce5d9bce85bcc6769484e432a42e3c613df0971180ffd80ac7fab73", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "babel", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.18.0", "correlation_key": "fp|165244011ce5d9bce85bcc6769484e432a42e3c613df0971180ffd80ac7fab73", "current_version": "2.16.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `async-lru` is minor version(s) behind (2.0.4 -> 2.3.0)"}, "properties": {"repobilityId": 468300, "scanner": "repobility-dependency-currency", "fingerprint": "cbc1b0991494a57b7651aad4bcf07890e1241653865f3020a860a67de54ab056", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "async-lru", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.3.0", "correlation_key": "fp|cbc1b0991494a57b7651aad4bcf07890e1241653865f3020a860a67de54ab056", "current_version": "2.0.4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `arrow` is minor version(s) behind (1.3.0 -> 1.4.0)"}, "properties": {"repobilityId": 468298, "scanner": "repobility-dependency-currency", "fingerprint": "1415aba6e1d736d25693d537dae9d94debd44ec3d1cda08731cbc4c9b8e93a22", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "arrow", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "1.4.0", "correlation_key": "fp|1415aba6e1d736d25693d537dae9d94debd44ec3d1cda08731cbc4c9b8e93a22", "current_version": "1.3.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `array-record` is minor version(s) behind (0.6.0 -> 0.8.3)"}, "properties": {"repobilityId": 468297, "scanner": "repobility-dependency-currency", "fingerprint": "53b048a40b3696c11357604d127cf5c1e297f81e2e68c2b97cf8fd4f1e70d7d3", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "array-record", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.8.3", "correlation_key": "fp|53b048a40b3696c11357604d127cf5c1e297f81e2e68c2b97cf8fd4f1e70d7d3", "current_version": "0.6.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `anyio` is minor version(s) behind (4.7.0 -> 4.14.0)"}, "properties": {"repobilityId": 468294, "scanner": "repobility-dependency-currency", "fingerprint": "61ea04ffb1d94852a01b010c83c683ccc02275a17517c58e108f54f1990b93d3", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "anyio", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.14.0", "correlation_key": "fp|61ea04ffb1d94852a01b010c83c683ccc02275a17517c58e108f54f1990b93d3", "current_version": "4.7.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `typer-slim` is minor version(s) behind (0.20.0 -> 0.24.0)"}, "properties": {"repobilityId": 468292, "scanner": "repobility-dependency-currency", "fingerprint": "6c6d1b4f23c6890f56ff8e6018859bf5c9647d1ca191417c8a39ef709b5b313a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "typer-slim", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.24.0", "correlation_key": "fp|6c6d1b4f23c6890f56ff8e6018859bf5c9647d1ca191417c8a39ef709b5b313a", "current_version": "0.20.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 43}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `tqdm` is minor version(s) behind (4.67.1 -> 4.68.3)"}, "properties": {"repobilityId": 468291, "scanner": "repobility-dependency-currency", "fingerprint": "92cf4e86c3ea3d32e775dca09279e49fff952309785640ba650a1d31a6bc7fe8", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "tqdm", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.68.3", "correlation_key": "fp|92cf4e86c3ea3d32e775dca09279e49fff952309785640ba650a1d31a6bc7fe8", "current_version": "4.67.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 41}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `safetensors` is minor version(s) behind (0.6.2 -> 0.8.0)"}, "properties": {"repobilityId": 468290, "scanner": "repobility-dependency-currency", "fingerprint": "1fb632d41d0022a87f88b455afa71f49930e131ff7d315880da6b1d6317894b3", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "safetensors", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.8.0", "correlation_key": "fp|1fb632d41d0022a87f88b455afa71f49930e131ff7d315880da6b1d6317894b3", "current_version": "0.6.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 35}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `idna` is minor version(s) behind (3.10 -> 3.18)"}, "properties": {"repobilityId": 468288, "scanner": "repobility-dependency-currency", "fingerprint": "aadceecac9e8c7561f284543648c770e1d9ced92dc11603e9aff8708aab7a5cd", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "idna", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.18", "correlation_key": "fp|aadceecac9e8c7561f284543648c770e1d9ced92dc11603e9aff8708aab7a5cd", "current_version": "3.10"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 25}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `huggingface-hub` is minor version(s) behind (1.0.1 -> 1.20.1)"}, "properties": {"repobilityId": 468287, "scanner": "repobility-dependency-currency", "fingerprint": "6fc7151cacfa72c62bc8c3295dcf476af5bb4a94baa833ac777cfeec83af4924", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "huggingface-hub", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "1.20.1", "correlation_key": "fp|6fc7151cacfa72c62bc8c3295dcf476af5bb4a94baa833ac777cfeec83af4924", "current_version": "1.0.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 23}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `hf-xet` is minor version(s) behind (1.2.0 -> 1.5.1)"}, "properties": {"repobilityId": 468286, "scanner": "repobility-dependency-currency", "fingerprint": "fa48ded8ff6aefa512ff39e80d7b239c32e5860265023507d28adc9daf503e71", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "hf-xet", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "1.5.1", "correlation_key": "fp|fa48ded8ff6aefa512ff39e80d7b239c32e5860265023507d28adc9daf503e71", "current_version": "1.2.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 17}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `filelock` is minor version(s) behind (3.19.1 -> 3.29.4)"}, "properties": {"repobilityId": 468284, "scanner": "repobility-dependency-currency", "fingerprint": "4a72932645e4d20b44681b43bede2c2072d0154b43b9d2206fad83b12cf60570", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "filelock", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.29.4", "correlation_key": "fp|4a72932645e4d20b44681b43bede2c2072d0154b43b9d2206fad83b12cf60570", "current_version": "3.19.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 11}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `click` is minor version(s) behind (8.3.0 -> 8.4.1)"}, "properties": {"repobilityId": 468283, "scanner": "repobility-dependency-currency", "fingerprint": "3a15a0fed629c5e5529e1d4b903fb6110fd64cbfbdc5d66441f946ea5b64fe18", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "click", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "8.4.1", "correlation_key": "fp|3a15a0fed629c5e5529e1d4b903fb6110fd64cbfbdc5d66441f946ea5b64fe18", "current_version": "8.3.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 9}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `anyio` is minor version(s) behind (4.11.0 -> 4.14.0)"}, "properties": {"repobilityId": 468281, "scanner": "repobility-dependency-currency", "fingerprint": "7a521c0b43d86fdee9f9d2207a44a40b1ebc68963eece33449255e6b1eaf9df6", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "anyio", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.14.0", "correlation_key": "fp|7a521c0b43d86fdee9f9d2207a44a40b1ebc68963eece33449255e6b1eaf9df6", "current_version": "4.11.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 3}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-python` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 468280, "scanner": "repobility-supply-chain", "fingerprint": "dcfc20be38c7067e108a1fd0ddc1d563af88b7cfafdf4566e4906ec18143627d", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|dcfc20be38c7067e108a1fd0ddc1d563af88b7cfafdf4566e4906ec18143627d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/manual_publish.yml"}, "region": {"startLine": 12}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 468279, "scanner": "repobility-supply-chain", "fingerprint": "265a1b11ce39b1ca4656dafc55162246a794ea0ebeb92f845a07cff55a5ec58f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|265a1b11ce39b1ca4656dafc55162246a794ea0ebeb92f845a07cff55a5ec58f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/manual_publish.yml"}, "region": {"startLine": 10}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-python` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 468278, "scanner": "repobility-supply-chain", "fingerprint": "7fd8802eaa4a5b3fdd94d15aaf6b1815231166a2feda793e196bbf0a4c3bee65", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|7fd8802eaa4a5b3fdd94d15aaf6b1815231166a2feda793e196bbf0a4c3bee65"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 15}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 468277, "scanner": "repobility-supply-chain", "fingerprint": "6830480325dcf6c72f043acedfdd7cade3979eca622bb451456f8db356e04e8f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|6830480325dcf6c72f043acedfdd7cade3979eca622bb451456f8db356e04e8f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 13}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468223, "scanner": "repobility-ai-code-hygiene", "fingerprint": "86c8a7c0f1af47096572b8ec82c3bff1c5d3f8a12ffbe6bfd1d79dab0e7eb192", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "src/timesfm/utils/xreg_lib.py", "duplicate_line": 41, "correlation_key": "fp|86c8a7c0f1af47096572b8ec82c3bff1c5d3f8a12ffbe6bfd1d79dab0e7eb192"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/xreg_lib.py"}, "region": {"startLine": 31}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468222, "scanner": "repobility-ai-code-hygiene", "fingerprint": "3d24284e30d4f2b0f117ebacf3fcf0d2ff351231b34afcd7fc84559ab223bf65", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/src/timesfm/timesfm_jax.py", "duplicate_line": 210, "correlation_key": "fp|3d24284e30d4f2b0f117ebacf3fcf0d2ff351231b34afcd7fc84559ab223bf65"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_torch.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468221, "scanner": "repobility-ai-code-hygiene", "fingerprint": "794249fdff77eeccc343d65f475a7a7e75e76d3515e91b506d1807fbb27d1ab2", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/src/timesfm/timesfm_base.py", "duplicate_line": 235, "correlation_key": "fp|794249fdff77eeccc343d65f475a7a7e75e76d3515e91b506d1807fbb27d1ab2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_torch.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468220, "scanner": "repobility-ai-code-hygiene", "fingerprint": "67e4396086f7a558f4face5012db5b17fdc73f9eb0ed9521befe751a3a1df931", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/src/timesfm/timesfm_base.py", "duplicate_line": 235, "correlation_key": "fp|67e4396086f7a558f4face5012db5b17fdc73f9eb0ed9521befe751a3a1df931"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 200}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468219, "scanner": "repobility-ai-code-hygiene", "fingerprint": "36c41306c61870584573402158a1f6800ca5d396d1b3ad073e49a881fde1396f", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "src/timesfm/timesfm_2p5/timesfm_2p5_base.py", "duplicate_line": 26, "correlation_key": "fp|36c41306c61870584573402158a1f6800ca5d396d1b3ad073e49a881fde1396f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_base.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468218, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b220a99d13c2035aed07b126dcac206987179c22f68b067b1df14cc740c1d2e1", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/src/timesfm/patched_decoder.py", "duplicate_line": 315, "correlation_key": "fp|b220a99d13c2035aed07b126dcac206987179c22f68b067b1df14cc740c1d2e1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/pytorch_patched_decoder.py"}, "region": {"startLine": 541}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468217, "scanner": "repobility-ai-code-hygiene", "fingerprint": "a009b20751756b665a94015e6b4b9e8a5dd1a84a62fd2add9f12f2a535d1170e", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/src/adapter/dora_layers.py", "duplicate_line": 54, "correlation_key": "fp|a009b20751756b665a94015e6b4b9e8a5dd1a84a62fd2add9f12f2a535d1170e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/adapter/lora_layers.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468216, "scanner": "repobility-ai-code-hygiene", "fingerprint": "034d481f118f0423dfa13851831ad66cfdea5bcf1f3f5a4e8a8c08b2cc0dc458", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "v1/experiments/extended_benchmarks/run_timegpt.py", "duplicate_line": 9, "correlation_key": "fp|034d481f118f0423dfa13851831ad66cfdea5bcf1f3f5a4e8a8c08b2cc0dc458"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/run_timesfm.py"}, "region": {"startLine": 9}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 468215, "scanner": "repobility-ai-code-hygiene", "fingerprint": "44fb3c648c33ab256a59a3a539f4a14a3175771a652c7e892574f18170f1b771", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "src/timesfm/timesfm_2p5/timesfm_2p5_flax.py", "duplicate_line": 425, "correlation_key": "fp|44fb3c648c33ab256a59a3a539f4a14a3175771a652c7e892574f18170f1b771"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/timesfm_2p5/timesfm_2p5_torch.py"}, "region": {"startLine": 304}}}]}, {"ruleId": "SEC011", "level": "none", "message": {"text": "[SEC011] Unsafe PyTorch Model Loading: torch.load() uses pickle internally and can execute arbitrary code from untrusted model files."}, "properties": {"repobilityId": 468324, "scanner": "repobility-threat-engine", "fingerprint": "489f4dd94f4a5d083f78ba608fe2b852c6660d82573a29a603aad68154a0403a", "category": "deserialization", "severity": "info", "confidence": 0.1, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Safe pattern 'weights_only\\s*=\\s*True' detected on same line", "evidence": {"match": "torch.load(", "reason": "Safe pattern 'weights_only\\s*=\\s*True' detected on same line", "rule_id": "SEC011", "scanner": "repobility-threat-engine", "confidence": 0.1, "correlation_key": "code|deserialization|token|64|sec011"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_torch.py"}, "region": {"startLine": 64}}}]}, {"ruleId": "SEC045", "level": "none", "message": {"text": "[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data \u2014 even admin-stored data \u2014 is a lateral-movement vector after any one credential compromise. Sandboxes (__builtins__ cleared) are escapable: attackers use object introspection (().__class__.__mro__[-1].__subclasses__()) to reach os.system. CWE-95 (eval injection)."}, "properties": {"repobilityId": 468323, "scanner": "repobility-threat-engine", "fingerprint": "2e09431ee19826ec42867376d24a7c3699e15a39a6bb6017d50f3058ed9d6a67", "category": "injection", "severity": "info", "confidence": 0.1, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Safe pattern '\\.eval\\(' detected on same line", "evidence": {"match": ".eval(", "reason": "Safe pattern '\\.eval\\(' detected on same line", "rule_id": "SEC045", "scanner": "repobility-threat-engine", "confidence": 0.1, "correlation_key": "code|injection|token|69|sec045"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_torch.py"}, "region": {"startLine": 69}}}]}, {"ruleId": "COMP001", "level": "none", "message": {"text": "[COMP001] High cognitive complexity (and 9 more): Same pattern found in 9 additional files. Review if needed."}, "properties": {"repobilityId": 468318, "scanner": "repobility-threat-engine", "fingerprint": "29306b5028b90ab8087937c717cb745fd7e07ab4ccb4b2237f19cccb49788ca3", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 9 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"scanner": "repobility-threat-engine", "function": "__call__", "breakdown": {"if": 8, "else": 2, "ternary": 1}, "aggregated": true, "complexity": 11, "correlation_key": "fp|29306b5028b90ab8087937c717cb745fd7e07ab4ccb4b2237f19cccb49788ca3", "aggregated_count": 9}}}, {"ruleId": "MINED057", "level": "none", "message": {"text": "[MINED057] Todo Bomb: Code path with a TODO/FIXME/HACK comment that gates correctness \u2014 left for later but never resolved."}, "properties": {"repobilityId": 468314, "scanner": "repobility-threat-engine", "fingerprint": "aa2487dca6e8de3178284c662ce76da107dd4be1fd8e02d628d229087a9f1cf0", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "todo-bomb", "owasp": null, "cwe_ids": [], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348035+00:00", "triaged_in_corpus": 10, "observations_count": 255662, "ai_coder_pattern_id": 4}, "scanner": "repobility-threat-engine", "correlation_key": "fp|aa2487dca6e8de3178284c662ce76da107dd4be1fd8e02d628d229087a9f1cf0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/configs.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "properties": {"repobilityId": 468313, "scanner": "repobility-threat-engine", "fingerprint": "86ba1835d70968651e1fbb2569a4d94211de579a814cf34a5d1e1e2eafe3f130", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|86ba1835d70968651e1fbb2569a4d94211de579a814cf34a5d1e1e2eafe3f130", "aggregated_count": 1}}}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 468312, "scanner": "repobility-threat-engine", "fingerprint": "929699e6d1db6e72dad85b47f496d4c2b9bf1509baaeb52d5b0caed8d484761d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|929699e6d1db6e72dad85b47f496d4c2b9bf1509baaeb52d5b0caed8d484761d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/baselines/timegpt_pipeline.py"}, "region": {"startLine": 96}}}]}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 468311, "scanner": "repobility-threat-engine", "fingerprint": "eef96fafba344eb5cc92577b70a0991a891950e8d1bfcc6a84b0d74a9995c980", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|eef96fafba344eb5cc92577b70a0991a891950e8d1bfcc6a84b0d74a9995c980"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/forecast_csv.py"}, "region": {"startLine": 165}}}]}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 468310, "scanner": "repobility-threat-engine", "fingerprint": "7d1749f28de63c52406d20308a792079f23295a42de3d10a4712ed12103edd41", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|7d1749f28de63c52406d20308a792079f23295a42de3d10a4712ed12103edd41"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/__init__.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `asttokens` is patch version(s) behind (3.0.0 -> 3.0.1)"}, "properties": {"repobilityId": 468299, "scanner": "repobility-dependency-currency", "fingerprint": "0b658758c14a16593579ba9b58c68141258c14427321793156bddd2eb2485b2d", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "asttokens", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.0.1", "correlation_key": "fp|0b658758c14a16593579ba9b58c68141258c14427321793156bddd2eb2485b2d", "current_version": "3.0.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8rrh-rw8j-w5fx", "level": "error", "message": {"text": "wheel: GHSA-8rrh-rw8j-w5fx"}, "properties": {"repobilityId": 468474, "scanner": "osv-scanner", "fingerprint": "cfe8548bf5e1a8cb7170ac35d124a9309b45b2680c656df48d0645b18461cc75", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24049"], "package": "wheel", "rule_id": "GHSA-8rrh-rw8j-w5fx", "scanner": "osv-scanner", "correlation_key": "vuln|wheel|CVE-2026-24049|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gm62-xv2j-4w53", "level": "error", "message": {"text": "urllib3: GHSA-gm62-xv2j-4w53"}, "properties": {"repobilityId": 468469, "scanner": "osv-scanner", "fingerprint": "b63e2bb6a4df4831f039511e893371d9791a297354f8fa952e84ef809dc93730", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-66418"], "package": "urllib3", "rule_id": "GHSA-gm62-xv2j-4w53", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2025-66418|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-38jv-5279-wg99", "level": "error", "message": {"text": "urllib3: GHSA-38jv-5279-wg99"}, "properties": {"repobilityId": 468467, "scanner": "osv-scanner", "fingerprint": "887b66a3ff51f31643f60576f81a3727f12e82f3c87d19e7b0a00922a37cfffb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-21441"], "package": "urllib3", "rule_id": "GHSA-38jv-5279-wg99", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2026-21441|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-2xpw-w6gg-jr37", "level": "error", "message": {"text": "urllib3: GHSA-2xpw-w6gg-jr37"}, "properties": {"repobilityId": 468466, "scanner": "osv-scanner", "fingerprint": "6e4c5fa8a6877defc1d6467fbb639d796b24f52ac30f10b203356ec9fd97d779", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-66471"], "package": "urllib3", "rule_id": "GHSA-2xpw-w6gg-jr37", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2025-66471|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-141", "level": "error", "message": {"text": "urllib3: PYSEC-2026-141"}, "properties": {"repobilityId": 468465, "scanner": "osv-scanner", "fingerprint": "1b6b5fae4a7aa75d393d05ef1d33ed5854457bd9465364cd82f152ee142b30e8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-44431", "GHSA-qccp-gfcp-xxvc"], "package": "urllib3", "rule_id": "PYSEC-2026-141", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2026-44431|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qccp-gfcp-xxvc", "PYSEC-2026-141"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["1b6b5fae4a7aa75d393d05ef1d33ed5854457bd9465364cd82f152ee142b30e8", "949ab5fbad1dd5fce3a9e27a753f78729bbaa9e917e774e097673c02fe1d0d49"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-40", "level": "error", "message": {"text": "transformers: PYSEC-2025-40"}, "properties": {"repobilityId": 468453, "scanner": "osv-scanner", "fingerprint": "179d0d04118edf652fe47856264c6d4d0c3bdfd490beb19970f94cf5ab5c9f69", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2025-2099", "GHSA-qq3j-4f4f-9583"], "package": "transformers", "rule_id": "PYSEC-2025-40", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-2099|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qq3j-4f4f-9583", "PYSEC-2025-40"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["179d0d04118edf652fe47856264c6d4d0c3bdfd490beb19970f94cf5ab5c9f69", "d1c41568983a3a40a75a725dcac75fca31d005e40a913262d28f8dd778c2654f"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-218", "level": "error", "message": {"text": "transformers: PYSEC-2025-218"}, "properties": {"repobilityId": 468452, "scanner": "osv-scanner", "fingerprint": "4f6e9d8a379cc6b9196e111b614f6c3c9aba63924b7475caa0eea236f13045a5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14930"], "package": "transformers", "rule_id": "PYSEC-2025-218", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14930|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-217", "level": "error", "message": {"text": "transformers: PYSEC-2025-217"}, "properties": {"repobilityId": 468451, "scanner": "osv-scanner", "fingerprint": "8ccbb2dee0a64fa9befaa7f62334628baccf5cb330bc280b5e81702f57a59541", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14929"], "package": "transformers", "rule_id": "PYSEC-2025-217", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14929|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-216", "level": "error", "message": {"text": "transformers: PYSEC-2025-216"}, "properties": {"repobilityId": 468450, "scanner": "osv-scanner", "fingerprint": "72191d9adf0103066f84f9893f8122c96648dda93395e97b84850dc9be5a1a97", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14928"], "package": "transformers", "rule_id": "PYSEC-2025-216", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14928|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-215", "level": "error", "message": {"text": "transformers: PYSEC-2025-215"}, "properties": {"repobilityId": 468449, "scanner": "osv-scanner", "fingerprint": "7fec52fe6b3e8b69caf1e6d010ffd652ed8f8289fef6c2f15b2a47c7f41a512c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14927"], "package": "transformers", "rule_id": "PYSEC-2025-215", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14927|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-214", "level": "error", "message": {"text": "transformers: PYSEC-2025-214"}, "properties": {"repobilityId": 468448, "scanner": "osv-scanner", "fingerprint": "9b24ba6a9598a92775a1a97efdf0cad3749a6394d3b7b34ff1f3108f5ec201f2", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14926"], "package": "transformers", "rule_id": "PYSEC-2025-214", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14926|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-213", "level": "error", "message": {"text": "transformers: PYSEC-2025-213"}, "properties": {"repobilityId": 468447, "scanner": "osv-scanner", "fingerprint": "651f721dfa02fe9c4e05e0a50f629ee3f1faec59d2e31c00b2823cf5b85a7458", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14924"], "package": "transformers", "rule_id": "PYSEC-2025-213", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14924|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-212", "level": "error", "message": {"text": "transformers: PYSEC-2025-212"}, "properties": {"repobilityId": 468446, "scanner": "osv-scanner", "fingerprint": "4e61d341b9ed11e16cef858370a33e8e4586a3406a2459e9e9b74f5fd6782fe8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14921"], "package": "transformers", "rule_id": "PYSEC-2025-212", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14921|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-211", "level": "error", "message": {"text": "transformers: PYSEC-2025-211"}, "properties": {"repobilityId": 468445, "scanner": "osv-scanner", "fingerprint": "6dfa75850070db4323b18482a653918f5d0219ea182d7ba90f732420f73f14a3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-14920"], "package": "transformers", "rule_id": "PYSEC-2025-211", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2025-14920|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2024-229", "level": "error", "message": {"text": "transformers: PYSEC-2024-229"}, "properties": {"repobilityId": 468444, "scanner": "osv-scanner", "fingerprint": "7efc7bcced3d7d7988ef69ba759443e9ffb5efc8d5cd53577738712237032b3f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2024-11394", "GHSA-hxxf-235m-72v3"], "package": "transformers", "rule_id": "PYSEC-2024-229", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2024-11394|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-hxxf-235m-72v3", "PYSEC-2024-229"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["7efc7bcced3d7d7988ef69ba759443e9ffb5efc8d5cd53577738712237032b3f", "cc35ab21ed30e1e636bde2bf526f9534222d72ba0d3a2b8f686307f925c3f13e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2024-228", "level": "error", "message": {"text": "transformers: PYSEC-2024-228"}, "properties": {"repobilityId": 468443, "scanner": "osv-scanner", "fingerprint": "c805b025cae9ed54b17778c5ed7f65c1d43a12eef81226645a82f2e2c0dbdb4b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2024-11393", "GHSA-wrfc-pvp9-mr9g"], "package": "transformers", "rule_id": "PYSEC-2024-228", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2024-11393|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-wrfc-pvp9-mr9g", "PYSEC-2024-228"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["6a2641b071994a2fd55188b7c0c646ce593378c7e7ab6e3d3bd327f1e6d0162b", "c805b025cae9ed54b17778c5ed7f65c1d43a12eef81226645a82f2e2c0dbdb4b"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2024-227", "level": "error", "message": {"text": "transformers: PYSEC-2024-227"}, "properties": {"repobilityId": 468442, "scanner": "osv-scanner", "fingerprint": "5a4b0791c27fdb2dd6301235beaf583843b2d8ccd1ed7de6e2eac0e68186989c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2024-11392", "GHSA-qxrp-vhvm-j765"], "package": "transformers", "rule_id": "PYSEC-2024-227", "scanner": "osv-scanner", "correlation_key": "vuln|transformers|CVE-2024-11392|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qxrp-vhvm-j765", "PYSEC-2024-227"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["4d52251f98df66265354d1af9b2e2c72cd1c1a8a20686c021b804210b66049b7", "5a4b0791c27fdb2dd6301235beaf583843b2d8ccd1ed7de6e2eac0e68186989c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mgf9-4vpg-hj56", "level": "error", "message": {"text": "tornado: GHSA-mgf9-4vpg-hj56"}, "properties": {"repobilityId": 468440, "scanner": "osv-scanner", "fingerprint": "7f817731e46d1b51d0d0eafd1c0bffb0258aba305112714c1daf331bfed14e65", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49855"], "package": "tornado", "rule_id": "GHSA-mgf9-4vpg-hj56", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2026-49855|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fqwm-6jpj-5wxc", "level": "error", "message": {"text": "tornado: GHSA-fqwm-6jpj-5wxc"}, "properties": {"repobilityId": 468439, "scanner": "osv-scanner", "fingerprint": "1e3d27cea6d7a40a5414210fd30bbc41cec829573b87990964ec14310c9f848e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-35536"], "package": "tornado", "rule_id": "GHSA-fqwm-6jpj-5wxc", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2026-35536|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7cx3-6m66-7c5m", "level": "error", "message": {"text": "tornado: GHSA-7cx3-6m66-7c5m"}, "properties": {"repobilityId": 468437, "scanner": "osv-scanner", "fingerprint": "f963994d01d5f92f3017cdb0ba5f53e693fc99a7157f9e1ccad75883f392bed3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-47287"], "package": "tornado", "rule_id": "GHSA-7cx3-6m66-7c5m", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2025-47287|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3x9g-8vmp-wqvf", "level": "error", "message": {"text": "tornado: GHSA-3x9g-8vmp-wqvf"}, "properties": {"repobilityId": 468435, "scanner": "osv-scanner", "fingerprint": "8c5afa6df0988cd0342db6d2253dcc43b67a8efdcb414e912dd155213ee2f0a3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49853"], "package": "tornado", "rule_id": "GHSA-3x9g-8vmp-wqvf", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2026-49853|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-140", "level": "error", "message": {"text": "tornado: PYSEC-2026-140"}, "properties": {"repobilityId": 468434, "scanner": "osv-scanner", "fingerprint": "1c835878d5b58f6aeb894f8c90c0efaf9cbb4e6097cfa47c58d59162b51e26af", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-31958", "GHSA-qjxf-f2mg-c6mc"], "package": "tornado", "rule_id": "PYSEC-2026-140", "scanner": "osv-scanner", "correlation_key": "vuln|tornado|CVE-2026-31958|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qjxf-f2mg-c6mc", "PYSEC-2026-140"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["1c835878d5b58f6aeb894f8c90c0efaf9cbb4e6097cfa47c58d59162b51e26af", "f15dcb6954303b35dd8bc7c797f80fd685f3ebe65a165a9098253ec290ae7da7"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-139", "level": "error", "message": {"text": "torch: PYSEC-2026-139"}, "properties": {"repobilityId": 468426, "scanner": "osv-scanner", "fingerprint": "402f918b2dea96a10cc52f6b0b10e896f1aba288f8f4f333bf5244232cba6a14", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2026-4538", "CVE-2026-4538"], "package": "torch", "rule_id": "PYSEC-2026-139", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2026-4538|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-209", "level": "error", "message": {"text": "torch: PYSEC-2025-209"}, "properties": {"repobilityId": 468424, "scanner": "osv-scanner", "fingerprint": "5b2ce9d9d971a40d3672c2a00dbc9481a8eaad65dd770ceb5429bdc55bf4845c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55560", "CVE-2025-55560"], "package": "torch", "rule_id": "PYSEC-2025-209", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55560|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-208", "level": "error", "message": {"text": "torch: PYSEC-2025-208"}, "properties": {"repobilityId": 468423, "scanner": "osv-scanner", "fingerprint": "6278b2ab77d813905ef60336f7d94e3a7650defd82e1da0a201703d046d31444", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55558", "CVE-2025-55558"], "package": "torch", "rule_id": "PYSEC-2025-208", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55558|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-207", "level": "error", "message": {"text": "torch: PYSEC-2025-207"}, "properties": {"repobilityId": 468422, "scanner": "osv-scanner", "fingerprint": "d9bdcd3f974230de88794ef6f83a41570418dd5c201b0327cbd1c6761062d186", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55557", "CVE-2025-55557"], "package": "torch", "rule_id": "PYSEC-2025-207", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55557|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-206", "level": "error", "message": {"text": "torch: PYSEC-2025-206"}, "properties": {"repobilityId": 468421, "scanner": "osv-scanner", "fingerprint": "4c721eb29d7c6b95d67a6bce8d2e0673b8a6f4553ad12fe794130dd7f3df2773", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55554", "CVE-2025-55554"], "package": "torch", "rule_id": "PYSEC-2025-206", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55554|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-205", "level": "error", "message": {"text": "torch: PYSEC-2025-205"}, "properties": {"repobilityId": 468420, "scanner": "osv-scanner", "fingerprint": "5ba33fe9bac2d0163bcf7e95f43dede4a8bd6010e5bd2d81bca953ffafe7fef9", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55553", "CVE-2025-55553"], "package": "torch", "rule_id": "PYSEC-2025-205", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55553|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-204", "level": "error", "message": {"text": "torch: PYSEC-2025-204"}, "properties": {"repobilityId": 468419, "scanner": "osv-scanner", "fingerprint": "d3b5e9ce748a4beee5ffe2d7c9958b55f94ef6dda5e528a0eb28d9d781822910", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55552", "CVE-2025-55552"], "package": "torch", "rule_id": "PYSEC-2025-204", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55552|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-203", "level": "error", "message": {"text": "torch: PYSEC-2025-203"}, "properties": {"repobilityId": 468418, "scanner": "osv-scanner", "fingerprint": "7a3bc736798bafa46253d2e6d32fbd1dc01a9136025f0d294e9fd25284163a72", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-55551", "CVE-2025-55551"], "package": "torch", "rule_id": "PYSEC-2025-203", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-55551|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-198", "level": "error", "message": {"text": "torch: PYSEC-2025-198"}, "properties": {"repobilityId": 468417, "scanner": "osv-scanner", "fingerprint": "df2942a63edf3380d74dc2aa31d3670c2b95f42103324cd2bc0cc2afa1702266", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-46148", "CVE-2025-46148"], "package": "torch", "rule_id": "PYSEC-2025-198", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-46148|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-191", "level": "error", "message": {"text": "torch: PYSEC-2025-191"}, "properties": {"repobilityId": 468416, "scanner": "osv-scanner", "fingerprint": "47aa0c5a05370bb7b8c5dcbe117abc97b4f9d5db8ccf5b9744d2b3ae6c74d98a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-2953", "CVE-2025-2953", "GHSA-3749-ghw9-m3mg"], "package": "torch", "rule_id": "PYSEC-2025-191", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-2953|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-3749-ghw9-m3mg", "PYSEC-2025-191"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["31d1661eeae12694fb757a6a2b6f2694d41e97aec8df8bc934d033ceb7d0f46f", "47aa0c5a05370bb7b8c5dcbe117abc97b4f9d5db8ccf5b9744d2b3ae6c74d98a"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2024-259", "level": "error", "message": {"text": "torch: PYSEC-2024-259"}, "properties": {"repobilityId": 468415, "scanner": "osv-scanner", "fingerprint": "189206e41ce83a5bf5c251c6caf66b67d5b8558862fe5241f012fe97c28afca9", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pytorch-2024-48063", "CVE-2024-48063"], "package": "torch", "rule_id": "PYSEC-2024-259", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2024-48063|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rcf8-g8jv-vg6p", "level": "error", "message": {"text": "tensorflow: GHSA-rcf8-g8jv-vg6p"}, "properties": {"repobilityId": 468414, "scanner": "osv-scanner", "fingerprint": "a37b7e2345d9b06b304c62446d7f9a3d1a1bac90ac657b93e900d6868220f829", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25669", "CVE-2023-25669"], "package": "tensorflow", "rule_id": "GHSA-rcf8-g8jv-vg6p", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25669|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qjqc-vqcf-5qvj", "level": "error", "message": {"text": "tensorflow: GHSA-qjqc-vqcf-5qvj"}, "properties": {"repobilityId": 468413, "scanner": "osv-scanner", "fingerprint": "55022fe4d56598c8e6127fc17ae3f3f9e430fce38052d7913d8224af18fb630a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25660", "CVE-2023-25660"], "package": "tensorflow", "rule_id": "GHSA-qjqc-vqcf-5qvj", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25660|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-j5w9-hmfh-4cr6", "level": "error", "message": {"text": "tensorflow: GHSA-j5w9-hmfh-4cr6"}, "properties": {"repobilityId": 468412, "scanner": "osv-scanner", "fingerprint": "990a96b3971acac6e634015d89ab780bf6e943fc96ed54e4505371f9ada4ed9d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25671", "CVE-2023-25671"], "package": "tensorflow", "rule_id": "GHSA-j5w9-hmfh-4cr6", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25671|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gjh7-xx4r-x345", "level": "error", "message": {"text": "tensorflow: GHSA-gjh7-xx4r-x345"}, "properties": {"repobilityId": 468410, "scanner": "osv-scanner", "fingerprint": "9cfc14f4482c3572aaea57bcdd510ebed767686ddaf9529d671089f2e23f0c5e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-33976", "CVE-2023-33976"], "package": "tensorflow", "rule_id": "GHSA-gjh7-xx4r-x345", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-33976|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gf97-q72m-7579", "level": "error", "message": {"text": "tensorflow: GHSA-gf97-q72m-7579"}, "properties": {"repobilityId": 468409, "scanner": "osv-scanner", "fingerprint": "5232925428f988018834f4e930cb20cca4b85c6b320fbff01046cca31c3951b6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25674", "CVE-2023-25674"], "package": "tensorflow", "rule_id": "GHSA-gf97-q72m-7579", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25674|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f637-vh3r-vfh2", "level": "error", "message": {"text": "tensorflow: GHSA-f637-vh3r-vfh2"}, "properties": {"repobilityId": 468406, "scanner": "osv-scanner", "fingerprint": "9aa3b4d81fc56e76c4902b536cb6f66071293d256ee38fd31316a09448796c51", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25666", "CVE-2023-25666"], "package": "tensorflow", "rule_id": "GHSA-f637-vh3r-vfh2", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25666|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f49c-87jh-g47q", "level": "error", "message": {"text": "tensorflow: GHSA-f49c-87jh-g47q"}, "properties": {"repobilityId": 468405, "scanner": "osv-scanner", "fingerprint": "245a6e2f9566db1af291c029969212e4e428327bcb7ae57a56452ae9d1b18fde", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25801", "CVE-2023-25801"], "package": "tensorflow", "rule_id": "GHSA-f49c-87jh-g47q", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25801|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-94mm-g2mv-8p7r", "level": "error", "message": {"text": "tensorflow: GHSA-94mm-g2mv-8p7r"}, "properties": {"repobilityId": 468404, "scanner": "osv-scanner", "fingerprint": "3d81c4c82994881cb698a2c8e6458e04fe0ecfe255d7c122bd32d9f9f1160caf", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25672", "CVE-2023-25672"], "package": "tensorflow", "rule_id": "GHSA-94mm-g2mv-8p7r", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25672|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-93vr-9q9m-pj8p", "level": "error", "message": {"text": "tensorflow: GHSA-93vr-9q9m-pj8p"}, "properties": {"repobilityId": 468403, "scanner": "osv-scanner", "fingerprint": "4e639b0a66624dcac6fc33cd53179307546759142ca60fe4d1fbe856127204d7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25659", "CVE-2023-25659"], "package": "tensorflow", "rule_id": "GHSA-93vr-9q9m-pj8p", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25659|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7x4v-9gxg-9hwj", "level": "error", "message": {"text": "tensorflow: GHSA-7x4v-9gxg-9hwj"}, "properties": {"repobilityId": 468402, "scanner": "osv-scanner", "fingerprint": "ca5a652c1ac06c04121c236c06243d88c815a41348ee203951681c3f99e11a6f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25675", "CVE-2023-25675"], "package": "tensorflow", "rule_id": "GHSA-7x4v-9gxg-9hwj", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25675|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7jvm-xxmr-v5cw", "level": "error", "message": {"text": "tensorflow: GHSA-7jvm-xxmr-v5cw"}, "properties": {"repobilityId": 468401, "scanner": "osv-scanner", "fingerprint": "63b8d46a12a26796237d5953a1a0c8fb90255f7f95cae71c8bfcd7e392387d0a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25662", "CVE-2023-25662"], "package": "tensorflow", "rule_id": "GHSA-7jvm-xxmr-v5cw", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25662|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6wfh-89q8-44jq", "level": "error", "message": {"text": "tensorflow: GHSA-6wfh-89q8-44jq"}, "properties": {"repobilityId": 468400, "scanner": "osv-scanner", "fingerprint": "35102f3456c5502c60e2a86b8d3de186a8b78400ad87a6970f17931212b1c8da", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25676", "CVE-2023-25676"], "package": "tensorflow", "rule_id": "GHSA-6wfh-89q8-44jq", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25676|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6hg6-5c2q-7rcr", "level": "error", "message": {"text": "tensorflow: GHSA-6hg6-5c2q-7rcr"}, "properties": {"repobilityId": 468399, "scanner": "osv-scanner", "fingerprint": "fb513d6a1ddb8cb54e0f0303c19243b825cd526d97233719c6e7514053b535f7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25664", "CVE-2023-25664"], "package": "tensorflow", "rule_id": "GHSA-6hg6-5c2q-7rcr", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25664|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-68v3-g9cm-rmm6", "level": "error", "message": {"text": "tensorflow: GHSA-68v3-g9cm-rmm6"}, "properties": {"repobilityId": 468398, "scanner": "osv-scanner", "fingerprint": "7bc694c0de0c314d939572ef69e11a62a31485f0ad0b55be70f31da787012b46", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25658", "CVE-2023-25658"], "package": "tensorflow", "rule_id": "GHSA-68v3-g9cm-rmm6", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25658|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-64jg-wjww-7c5w", "level": "error", "message": {"text": "tensorflow: GHSA-64jg-wjww-7c5w"}, "properties": {"repobilityId": 468397, "scanner": "osv-scanner", "fingerprint": "da0937969d27f23a0b14c006955363f1df795558eace24ae4c690a5d5d417c2f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25663", "CVE-2023-25663"], "package": "tensorflow", "rule_id": "GHSA-64jg-wjww-7c5w", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25663|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-647v-r7qq-24fh", "level": "error", "message": {"text": "tensorflow: GHSA-647v-r7qq-24fh"}, "properties": {"repobilityId": 468396, "scanner": "osv-scanner", "fingerprint": "53dba434520bd186dbf40c62e697d48a80b6da901c1a9635badea35fde9999e3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25673", "CVE-2023-25673"], "package": "tensorflow", "rule_id": "GHSA-647v-r7qq-24fh", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25673|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5w96-866f-6rm8", "level": "error", "message": {"text": "tensorflow: GHSA-5w96-866f-6rm8"}, "properties": {"repobilityId": 468395, "scanner": "osv-scanner", "fingerprint": "3951a8b99caa25114659fdbcef708cc83662225383862fd0fbec5bc411db0d48", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-27579", "CVE-2023-27579"], "package": "tensorflow", "rule_id": "GHSA-5w96-866f-6rm8", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-27579|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-558h-mq8x-7q9g", "level": "error", "message": {"text": "tensorflow: GHSA-558h-mq8x-7q9g"}, "properties": {"repobilityId": 468394, "scanner": "osv-scanner", "fingerprint": "a4cb12ff88e0d3f0562c5a02f98fd9b4054909fb5d47e69984aa9ace6294a2e2", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25665", "CVE-2023-25665"], "package": "tensorflow", "rule_id": "GHSA-558h-mq8x-7q9g", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25665|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-49rq-hwc3-x77w", "level": "error", "message": {"text": "tensorflow: GHSA-49rq-hwc3-x77w"}, "properties": {"repobilityId": 468393, "scanner": "osv-scanner", "fingerprint": "b7474312ed2c4cbf339d51e4c6f4c37eeae2ee8f276d600b4f9f8ec97be5243b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25670", "CVE-2023-25670"], "package": "tensorflow", "rule_id": "GHSA-49rq-hwc3-x77w", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25670|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-49", "level": "error", "message": {"text": "setuptools: PYSEC-2025-49"}, "properties": {"repobilityId": 468392, "scanner": "osv-scanner", "fingerprint": "90f0e482e8840dedf0e3be28b11971b248f36bb7c1af832174cc68fd32f397af", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-setuptools-2025-47273", "CVE-2025-47273", "GHSA-5rjg-fvgr-3xxf"], "package": "setuptools", "rule_id": "PYSEC-2025-49", "scanner": "osv-scanner", "correlation_key": "vuln|setuptools|CVE-2025-47273|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5rjg-fvgr-3xxf", "PYSEC-2025-49"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["90f0e482e8840dedf0e3be28b11971b248f36bb7c1af832174cc68fd32f397af", "ff7320fb147ced3f3f31894ac37b8da243a466d48244c1ac2707575f4c9dba42"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-38vq-g6vr-w8wf", "level": "error", "message": {"text": "sentencepiece: GHSA-38vq-g6vr-w8wf"}, "properties": {"repobilityId": 468391, "scanner": "osv-scanner", "fingerprint": "5b897cfb6d15fd441b19636bf883647a9857904268d5bdc4276e10f4fc6ecff9", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-1260"], "package": "sentencepiece", "rule_id": "GHSA-38vq-g6vr-w8wf", "scanner": "osv-scanner", "correlation_key": "vuln|sentencepiece|CVE-2026-1260|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jr27-m4p2-rc6r", "level": "error", "message": {"text": "pyasn1: GHSA-jr27-m4p2-rc6r"}, "properties": {"repobilityId": 468386, "scanner": "osv-scanner", "fingerprint": "7e6367ade8fba4ea651d7629fd16599390bd6b48d2e6609beddbaf87d98d0513", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-30922"], "package": "pyasn1", "rule_id": "GHSA-jr27-m4p2-rc6r", "scanner": "osv-scanner", "correlation_key": "vuln|pyasn1|CVE-2026-30922|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-63vm-454h-vhhq", "level": "error", "message": {"text": "pyasn1: GHSA-63vm-454h-vhhq"}, "properties": {"repobilityId": 468385, "scanner": "osv-scanner", "fingerprint": "6a01b18f03e0748558e9ccf56fa8ccb999186fcf31703a7254b312f27f44c140", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-23490"], "package": "pyasn1", "rule_id": "GHSA-63vm-454h-vhhq", "scanner": "osv-scanner", "correlation_key": "vuln|pyasn1|CVE-2026-23490|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8qvm-5x2c-j2w7", "level": "error", "message": {"text": "protobuf: GHSA-8qvm-5x2c-j2w7"}, "properties": {"repobilityId": 468384, "scanner": "osv-scanner", "fingerprint": "5888f55c274f3a6be2a843236e48f3b24073c3b0dc968600595bda5c6f300231", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-4565"], "package": "protobuf", "rule_id": "GHSA-8qvm-5x2c-j2w7", "scanner": "osv-scanner", "correlation_key": "vuln|protobuf|CVE-2025-4565|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7gcm-g887-7qv7", "level": "error", "message": {"text": "protobuf: GHSA-7gcm-g887-7qv7"}, "properties": {"repobilityId": 468383, "scanner": "osv-scanner", "fingerprint": "4653b79578cb9a3c019f4d89398b70e0a580275c12380ed43d1eddadf07faf57", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-0994"], "package": "protobuf", "rule_id": "GHSA-7gcm-g887-7qv7", "scanner": "osv-scanner", "correlation_key": "vuln|protobuf|CVE-2026-0994|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-whj4-6x5x-4v2j", "level": "error", "message": {"text": "pillow: GHSA-whj4-6x5x-4v2j"}, "properties": {"repobilityId": 468382, "scanner": "osv-scanner", "fingerprint": "24c3dfbb2d7bc12a5339ab814150b8787cd2307f5e4343855aacc2bf0ec4341c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-40192", "CVE-2026-40192"], "package": "pillow", "rule_id": "GHSA-whj4-6x5x-4v2j", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-40192|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pwv6-vv43-88gr", "level": "error", "message": {"text": "pillow: GHSA-pwv6-vv43-88gr"}, "properties": {"repobilityId": 468380, "scanner": "osv-scanner", "fingerprint": "3015401648def4d83665f20bce7c93f64bc40a0ff31d3600f993102e11c23f78", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42311", "CVE-2026-42311"], "package": "pillow", "rule_id": "GHSA-pwv6-vv43-88gr", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42311|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-cfh3-3jmp-rvhc", "level": "error", "message": {"text": "pillow: GHSA-cfh3-3jmp-rvhc"}, "properties": {"repobilityId": 468379, "scanner": "osv-scanner", "fingerprint": "031ac924d4b5f4359451733cba0f30f31084ae925754eeeec8709e3d20966d2e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-25990", "CVE-2026-25990"], "package": "pillow", "rule_id": "GHSA-cfh3-3jmp-rvhc", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-25990|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-165", "level": "error", "message": {"text": "pillow: PYSEC-2026-165"}, "properties": {"repobilityId": 468378, "scanner": "osv-scanner", "fingerprint": "410c6c8284c6be4a482953a8c7ab4b2c163dcfd871c02b194711c3b6df42954e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42308", "CVE-2026-42308", "GHSA-wjx4-4jcj-g98j"], "package": "pillow", "rule_id": "PYSEC-2026-165", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42308|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-wjx4-4jcj-g98j", "PYSEC-2026-165"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["0583cc9b393a9cebf71617424aba942e325a33adc7ad43b85fe42eb038da938b", "410c6c8284c6be4a482953a8c7ab4b2c163dcfd871c02b194711c3b6df42954e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rch3-82jr-f9w9", "level": "error", "message": {"text": "notebook: GHSA-rch3-82jr-f9w9"}, "properties": {"repobilityId": 468377, "scanner": "osv-scanner", "fingerprint": "00aa9f1ca8f14bc2283c012dbdebd6eff4083f03fa5c4c21c800241ee2990608", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-jupyter-base-notebook-2026-40171", "BIT-jupyter-notebook-2026-40171", "BIT-jupyterlab-2026-40171", "CVE-2026-40171"], "package": "notebook", "rule_id": "GHSA-rch3-82jr-f9w9", "scanner": "osv-scanner", "correlation_key": "vuln|notebook|CVE-2026-40171|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mqcg-5x36-vfcg", "level": "error", "message": {"text": "notebook: GHSA-mqcg-5x36-vfcg"}, "properties": {"repobilityId": 468376, "scanner": "osv-scanner", "fingerprint": "2dd69c32e0408d8762d55e9ecda08446fad2fae58ba66d59ba51ef869aa8a9a6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-jupyter-base-notebook-2026-42557", "BIT-jupyter-notebook-2026-42557", "BIT-jupyterlab-2026-42557", "CVE-2026-42557"], "package": "notebook", "rule_id": "GHSA-mqcg-5x36-vfcg", "scanner": "osv-scanner", "correlation_key": "vuln|notebook|CVE-2026-42557|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-p4gq-832x-fm9v", "level": "error", "message": {"text": "nltk: GHSA-p4gq-832x-fm9v"}, "properties": {"repobilityId": 468374, "scanner": "osv-scanner", "fingerprint": "55f642b1be76152b382a7077586b0b7e3f85e5763e8490e5305f653d7f78834d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-54293"], "package": "nltk", "rule_id": "GHSA-p4gq-832x-fm9v", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-54293|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jm6w-m3j8-898g", "level": "error", "message": {"text": "nltk: GHSA-jm6w-m3j8-898g"}, "properties": {"repobilityId": 468373, "scanner": "osv-scanner", "fingerprint": "ad70b4a02983d11eba012ea7430f387bcb0e52d9a6c1c990c22c2aae69982c99", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33231"], "package": "nltk", "rule_id": "GHSA-jm6w-m3j8-898g", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-33231|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-469j-vmhf-r6v7", "level": "error", "message": {"text": "nltk: GHSA-469j-vmhf-r6v7"}, "properties": {"repobilityId": 468371, "scanner": "osv-scanner", "fingerprint": "322076718d8f2bca6aba3df6199058d8938686d87554697706e299b54ca8668f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33236"], "package": "nltk", "rule_id": "GHSA-469j-vmhf-r6v7", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-33236|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-99", "level": "error", "message": {"text": "nltk: PYSEC-2026-99"}, "properties": {"repobilityId": 468370, "scanner": "osv-scanner", "fingerprint": "ec98b663bb2c029a3ae00eabe6ef35a0e7dfe0ee23d0ba36067f78b58dc9724d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-0848"], "package": "nltk", "rule_id": "PYSEC-2026-99", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-0848|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-98", "level": "error", "message": {"text": "nltk: PYSEC-2026-98"}, "properties": {"repobilityId": 468369, "scanner": "osv-scanner", "fingerprint": "26268154fba635f93b5a8cfdb6aa8716cbb5bf3a07d4951a7bedfab6280017b3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-0847", "GHSA-68j8-pq59-fqgm"], "package": "nltk", "rule_id": "PYSEC-2026-98", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-0847|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-68j8-pq59-fqgm", "PYSEC-2026-98"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["26268154fba635f93b5a8cfdb6aa8716cbb5bf3a07d4951a7bedfab6280017b3", "c461470691bc00d11c4d26040053b5066f775f3e328c8832b6cbcff993e9bf4c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-97", "level": "error", "message": {"text": "nltk: PYSEC-2026-97"}, "properties": {"repobilityId": 468368, "scanner": "osv-scanner", "fingerprint": "518a483eaaae64117738ec635e3a258ed50b6848ee48dd49db73f18a4f7f7522", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-0846", "GHSA-h8wq-7xc4-p3qx"], "package": "nltk", "rule_id": "PYSEC-2026-97", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2026-0846|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-h8wq-7xc4-p3qx", "PYSEC-2026-97"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["01235f215ca32f28cf9e73ab290252bf7f8eab70032ab8f7027b806574b4b8b0", "518a483eaaae64117738ec635e3a258ed50b6848ee48dd49db73f18a4f7f7522"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xm59-rqc7-hhvf", "level": "error", "message": {"text": "nbconvert: GHSA-xm59-rqc7-hhvf"}, "properties": {"repobilityId": 468366, "scanner": "osv-scanner", "fingerprint": "2e75f96e486e653530cec729756db15ec3655129000e5dd4b1951cea4d9dfe82", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-53000"], "package": "nbconvert", "rule_id": "GHSA-xm59-rqc7-hhvf", "scanner": "osv-scanner", "correlation_key": "vuln|nbconvert|CVE-2025-53000|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6v7p-g79w-8964", "level": "error", "message": {"text": "msgpack: GHSA-6v7p-g79w-8964"}, "properties": {"repobilityId": 468363, "scanner": "osv-scanner", "fingerprint": "86a75b3871ddad243b711274eba3ffa69eae717f80011e92e74bfe0c1775bf53", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "msgpack", "rule_id": "GHSA-6v7p-g79w-8964", "scanner": "osv-scanner", "correlation_key": "vuln|msgpack|GHSA-6V7P-G79W-8964|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8mp2-v27r-99xp", "level": "error", "message": {"text": "mistune: GHSA-8mp2-v27r-99xp"}, "properties": {"repobilityId": 468361, "scanner": "osv-scanner", "fingerprint": "ba9b88a6976c8ba284931259c32c8889e9ea6be0249c8cbe8114c6b52743b1b1", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33079"], "package": "mistune", "rule_id": "GHSA-8mp2-v27r-99xp", "scanner": "osv-scanner", "correlation_key": "vuln|mistune|CVE-2026-33079|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-168", "level": "error", "message": {"text": "mistune: PYSEC-2026-168"}, "properties": {"repobilityId": 468359, "scanner": "osv-scanner", "fingerprint": "3718a593fb8470b0c0d4041a3a9134a1f278814a9ce0adb1af24995eb1ab4bf8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-44896", "GHSA-58cw-g322-p94v"], "package": "mistune", "rule_id": "PYSEC-2026-168", "scanner": "osv-scanner", "correlation_key": "vuln|mistune|CVE-2026-44896|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-58cw-g322-p94v", "PYSEC-2026-168"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["044265752d1b7221810e83b0ce7c11bf714cde909a4fc560151cb7ddcf73a334", "3718a593fb8470b0c0d4041a3a9134a1f278814a9ce0adb1af24995eb1ab4bf8"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-89", "level": "error", "message": {"text": "markdown: PYSEC-2026-89"}, "properties": {"repobilityId": 468358, "scanner": "osv-scanner", "fingerprint": "34b6b1b1a6c7221c9f7c9941f5936e1f5eefe056305dee68fe3221f820485085", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2025-69534", "GHSA-5wmx-573v-2qwq"], "package": "markdown", "rule_id": "PYSEC-2026-89", "scanner": "osv-scanner", "correlation_key": "vuln|markdown|CVE-2025-69534|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5wmx-573v-2qwq", "PYSEC-2026-89"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["34b6b1b1a6c7221c9f7c9941f5936e1f5eefe056305dee68fe3221f820485085", "c32a0191daa702a8b14c8beec6f16304c48e840cfcda72e0542f75fb03592c40"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-87", "level": "error", "message": {"text": "lxml: PYSEC-2026-87"}, "properties": {"repobilityId": 468357, "scanner": "osv-scanner", "fingerprint": "01370de61c7909549b430ada07eb1f6c544c89417b8318672e69c4f54bbab1f3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-41066", "GHSA-vfmq-68hx-4jfw"], "package": "lxml", "rule_id": "PYSEC-2026-87", "scanner": "osv-scanner", "correlation_key": "vuln|lxml|CVE-2026-41066|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-vfmq-68hx-4jfw", "PYSEC-2026-87"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["01370de61c7909549b430ada07eb1f6c544c89417b8318672e69c4f54bbab1f3", "d558fe7becabe0bb57ef38403de1adbb332e35287f6fae60aa0345c79cd20129"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hjqc-jx6g-rwp9", "level": "error", "message": {"text": "keras: GHSA-hjqc-jx6g-rwp9"}, "properties": {"repobilityId": 468354, "scanner": "osv-scanner", "fingerprint": "2fce13f324234189099633516ba29121c5779e946381d7e90d38379be5d104a8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-12060"], "package": "keras", "rule_id": "GHSA-hjqc-jx6g-rwp9", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2025-12060|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4f3f-g24h-fr8m", "level": "error", "message": {"text": "keras: GHSA-4f3f-g24h-fr8m"}, "properties": {"repobilityId": 468353, "scanner": "osv-scanner", "fingerprint": "a8a97c666f616ab537aecbe7566b66a54ca3dd985502c7d7553fbf1906e81f92", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-1462"], "package": "keras", "rule_id": "GHSA-4f3f-g24h-fr8m", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2026-1462|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-36fq-jgmw-4r9c", "level": "error", "message": {"text": "keras: GHSA-36fq-jgmw-4r9c"}, "properties": {"repobilityId": 468352, "scanner": "osv-scanner", "fingerprint": "9754c4e3230995b1b6d51171ae713b2e979fb00c5a64cecf5d19cc98252b1776", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-9906", "PYSEC-2025-76"], "package": "keras", "rule_id": "GHSA-36fq-jgmw-4r9c", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2025-9906|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-121", "level": "error", "message": {"text": "keras: PYSEC-2025-121"}, "properties": {"repobilityId": 468351, "scanner": "osv-scanner", "fingerprint": "ed6a05486c5c5fa64ddddd1be7145981d0ff1b21a4fe48937ebbff156d5c9995", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2024-55459", "GHSA-cjgq-5qmw-rcj6"], "package": "keras", "rule_id": "PYSEC-2025-121", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2024-55459|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-cjgq-5qmw-rcj6", "PYSEC-2025-121"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["60c015904ded662559e34859d297dde108ba01f4c87a55395d96845415597e11", "ed6a05486c5c5fa64ddddd1be7145981d0ff1b21a4fe48937ebbff156d5c9995"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-rch3-82jr-f9w9", "level": "error", "message": {"text": "jupyterlab: GHSA-rch3-82jr-f9w9"}, "properties": {"repobilityId": 468348, "scanner": "osv-scanner", "fingerprint": "689862d92170fe78c09defaf8dfc8849e49c2301aa922f2a7104fab5a3354353", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-jupyter-base-notebook-2026-40171", "BIT-jupyter-notebook-2026-40171", "BIT-jupyterlab-2026-40171", "CVE-2026-40171"], "package": "jupyterlab", "rule_id": "GHSA-rch3-82jr-f9w9", "scanner": "osv-scanner", "correlation_key": "vuln|jupyterlab|CVE-2026-40171|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mqcg-5x36-vfcg", "level": "error", "message": {"text": "jupyterlab: GHSA-mqcg-5x36-vfcg"}, "properties": {"repobilityId": 468347, "scanner": "osv-scanner", "fingerprint": "5da3b3083ecf9cf97a91c6903f884b4a1200afd7abcca7dda38b643c67265356", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-jupyter-base-notebook-2026-42557", "BIT-jupyter-notebook-2026-42557", "BIT-jupyterlab-2026-42557", "CVE-2026-42557"], "package": "jupyterlab", "rule_id": "GHSA-mqcg-5x36-vfcg", "scanner": "osv-scanner", "correlation_key": "vuln|jupyterlab|CVE-2026-42557|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-164", "level": "error", "message": {"text": "jupyterlab: PYSEC-2026-164"}, "properties": {"repobilityId": 468346, "scanner": "osv-scanner", "fingerprint": "37cd3d80fff6abe7f9e95d2eef30b754dffef94cf6bd8ab78e02d0d298860a05", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-jupyterlab-2026-42266", "CVE-2026-42266", "GHSA-37w4-hwhx-4rc4"], "package": "jupyterlab", "rule_id": "PYSEC-2026-164", "scanner": "osv-scanner", "correlation_key": "vuln|jupyterlab|CVE-2026-42266|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-37w4-hwhx-4rc4", "PYSEC-2026-164"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["167b6ac6127a7234e20f07138280bf97177d362c7bd72e774651c928278479e7", "37cd3d80fff6abe7f9e95d2eef30b754dffef94cf6bd8ab78e02d0d298860a05"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-24qx-w28j-9m6p", "level": "error", "message": {"text": "jupyter-server: GHSA-24qx-w28j-9m6p"}, "properties": {"repobilityId": 468344, "scanner": "osv-scanner", "fingerprint": "f2d07caee79632a2b8b7ab2f39ebb0b3bef68d89bad8b9897dd2fe2c294fcab5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-40110"], "package": "jupyter-server", "rule_id": "GHSA-24qx-w28j-9m6p", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-server|CVE-2026-40110|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-69", "level": "error", "message": {"text": "jupyter-server: PYSEC-2026-69"}, "properties": {"repobilityId": 468343, "scanner": "osv-scanner", "fingerprint": "a374cb7a0ee86dee6d430f00fbddc7da29fbbd64a09e26eb03764fd2d16c94d5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-40934", "GHSA-5mrq-x3x5-8v8f"], "package": "jupyter-server", "rule_id": "PYSEC-2026-69", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-server|CVE-2026-40934|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5mrq-x3x5-8v8f", "PYSEC-2026-69"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["2e6c21c0b6fec8c0af32b4435d3dd99fb8469221e1250f2096ffe0adc2771904", "a374cb7a0ee86dee6d430f00fbddc7da29fbbd64a09e26eb03764fd2d16c94d5"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-68", "level": "error", "message": {"text": "jupyter-server: PYSEC-2026-68"}, "properties": {"repobilityId": 468342, "scanner": "osv-scanner", "fingerprint": "337131eefb9ca89745c30fce1f98941922b41a4801283b119e3f30ffc3201d55", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-35397", "GHSA-5789-5fc7-67v3"], "package": "jupyter-server", "rule_id": "PYSEC-2026-68", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-server|CVE-2026-35397|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5789-5fc7-67v3", "PYSEC-2026-68"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["337131eefb9ca89745c30fce1f98941922b41a4801283b119e3f30ffc3201d55", "5d80f73f9066afa00eddecf1514e75a3806fe742f3877cfa94a34ecd19252d99"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-67", "level": "error", "message": {"text": "jupyter-server: PYSEC-2026-67"}, "properties": {"repobilityId": 468341, "scanner": "osv-scanner", "fingerprint": "008f12f911be55da5775f5ccaa9529bd1ea08b93ac4653af112790fdec315e7e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2025-61669", "GHSA-qh7q-6qm3-653w"], "package": "jupyter-server", "rule_id": "PYSEC-2026-67", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-server|CVE-2025-61669|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qh7q-6qm3-653w", "PYSEC-2026-67"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["008f12f911be55da5775f5ccaa9529bd1ea08b93ac4653af112790fdec315e7e", "9d0416310a79e0cff53befa0b10546bf10bbfb1479fff39455db2a5631dbc127"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-33p9-3p43-82vq", "level": "error", "message": {"text": "jupyter-core: GHSA-33p9-3p43-82vq"}, "properties": {"repobilityId": 468340, "scanner": "osv-scanner", "fingerprint": "2c60327d5e2212fe990610aa86d64013688a3a282b692390768dcc4c39e003a5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-30167"], "package": "jupyter-core", "rule_id": "GHSA-33p9-3p43-82vq", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-core|CVE-2025-30167|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-215", "level": "error", "message": {"text": "idna: PYSEC-2026-215"}, "properties": {"repobilityId": 468338, "scanner": "osv-scanner", "fingerprint": "c76f3b1af4b8a42b95bb9fa52d1a98f2e2223421b43c6baf8c7e3c44403e5e5e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-45409", "GHSA-65pc-fj4g-8rjx"], "package": "idna", "rule_id": "PYSEC-2026-215", "scanner": "osv-scanner", "correlation_key": "vuln|idna|CVE-2024-3651|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-65pc-fj4g-8rjx", "PYSEC-2026-215"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["015e1e60e2c513905f864e4deb56e9753a275de5ce3cd3f0bf022fd9df172d4d", "c76f3b1af4b8a42b95bb9fa52d1a98f2e2223421b43c6baf8c7e3c44403e5e5e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-x2qx-6953-8485", "level": "error", "message": {"text": "gitpython: GHSA-x2qx-6953-8485"}, "properties": {"repobilityId": 468336, "scanner": "osv-scanner", "fingerprint": "66dfa9f61211a1245188c08e5f58b3bb7c77ee5413b75a0d77ee62e5946b9474", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42284"], "package": "gitpython", "rule_id": "GHSA-x2qx-6953-8485", "scanner": "osv-scanner", "correlation_key": "vuln|gitpython|CVE-2026-42284|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-v87r-6q3f-2j67", "level": "error", "message": {"text": "gitpython: GHSA-v87r-6q3f-2j67"}, "properties": {"repobilityId": 468335, "scanner": "osv-scanner", "fingerprint": "f56be6b9f06fcd9dae07fa964f808fc8af7a32538f003c90f866e3cfbcaee19d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44244"], "package": "gitpython", "rule_id": "GHSA-v87r-6q3f-2j67", "scanner": "osv-scanner", "correlation_key": "vuln|gitpython|CVE-2026-44244|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mv93-w799-cj2w", "level": "error", "message": {"text": "gitpython: GHSA-mv93-w799-cj2w"}, "properties": {"repobilityId": 468334, "scanner": "osv-scanner", "fingerprint": "da24a013a723be3152be1f982bdf2add0816e81beb6b9bb4f1b4927eebfd8429", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "package": "gitpython", "rule_id": "GHSA-mv93-w799-cj2w", "scanner": "osv-scanner", "correlation_key": "vuln|gitpython|CVE-2026-42215|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-mv93-w799-cj2w", "GHSA-rpm5-65cw-6hj4"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["d8b0d72ff08e87fa70d8e6e2e1b7afc0139c79fd193caecd15a6a6c1fc9bd8ac", "da24a013a723be3152be1f982bdf2add0816e81beb6b9bb4f1b4927eebfd8429"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7545-fcxq-7j24", "level": "error", "message": {"text": "gitpython: GHSA-7545-fcxq-7j24"}, "properties": {"repobilityId": 468333, "scanner": "osv-scanner", "fingerprint": "605cec5a32f651d350a3d7e6f928f2d7070d6b917d69f56ba63378f9768965fb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44243"], "package": "gitpython", "rule_id": "GHSA-7545-fcxq-7j24", "scanner": "osv-scanner", "correlation_key": "vuln|gitpython|CVE-2026-44243|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-215", "level": "error", "message": {"text": "idna: PYSEC-2026-215"}, "properties": {"repobilityId": 468327, "scanner": "osv-scanner", "fingerprint": "2fb6ef4e2dd438bc05185f7998bfbd6676991d35fcc33a243600b3b1acdc23d8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-45409", "GHSA-65pc-fj4g-8rjx"], "package": "idna", "rule_id": "PYSEC-2026-215", "scanner": "osv-scanner", "correlation_key": "vuln|idna|CVE-2024-3651|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-65pc-fj4g-8rjx", "PYSEC-2026-215"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["096ad1adcda9b23f165f1175fd8691f1cfd4f580557aea52903b73ec76fbc472", "2fb6ef4e2dd438bc05185f7998bfbd6676991d35fcc33a243600b3b1acdc23d8"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED001", "level": "error", "message": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "properties": {"repobilityId": 468309, "scanner": "repobility-threat-engine", "fingerprint": "849fbf7871a972c0061024e8c8a527cf619341063ce5d4d36e305681e5151594", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "correlation_key": "fp|849fbf7871a972c0061024e8c8a527cf619341063ce5d4d36e305681e5151594"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/forecast_csv.py"}, "region": {"startLine": 164}}}]}, {"ruleId": "MINED001", "level": "error", "message": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "properties": {"repobilityId": 468308, "scanner": "repobility-threat-engine", "fingerprint": "ba7897c091cbdc54420c2edb32ea889876da4bf95eb150053423a3c1e92688ce", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "correlation_key": "fp|ba7897c091cbdc54420c2edb32ea889876da4bf95eb150053423a3c1e92688ce"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/__init__.py"}, "region": {"startLine": 22}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_df"}, "properties": {"repobilityId": 468274, "scanner": "repobility-ast-engine", "fingerprint": "cbfeef71e3159d0f0cd41fe5aa0cbda639c2d1ddc6b15a967124b652a06e9aaa", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|cbfeef71e3159d0f0cd41fe5aa0cbda639c2d1ddc6b15a967124b652a06e9aaa"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/utils.py"}, "region": {"startLine": 169}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_val_gen"}, "properties": {"repobilityId": 468272, "scanner": "repobility-ast-engine", "fingerprint": "cc8556c890d4fcaaa4a451252d5f84cd75acf95bedcb895629cc891acb85c8eb", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|cc8556c890d4fcaaa4a451252d5f84cd75acf95bedcb895629cc891acb85c8eb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/data_loader.py"}, "region": {"startLine": 179}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.model_p` used but never assigned in __init__"}, "properties": {"repobilityId": 468271, "scanner": "repobility-ast-engine", "fingerprint": "a718b2df1615da80bdffe33b018378e854f8a2aed268d7572eff6df0ea494d5c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|a718b2df1615da80bdffe33b018378e854f8a2aed268d7572eff6df0ea494d5c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 110}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.mesh_name` used but never assigned in __init__"}, "properties": {"repobilityId": 468270, "scanner": "repobility-ast-engine", "fingerprint": "00edb9a8157b06343a79f9da56b3df4541b027e4f4e23d888ab1a5ff489e1d89", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|00edb9a8157b06343a79f9da56b3df4541b027e4f4e23d888ab1a5ff489e1d89"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 108}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.mesh_shape` used but never assigned in __init__"}, "properties": {"repobilityId": 468269, "scanner": "repobility-ast-engine", "fingerprint": "8103e0efe44e4468379fc9f2f2c23b47df585f5f4356b3d84a5b6237ad70da5b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|8103e0efe44e4468379fc9f2f2c23b47df585f5f4356b3d84a5b6237ad70da5b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.num_cores` used but never assigned in __init__"}, "properties": {"repobilityId": 468268, "scanner": "repobility-ast-engine", "fingerprint": "74e6e3a5606550602ce3703e0fe897585be9b2f68509d28ba86ee3628b79b406", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|74e6e3a5606550602ce3703e0fe897585be9b2f68509d28ba86ee3628b79b406"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.per_core_batch_size` used but never assigned in __init__"}, "properties": {"repobilityId": 468267, "scanner": "repobility-ast-engine", "fingerprint": "72af5b98719f9f4f04b513d265282c150e2e0623a7d88dcabfb80af053a4b079", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|72af5b98719f9f4f04b513d265282c150e2e0623a7d88dcabfb80af053a4b079"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.backend` used but never assigned in __init__"}, "properties": {"repobilityId": 468266, "scanner": "repobility-ast-engine", "fingerprint": "32273c16d1d342e1629bef628b4e652172ce807bb20cc0abc14ec7e4d0dd4c13", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|32273c16d1d342e1629bef628b4e652172ce807bb20cc0abc14ec7e4d0dd4c13"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self._median_index` used but never assigned in __init__"}, "properties": {"repobilityId": 468265, "scanner": "repobility-ast-engine", "fingerprint": "59b5018d9b469cf6eafd9b9bdd20d8ca65ba30dd3efbcaecfa3eeb9b0609293b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|59b5018d9b469cf6eafd9b9bdd20d8ca65ba30dd3efbcaecfa3eeb9b0609293b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 92}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self._train_state` used but never assigned in __init__"}, "properties": {"repobilityId": 468264, "scanner": "repobility-ast-engine", "fingerprint": "04f6ca0f765312c0729edefe815c3692c8db57e3c086a4094f8a101e1ef197e6", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|04f6ca0f765312c0729edefe815c3692c8db57e3c086a4094f8a101e1ef197e6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 91}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self._model` used but never assigned in __init__"}, "properties": {"repobilityId": 468263, "scanner": "repobility-ast-engine", "fingerprint": "7f882a33fcd385d822c0638bec7df8c953c5ec930d77e18afd154a3ff22d7cf6", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7f882a33fcd385d822c0638bec7df8c953c5ec930d77e18afd154a3ff22d7cf6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 90}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self._pmapped_decode` used but never assigned in __init__"}, "properties": {"repobilityId": 468262, "scanner": "repobility-ast-engine", "fingerprint": "d0fea7d4970f216561b346e928245afa118694aa0192c095850b70a35943ab5d", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d0fea7d4970f216561b346e928245afa118694aa0192c095850b70a35943ab5d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 89}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self._eval_context` used but never assigned in __init__"}, "properties": {"repobilityId": 468261, "scanner": "repobility-ast-engine", "fingerprint": "0e7aa237e46da2c25c6aab0332e206360f1eda77faf89a42b5e2c3b6962ed4ef", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|0e7aa237e46da2c25c6aab0332e206360f1eda77faf89a42b5e2c3b6962ed4ef"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 88}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.global_batch_size` used but never assigned in __init__"}, "properties": {"repobilityId": 468260, "scanner": "repobility-ast-engine", "fingerprint": "b9f9431394edac78121ad2d5fa41a9f540170461db4bff33eeeb1e1a0f21427b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|b9f9431394edac78121ad2d5fa41a9f540170461db4bff33eeeb1e1a0f21427b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.num_cores` used but never assigned in __init__"}, "properties": {"repobilityId": 468259, "scanner": "repobility-ast-engine", "fingerprint": "ac78d397cf5a3996f36ea35e242eb2fc3e1b6576b91e427daa2530dc976eb3fc", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|ac78d397cf5a3996f36ea35e242eb2fc3e1b6576b91e427daa2530dc976eb3fc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.output_patch_len` used but never assigned in __init__"}, "properties": {"repobilityId": 468258, "scanner": "repobility-ast-engine", "fingerprint": "9c6f030add7ee844cecf177c1d6cbdc343482ae2a7b6b3eb0298869391ab07c7", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|9c6f030add7ee844cecf177c1d6cbdc343482ae2a7b6b3eb0298869391ab07c7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 71}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.context_len` used but never assigned in __init__"}, "properties": {"repobilityId": 468257, "scanner": "repobility-ast-engine", "fingerprint": "57d9d0a078c85a89f39dda3c1eb961a1913ae760705d4cbdbc762ad8139735c5", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|57d9d0a078c85a89f39dda3c1eb961a1913ae760705d4cbdbc762ad8139735c5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 71}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.output_patch_len` used but never assigned in __init__"}, "properties": {"repobilityId": 468256, "scanner": "repobility-ast-engine", "fingerprint": "e597027e3a8232cab139e488cc6b3e46067abe31a6a8a03b6b1a102ad4839e1c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e597027e3a8232cab139e488cc6b3e46067abe31a6a8a03b6b1a102ad4839e1c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 63}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.context_len` used but never assigned in __init__"}, "properties": {"repobilityId": 468255, "scanner": "repobility-ast-engine", "fingerprint": "06aa860f8fd93c8f45fb05d64d0fe7c1d1707daabefd1fa6b21677772b5391aa", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|06aa860f8fd93c8f45fb05d64d0fe7c1d1707daabefd1fa6b21677772b5391aa"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 63}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.per_core_batch_size` used but never assigned in __init__"}, "properties": {"repobilityId": 468254, "scanner": "repobility-ast-engine", "fingerprint": "84eb3e31c0abf7871d01c6a819db22c786ff225830c6a83fd110804fc95b660d", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|84eb3e31c0abf7871d01c6a819db22c786ff225830c6a83fd110804fc95b660d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 78}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.per_core_batch_size` used but never assigned in __init__"}, "properties": {"repobilityId": 468253, "scanner": "repobility-ast-engine", "fingerprint": "c07cd9115aba1ed819e9900f82fbbaf518c8f334b1fe5255940d46f2daa33f58", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|c07cd9115aba1ed819e9900f82fbbaf518c8f334b1fe5255940d46f2daa33f58"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 70}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.per_core_batch_size` used but never assigned in __init__"}, "properties": {"repobilityId": 468252, "scanner": "repobility-ast-engine", "fingerprint": "126db2db7d652e4855be282cb93114ce09919eb55459325b2ebb0445d4f5c32c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|126db2db7d652e4855be282cb93114ce09919eb55459325b2ebb0445d4f5c32c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_jax.py"}, "region": {"startLine": 62}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.core_layer` used but never assigned in __init__"}, "properties": {"repobilityId": 468251, "scanner": "repobility-ast-engine", "fingerprint": "9078c38b492b3499d69cf54b2c432b69fd1462588c7e72e9a91562f006e7ba40", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|9078c38b492b3499d69cf54b2c432b69fd1462588c7e72e9a91562f006e7ba40"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py"}, "region": {"startLine": 538}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.do_eval` used but never assigned in __init__"}, "properties": {"repobilityId": 468250, "scanner": "repobility-ast-engine", "fingerprint": "6b72be6103fd201c12762fc1c59bf0ce7c9321dd4b36103271e7e1a625644c0a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6b72be6103fd201c12762fc1c59bf0ce7c9321dd4b36103271e7e1a625644c0a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py"}, "region": {"startLine": 342}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.stacked_transformer_layer` used but never assigned in __init__"}, "properties": {"repobilityId": 468249, "scanner": "repobility-ast-engine", "fingerprint": "8bfeca27ad741b3525dd0dd3dbe43ec074b7793131c3e5bdff14efaeed3cf97a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|8bfeca27ad741b3525dd0dd3dbe43ec074b7793131c3e5bdff14efaeed3cf97a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py"}, "region": {"startLine": 291}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.test_lens` used but never assigned in __init__"}, "properties": {"repobilityId": 468248, "scanner": "repobility-ast-engine", "fingerprint": "de8d6cd72e3d41421a598e8a8bb8ca4d54f2b052fe860cf525fce8dcea6b743b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|de8d6cd72e3d41421a598e8a8bb8ca4d54f2b052fe860cf525fce8dcea6b743b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/xreg_lib.py"}, "region": {"startLine": 450}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.train_lens` used but never assigned in __init__"}, "properties": {"repobilityId": 468247, "scanner": "repobility-ast-engine", "fingerprint": "6f4c154f1fb4a5f9ae9f9ca796c1e7b3ae90700402d49fd6f8e5dc3fdbd17f3e", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6f4c154f1fb4a5f9ae9f9ca796c1e7b3ae90700402d49fd6f8e5dc3fdbd17f3e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/xreg_lib.py"}, "region": {"startLine": 450}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_single_non_nan_fills_all_gaps"}, "properties": {"repobilityId": 468244, "scanner": "repobility-ast-engine", "fingerprint": "04dc26b3ea6703a268a52188f4612530644e6c4403d578dde4cbfcc63cc3aaf8", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|04dc26b3ea6703a268a52188f4612530644e6c4403d578dde4cbfcc63cc3aaf8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 163}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_preserves_non_nan_values"}, "properties": {"repobilityId": 468243, "scanner": "repobility-ast-engine", "fingerprint": "007685b8218f0e13574e2d272966df069bf43324ce41db5b8d2e915cb607b90e", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|007685b8218f0e13574e2d272966df069bf43324ce41db5b8d2e915cb607b90e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 144}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_extrapolates_leading_nans"}, "properties": {"repobilityId": 468242, "scanner": "repobility-ast-engine", "fingerprint": "41eb931184350a4e888fdfa655ab3d514be8a654ae183203499eb767b957b9ac", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|41eb931184350a4e888fdfa655ab3d514be8a654ae183203499eb767b957b9ac"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 128}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_extrapolates_trailing_nans"}, "properties": {"repobilityId": 468241, "scanner": "repobility-ast-engine", "fingerprint": "f8b3ab5b6e144b12fc06146e94c965e3b9570bfff56d467d9bb9de4d7b1b4f0a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f8b3ab5b6e144b12fc06146e94c965e3b9570bfff56d467d9bb9de4d7b1b4f0a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 120}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_interpolates_multiple_interior_nans"}, "properties": {"repobilityId": 468240, "scanner": "repobility-ast-engine", "fingerprint": "39ea7b5e8519460a4bddb193c7e3886bb76bd08c90a2e8ce590a184ba194ae23", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|39ea7b5e8519460a4bddb193c7e3886bb76bd08c90a2e8ce590a184ba194ae23"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 114}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_interpolates_single_interior_nan"}, "properties": {"repobilityId": 468239, "scanner": "repobility-ast-engine", "fingerprint": "eab934f2df58589e2559d1d2db3ec6f6e6dd2a3501b26d54cdb5432178fb6f6e", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|eab934f2df58589e2559d1d2db3ec6f6e6dd2a3501b26d54cdb5432178fb6f6e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 108}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_no_nans_returns_identical"}, "properties": {"repobilityId": 468238, "scanner": "repobility-ast-engine", "fingerprint": "d94a59c05166f3d176c41f1204b6a377369b8e9fff6ab285a94be97848851ada", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d94a59c05166f3d176c41f1204b6a377369b8e9fff6ab285a94be97848851ada"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_single_valid_element"}, "properties": {"repobilityId": 468237, "scanner": "repobility-ast-engine", "fingerprint": "4eedddbb2722b70f74f7bd553448576bce06b83952723e95a011bc7e97add8c2", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|4eedddbb2722b70f74f7bd553448576bce06b83952723e95a011bc7e97add8c2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_no_leading_nan_with_internal_nans"}, "properties": {"repobilityId": 468236, "scanner": "repobility-ast-engine", "fingerprint": "3d4d96060bf32a6719ae6e488b3922cf9348b9cfc4522a4e55d72f7ddd2f306b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|3d4d96060bf32a6719ae6e488b3922cf9348b9cfc4522a4e55d72f7ddd2f306b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_single_leading_nan"}, "properties": {"repobilityId": 468235, "scanner": "repobility-ast-engine", "fingerprint": "f6dc61671a36cb6acf33660d34ee7b503ba81f3fed5f844d49a79de9a8b9a6b8", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f6dc61671a36cb6acf33660d34ee7b503ba81f3fed5f844d49a79de9a8b9a6b8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 53}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_strips_leading_nans_only"}, "properties": {"repobilityId": 468234, "scanner": "repobility-ast-engine", "fingerprint": "aa0bfeb5fcf7d07995e287842d0aae7602944ddb634657b1da7741db739b16c4", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|aa0bfeb5fcf7d07995e287842d0aae7602944ddb634657b1da7741db739b16c4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_no_nans_returns_unchanged"}, "properties": {"repobilityId": 468233, "scanner": "repobility-ast-engine", "fingerprint": "bf8a2e0d4dcc6a6249f99efb3cd359c51a1e766766aa648e11894e56fdb16bae", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|bf8a2e0d4dcc6a6249f99efb3cd359c51a1e766766aa648e11894e56fdb16bae"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_base_utils.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_negative_values_handled_correctly"}, "properties": {"repobilityId": 468232, "scanner": "repobility-ast-engine", "fingerprint": "6806da314adb19d283c6bcb468634a1216517b908ea2f9d6987b496b70432ffe", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6806da314adb19d283c6bcb468634a1216517b908ea2f9d6987b496b70432ffe"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 289}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_roundtrip_with_batched_4d_input"}, "properties": {"repobilityId": 468231, "scanner": "repobility-ast-engine", "fingerprint": "596acc03bdc96d49fe0ee2a2516a3bfc7ba33850d2ef70e68d698bac95de372b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|596acc03bdc96d49fe0ee2a2516a3bfc7ba33850d2ef70e68d698bac95de372b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 270}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_roundtrip_with_batched_3d_input"}, "properties": {"repobilityId": 468230, "scanner": "repobility-ast-engine", "fingerprint": "e8d19922ff68ebd0f4e0d581aee45be20db4ebeae776de0fe8af51d5de3612d3", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e8d19922ff68ebd0f4e0d581aee45be20db4ebeae776de0fe8af51d5de3612d3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 257}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_reverse_produces_correct_denormalization"}, "properties": {"repobilityId": 468229, "scanner": "repobility-ast-engine", "fingerprint": "1fab6b13626357bd7885fb35bf390c830a48d08ec194b4cc9de6bbb7b977d17c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1fab6b13626357bd7885fb35bf390c830a48d08ec194b4cc9de6bbb7b977d17c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 217}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_forward_produces_correct_normalization"}, "properties": {"repobilityId": 468228, "scanner": "repobility-ast-engine", "fingerprint": "1697df63bdf660b394792463143712f25829da13acd501936789f546d6e44f65", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1697df63bdf660b394792463143712f25829da13acd501936789f546d6e44f65"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 206}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_forward_then_reverse_is_identity"}, "properties": {"repobilityId": 468227, "scanner": "repobility-ast-engine", "fingerprint": "42ad47b873afa16e7eb8141949623ecab824c8423a960e8c92b097431019dec0", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|42ad47b873afa16e7eb8141949623ecab824c8423a960e8c92b097431019dec0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_utils.py"}, "region": {"startLine": 189}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_unit_scale_preserves_rms_magnitude"}, "properties": {"repobilityId": 468226, "scanner": "repobility-ast-engine", "fingerprint": "c868778691f4445338e690d02a263519ec6a6f73326fb2fa0cbdb9ce0b711e2f", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|c868778691f4445338e690d02a263519ec6a6f73326fb2fa0cbdb9ce0b711e2f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_layers.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_zero_scale_produces_zeros"}, "properties": {"repobilityId": 468225, "scanner": "repobility-ast-engine", "fingerprint": "75301190cf22d4402f4512a207284b34fea9e077dd1430c03cebe6bc15b168cd", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|75301190cf22d4402f4512a207284b34fea9e077dd1430c03cebe6bc15b168cd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_layers.py"}, "region": {"startLine": 160}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_residual_connection_nonzero"}, "properties": {"repobilityId": 468224, "scanner": "repobility-ast-engine", "fingerprint": "16710b8ea88a2568e94d896349882b853076f6a8f6c49b9ec271b288810e08b1", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|16710b8ea88a2568e94d896349882b853076f6a8f6c49b9ec271b288810e08b1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/test_torch_layers.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "GHSA-53q9-r3pm-6pq6", "level": "error", "message": {"text": "torch: GHSA-53q9-r3pm-6pq6"}, "properties": {"repobilityId": 468425, "scanner": "osv-scanner", "fingerprint": "f356dc2f982d4fa0c3f05fd9d295a771e1c5629e39d9b6e432e3bf7e1417eb2f", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pytorch-2025-32434", "CVE-2025-32434", "PYSEC-2025-41"], "package": "torch", "rule_id": "GHSA-53q9-r3pm-6pq6", "scanner": "osv-scanner", "correlation_key": "vuln|torch|CVE-2025-32434|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-53q9-r3pm-6pq6", "PYSEC-2025-41"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["15e588b290cb0abe518654ff1939b2be9b99d60ca926b83ea0df116bda1cd3d0", "f356dc2f982d4fa0c3f05fd9d295a771e1c5629e39d9b6e432e3bf7e1417eb2f"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gw97-ff7c-9v96", "level": "error", "message": {"text": "tensorflow: GHSA-gw97-ff7c-9v96"}, "properties": {"repobilityId": 468411, "scanner": "osv-scanner", "fingerprint": "4ebc9500c61853dc239a5042b8141be4ab38f45c31ddc61a2817c7c6e7ff1a6e", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-tensorflow-2023-25668", "CVE-2023-25668"], "package": "tensorflow", "rule_id": "GHSA-gw97-ff7c-9v96", "scanner": "osv-scanner", "correlation_key": "vuln|tensorflow|CVE-2023-25668|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7p94-766c-hgjp", "level": "error", "message": {"text": "nltk: GHSA-7p94-766c-hgjp"}, "properties": {"repobilityId": 468367, "scanner": "osv-scanner", "fingerprint": "ab10b631f4579d1ced2e8a7df745e4c74f9b8a76b341202a06212a1e659b26e3", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2025-14009", "PYSEC-2026-96"], "package": "nltk", "rule_id": "GHSA-7p94-766c-hgjp", "scanner": "osv-scanner", "correlation_key": "vuln|nltk|CVE-2025-14009|v1/poetry.lock", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-7p94-766c-hgjp", "PYSEC-2026-96"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["ab10b631f4579d1ced2e8a7df745e4c74f9b8a76b341202a06212a1e659b26e3", "c066f56e96bfbfb697457fc0be229e41c193a0b88f8744c7f4f85caa1a5d82ae"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-x4wf-678h-2pmq", "level": "error", "message": {"text": "keras: GHSA-x4wf-678h-2pmq"}, "properties": {"repobilityId": 468356, "scanner": "osv-scanner", "fingerprint": "1b9e3e324191362599ac36842dcf7830f105a07f1f428f7bf15a763560eacf8c", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2024-3660"], "package": "keras", "rule_id": "GHSA-x4wf-678h-2pmq", "scanner": "osv-scanner", "correlation_key": "vuln|keras|CVE-2024-3660|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fcw5-x6j4-ccmp", "level": "error", "message": {"text": "jupyter-server: GHSA-fcw5-x6j4-ccmp"}, "properties": {"repobilityId": 468345, "scanner": "osv-scanner", "fingerprint": "6be468dc597090885f9abf1ebd2e73b95d2165b893b55568bbd5e90e7004e0b5", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44727"], "package": "jupyter-server", "rule_id": "GHSA-fcw5-x6j4-ccmp", "scanner": "osv-scanner", "correlation_key": "vuln|jupyter-server|CVE-2026-44727|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vqfr-h8mv-ghfj", "level": "error", "message": {"text": "h11: GHSA-vqfr-h8mv-ghfj"}, "properties": {"repobilityId": 468337, "scanner": "osv-scanner", "fingerprint": "7010dc4352d46a92f1f70827896d4fd7b5370db160113cf14eba190037aa6e8c", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-43859"], "package": "h11", "rule_id": "GHSA-vqfr-h8mv-ghfj", "scanner": "osv-scanner", "correlation_key": "vuln|h11|CVE-2025-43859|v1/poetry.lock"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/poetry.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `stat` used but not imported"}, "properties": {"repobilityId": 468276, "scanner": "repobility-ast-engine", "fingerprint": "f037ad0bb5a1d717329e804afa99abdc4f19715e3397d0d07214191836296e2d", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f037ad0bb5a1d717329e804afa99abdc4f19715e3397d0d07214191836296e2d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 164}}}]}, {"ruleId": "scanner-7df3594de8cc900b", "level": "note", "message": {"text": "Possibly dead Python function: train_step"}, "properties": {"repobilityId": "594d3bcf55940ace", "scanner": "scanner-primary", "fingerprint": "7df3594de8cc900b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/peft/finetune.py:305"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da72af9cd4033f74", "level": "note", "message": {"text": "Possibly dead Python function: eval_step"}, "properties": {"repobilityId": "8e57720037f2b9fd", "scanner": "scanner-primary", "fingerprint": "da72af9cd4033f74", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/peft/finetune.py:308"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f36d94d2d16c6e2", "level": "note", "message": {"text": "Possibly dead Python function: load_adapter_checkpoint"}, "properties": {"repobilityId": "7dfc89a2e0f03ef0", "scanner": "scanner-primary", "fingerprint": "9f36d94d2d16c6e2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/adapter/utils.py:101"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b71aa8cd115d609", "level": "note", "message": {"text": "Possibly dead Python function: setup_process"}, "properties": {"repobilityId": "8baff27f23697fe7", "scanner": "scanner-primary", "fingerprint": "5b71aa8cd115d609", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/finetuning/finetuning_example.py:300"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0ef42c9e7fb53dd", "level": "note", "message": {"text": "Possibly dead Python function: shift_row"}, "properties": {"repobilityId": "dcdf2f1f3eee0823", "scanner": "scanner-primary", "fingerprint": "b0ef42c9e7fb53dd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py:71"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87aef4dd05079e9e", "level": "note", "message": {"text": "Possibly dead Python function: compute_predictions"}, "properties": {"repobilityId": "4677300e386e265c", "scanner": "scanner-primary", "fingerprint": "87aef4dd05079e9e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py:496"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8c107af86428755e", "level": "note", "message": {"text": "Possibly dead Python function: compute_loss"}, "properties": {"repobilityId": "70b270f82fffe454", "scanner": "scanner-primary", "fingerprint": "8c107af86428755e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/patched_decoder.py:532"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-222b152ee4f5c376", "level": "note", "message": {"text": "Possibly dead Python function: forecast_with_covariates"}, "properties": {"repobilityId": "caf2189620fca7d0", "scanner": "scanner-primary", "fingerprint": "222b152ee4f5c376", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/timesfm_base.py:429"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76e094a098db4ad8", "level": "note", "message": {"text": "Possibly dead Python function: apply_mask_to_logits"}, "properties": {"repobilityId": "c5fe442e87385319", "scanner": "scanner-primary", "fingerprint": "76e094a098db4ad8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/pytorch_patched_decoder.py:155"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28fce836053b755c", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "28fce836053b755c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/src/timesfm/pytorch_patched_decoder.py:694"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50ef2a48425110cf", "level": "note", "message": {"text": "Possibly dead Python function: cross_validation"}, "properties": {"repobilityId": "bf247519b39349ec", "scanner": "scanner-primary", "fingerprint": "50ef2a48425110cf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/baselines/timegpt_pipeline.py:98"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7aaf64cc1e22ba12", "level": "note", "message": {"text": "Possibly dead Python function: parallel_transform"}, "properties": {"repobilityId": "94bf0cb68e039d78", "scanner": "scanner-primary", "fingerprint": "7aaf64cc1e22ba12", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/utils.py:36"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d681765b1cb937e7", "level": "note", "message": {"text": "Possibly dead Python function: save_results"}, "properties": {"repobilityId": "1c06222f2aedee2c", "scanner": "scanner-primary", "fingerprint": "d681765b1cb937e7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/utils.py:180"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-088e7eb6f1ddea80", "level": "note", "message": {"text": "Possibly dead Python function: evaluate_models"}, "properties": {"repobilityId": "6c13ae32c0379c13", "scanner": "scanner-primary", "fingerprint": "088e7eb6f1ddea80", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "v1/experiments/extended_benchmarks/utils.py:213"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e34785475171e0c7", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "e34785475171e0c7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/torch/normalization.py:35"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56f770233f5053c8", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "56f770233f5053c8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/torch/dense.py:84"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a26ac96ee385c857", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "a26ac96ee385c857", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/torch/transformer.py:354"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-26f453677d5dd3ec", "level": "note", "message": {"text": "Possibly dead Python function: scan_along_axis"}, "properties": {"repobilityId": "5c35b0f2e442545f", "scanner": "scanner-primary", "fingerprint": "26f453677d5dd3ec", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/flax/util.py:80"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5232df71255e1f87", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "5232df71255e1f87", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/timesfm_2p5/timesfm_2p5_torch.py:93"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42986388389a64a3", "level": "note", "message": {"text": "Possibly dead Python function: forecast_with_covariates"}, "properties": {"repobilityId": "caf2189620fca7d0", "scanner": "scanner-primary", "fingerprint": "42986388389a64a3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/timesfm/timesfm_2p5/timesfm_2p5_base.py:198"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fb8c38d0921783a", "level": "warning", "message": {"text": "eval detected \u2014 v1/experiments/long_horizon_benchmarks/run_eval.py:238"}, "properties": {"repobilityId": "c6e24bf6cdd9114f", "scanner": "scanner-primary", "fingerprint": "0fb8c38d0921783a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-ff1c2606dbebc21d", "level": "warning", "message": {"text": "CVE-2025-68146: filelock 3.19.1 \u2014 requirements.txt"}, "properties": {"repobilityId": "b4d4bf035f139d09", "scanner": "scanner-primary", "fingerprint": "ff1c2606dbebc21d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68146"]}}, {"ruleId": "scanner-2eba7a0e1868876e", "level": "warning", "message": {"text": "CVE-2026-22701: filelock 3.19.1 \u2014 requirements.txt"}, "properties": {"repobilityId": "55dfb4a08f42f961", "scanner": "scanner-primary", "fingerprint": "2eba7a0e1868876e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22701"]}}, {"ruleId": "scanner-dc35d3a43c2ac75c", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 requirements.txt"}, "properties": {"repobilityId": "dd2a72ad411bff63", "scanner": "scanner-primary", "fingerprint": "dc35d3a43c2ac75c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-ec730f875f7d02a5", "level": "warning", "message": {"text": "GHSA-gj48-438w-jh9v: bleach 6.2.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "ee2d08e2dcc39863", "scanner": "scanner-primary", "fingerprint": "ec730f875f7d02a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gj48-438w-jh9v"]}}, {"ruleId": "scanner-d6a08778003f95c2", "level": "note", "message": {"text": "GHSA-8rfp-98v4-mmr6: bleach 6.2.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b559b6dc83fc8c9f", "scanner": "scanner-primary", "fingerprint": "d6a08778003f95c2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8rfp-98v4-mmr6"]}}, {"ruleId": "scanner-7b80ca85e5888f65", "level": "warning", "message": {"text": "CVE-2025-68146: filelock 3.16.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "8d2bc7475332af47", "scanner": "scanner-primary", "fingerprint": "7b80ca85e5888f65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68146"]}}, {"ruleId": "scanner-dddf5504846ce23a", "level": "warning", "message": {"text": "CVE-2026-22701: filelock 3.16.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "00bc1b255912a60a", "scanner": "scanner-primary", "fingerprint": "dddf5504846ce23a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22701"]}}, {"ruleId": "scanner-d43142ff27679603", "level": "warning", "message": {"text": "CVE-2025-66034: fonttools 4.55.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "687d7c1441372d56", "scanner": "scanner-primary", "fingerprint": "d43142ff27679603", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66034"]}}, {"ruleId": "scanner-110d9d4104433a53", "level": "error", "message": {"text": "CVE-2026-42215: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "d2a5af91a3565f53", "scanner": "scanner-primary", "fingerprint": "110d9d4104433a53", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42215"]}}, {"ruleId": "scanner-3e8c1c3d8301bd06", "level": "error", "message": {"text": "CVE-2026-42284: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "bf0e06b34baebbd8", "scanner": "scanner-primary", "fingerprint": "3e8c1c3d8301bd06", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42284"]}}, {"ruleId": "scanner-a26e4272c4f25f6e", "level": "error", "message": {"text": "CVE-2026-44243: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "02b7eeca57e1de99", "scanner": "scanner-primary", "fingerprint": "a26e4272c4f25f6e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44243"]}}, {"ruleId": "scanner-7f98b3a1e68232c1", "level": "error", "message": {"text": "CVE-2026-44244: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "5c5bdf93f10b6bdf", "scanner": "scanner-primary", "fingerprint": "7f98b3a1e68232c1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44244"]}}, {"ruleId": "scanner-7ff355d8c032d630", "level": "error", "message": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.43 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4ced009a4c702306", "scanner": "scanner-primary", "fingerprint": "7ff355d8c032d630", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mv93-w799-cj2w"]}}, {"ruleId": "scanner-0538493fd71233f5", "level": "error", "message": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "123cd6218145db3b", "scanner": "scanner-primary", "fingerprint": "0538493fd71233f5", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-43859"]}}, {"ruleId": "scanner-42c9109efc772f64", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "33a6f8d6849b0ce0", "scanner": "scanner-primary", "fingerprint": "42c9109efc772f64", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-eae311993e2633b5", "level": "warning", "message": {"text": "CVE-2025-27516: jinja2 3.1.5 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "89039c3815a2817a", "scanner": "scanner-primary", "fingerprint": "eae311993e2633b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27516"]}}, {"ruleId": "scanner-39b281082204636e", "level": "error", "message": {"text": "CVE-2025-30167: jupyter-core 5.7.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b51dce25c227dd87", "scanner": "scanner-primary", "fingerprint": "39b281082204636e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-30167"]}}, {"ruleId": "scanner-7cf1bdc96861f491", "level": "error", "message": {"text": "CVE-2026-44727: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "0a09dbb0ec4e3927", "scanner": "scanner-primary", "fingerprint": "7cf1bdc96861f491", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44727"]}}, {"ruleId": "scanner-3a5ac536b350e96d", "level": "error", "message": {"text": "CVE-2026-35397: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "577fa7a69cf159cc", "scanner": "scanner-primary", "fingerprint": "3a5ac536b350e96d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35397"]}}, {"ruleId": "scanner-cd0984c5897a9d58", "level": "error", "message": {"text": "CVE-2026-40110: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "88432e93dd7bba07", "scanner": "scanner-primary", "fingerprint": "cd0984c5897a9d58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40110"]}}, {"ruleId": "scanner-a096a062b809bba0", "level": "error", "message": {"text": "CVE-2026-40934: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "3bb01aacd5c59005", "scanner": "scanner-primary", "fingerprint": "a096a062b809bba0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40934"]}}, {"ruleId": "scanner-7e7f7b69fcb20d34", "level": "warning", "message": {"text": "CVE-2025-61669: jupyter-server 2.15.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "dd21af0b5eada5de", "scanner": "scanner-primary", "fingerprint": "7e7f7b69fcb20d34", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-61669"]}}, {"ruleId": "scanner-e77611419a94e88e", "level": "error", "message": {"text": "CVE-2026-40171: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "c0c7219401f38b7c", "scanner": "scanner-primary", "fingerprint": "e77611419a94e88e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40171"]}}, {"ruleId": "scanner-4691a31a042b9d67", "level": "error", "message": {"text": "CVE-2026-42266: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "6237ea532992da28", "scanner": "scanner-primary", "fingerprint": "4691a31a042b9d67", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42266"]}}, {"ruleId": "scanner-e72c86118dd080d4", "level": "error", "message": {"text": "CVE-2026-42557: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b27df2b8d86687fa", "scanner": "scanner-primary", "fingerprint": "e72c86118dd080d4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42557"]}}, {"ruleId": "scanner-0f5951d4ddaa8ac3", "level": "warning", "message": {"text": "GHSA-vmhf-c436-hxj4: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "6900e3602161eb32", "scanner": "scanner-primary", "fingerprint": "0f5951d4ddaa8ac3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vmhf-c436-hxj4"]}}, {"ruleId": "scanner-c14de822a03e7086", "level": "note", "message": {"text": "CVE-2025-59842: jupyterlab 4.3.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b2ca4bea971a7d49", "scanner": "scanner-primary", "fingerprint": "c14de822a03e7086", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59842"]}}, {"ruleId": "scanner-15a602c47cf46236", "level": "error", "message": {"text": "CVE-2024-3660: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "55a038837875b6ef", "scanner": "scanner-primary", "fingerprint": "15a602c47cf46236", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-3660"]}}, {"ruleId": "scanner-fad1d165e8847b13", "level": "error", "message": {"text": "CVE-2025-12060: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "704fecaa1ff68300", "scanner": "scanner-primary", "fingerprint": "fad1d165e8847b13", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-12060"]}}, {"ruleId": "scanner-31f8995083b20304", "level": "error", "message": {"text": "CVE-2025-9906: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "236b0a255648393e", "scanner": "scanner-primary", "fingerprint": "31f8995083b20304", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-9906"]}}, {"ruleId": "scanner-475114b64805007d", "level": "error", "message": {"text": "CVE-2026-1462: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "32212326608df311", "scanner": "scanner-primary", "fingerprint": "475114b64805007d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1462"]}}, {"ruleId": "scanner-26d67a8d91e266a4", "level": "warning", "message": {"text": "CVE-2024-55459: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "e5a636cf52c2614a", "scanner": "scanner-primary", "fingerprint": "26d67a8d91e266a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-55459"]}}, {"ruleId": "scanner-386a65c7092e6ab9", "level": "warning", "message": {"text": "CVE-2025-12058: keras 2.9.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "804916c7c6022a44", "scanner": "scanner-primary", "fingerprint": "386a65c7092e6ab9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-12058"]}}, {"ruleId": "scanner-58876f81eea9da01", "level": "error", "message": {"text": "CVE-2026-41066: lxml 5.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "836c3cb666ae8b57", "scanner": "scanner-primary", "fingerprint": "58876f81eea9da01", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41066"]}}, {"ruleId": "scanner-5a9ea17a5bad8514", "level": "warning", "message": {"text": "CVE-2025-69534: markdown 3.7 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "a565139ab3b61554", "scanner": "scanner-primary", "fingerprint": "5a9ea17a5bad8514", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69534"]}}, {"ruleId": "scanner-e8834e404efb654a", "level": "error", "message": {"text": "CVE-2026-33079: mistune 3.1.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "daeeb1786a8f8005", "scanner": "scanner-primary", "fingerprint": "e8834e404efb654a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33079"]}}, {"ruleId": "scanner-6eaa415d738eb898", "level": "warning", "message": {"text": "CVE-2026-44708: mistune 3.1.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "cee9cc9d3bc89890", "scanner": "scanner-primary", "fingerprint": "6eaa415d738eb898", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44708"]}}, {"ruleId": "scanner-c2f61bafae433dac", "level": "warning", "message": {"text": "CVE-2026-44896: mistune 3.1.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b37dbf4a298c92a4", "scanner": "scanner-primary", "fingerprint": "c2f61bafae433dac", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44896"]}}, {"ruleId": "scanner-cd4be3e8e9b87b37", "level": "warning", "message": {"text": "CVE-2026-44897: mistune 3.1.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "91be846a7d1d3bd5", "scanner": "scanner-primary", "fingerprint": "cd4be3e8e9b87b37", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44897"]}}, {"ruleId": "scanner-c4edb95a2c0a7b5e", "level": "error", "message": {"text": "CVE-2025-53000: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "053f00bff59c8ebf", "scanner": "scanner-primary", "fingerprint": "c4edb95a2c0a7b5e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53000"]}}, {"ruleId": "scanner-2542516ebc45e1ef", "level": "warning", "message": {"text": "CVE-2026-39377: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "54cce25e9f707195", "scanner": "scanner-primary", "fingerprint": "2542516ebc45e1ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39377"]}}, {"ruleId": "scanner-9d5d6f0b75f2a5da", "level": "warning", "message": {"text": "CVE-2026-39378: nbconvert 7.16.4 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "afcc4bf98fe38447", "scanner": "scanner-primary", "fingerprint": "9d5d6f0b75f2a5da", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39378"]}}, {"ruleId": "scanner-9b0b10871bf6a0e8", "level": "error", "message": {"text": "CVE-2025-14009: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "df3ef5ccce4ccded", "scanner": "scanner-primary", "fingerprint": "9b0b10871bf6a0e8", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-14009"]}}, {"ruleId": "scanner-0eb8755aaadd6ef6", "level": "error", "message": {"text": "CVE-2026-0846: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "6d8c3170767a4828", "scanner": "scanner-primary", "fingerprint": "0eb8755aaadd6ef6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0846"]}}, {"ruleId": "scanner-988004a24fc6bff6", "level": "error", "message": {"text": "CVE-2026-0847: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "501b9172bffd439f", "scanner": "scanner-primary", "fingerprint": "988004a24fc6bff6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0847"]}}, {"ruleId": "scanner-ce123a1ee8d502c9", "level": "error", "message": {"text": "CVE-2026-33231: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "6d1fbea085b0001c", "scanner": "scanner-primary", "fingerprint": "ce123a1ee8d502c9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33231"]}}, {"ruleId": "scanner-6ea2396f55f31f22", "level": "error", "message": {"text": "CVE-2026-33236: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4af1930ca664c114", "scanner": "scanner-primary", "fingerprint": "6ea2396f55f31f22", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33236"]}}, {"ruleId": "scanner-848bfd84523185c0", "level": "error", "message": {"text": "CVE-2026-54293: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "fa4627995a3f1144", "scanner": "scanner-primary", "fingerprint": "848bfd84523185c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54293"]}}, {"ruleId": "scanner-f67e17cbebf1ead4", "level": "warning", "message": {"text": "CVE-2026-33230: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "3c395a9dd1020774", "scanner": "scanner-primary", "fingerprint": "f67e17cbebf1ead4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33230"]}}, {"ruleId": "scanner-0fac83d0f315b0b8", "level": "warning", "message": {"text": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "7dca3d7cac444b19", "scanner": "scanner-primary", "fingerprint": "0fac83d0f315b0b8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rf74-v2fm-23pw"]}}, {"ruleId": "scanner-dddabd5dff039808", "level": "error", "message": {"text": "CVE-2026-40171: notebook 7.3.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "c6773b9240cd3194", "scanner": "scanner-primary", "fingerprint": "dddabd5dff039808", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40171"]}}, {"ruleId": "scanner-418e7d85afe72da3", "level": "error", "message": {"text": "CVE-2026-42557: notebook 7.3.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "9c613e0ac43bf6fb", "scanner": "scanner-primary", "fingerprint": "418e7d85afe72da3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42557"]}}, {"ruleId": "scanner-9b9e912733651081", "level": "error", "message": {"text": "CVE-2026-25990: pillow 11.0.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "86fecfae7e8832ff", "scanner": "scanner-primary", "fingerprint": "9b9e912733651081", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-af8638507e384106", "level": "error", "message": {"text": "CVE-2026-40192: pillow 11.0.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "1961b7340d1f9d69", "scanner": "scanner-primary", "fingerprint": "af8638507e384106", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-824e18a949761323", "level": "error", "message": {"text": "CVE-2026-42311: pillow 11.0.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "0895073c56bc9073", "scanner": "scanner-primary", "fingerprint": "824e18a949761323", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-a14591c92827a925", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 11.0.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "49e94b6125744b05", "scanner": "scanner-primary", "fingerprint": "a14591c92827a925", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-31cb5400987a41e5", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 11.0.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "64443efb2f463ddb", "scanner": "scanner-primary", "fingerprint": "31cb5400987a41e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-5427e02aadb98844", "level": "error", "message": {"text": "CVE-2025-4565: protobuf 3.19.6 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "e768599c5a389332", "scanner": "scanner-primary", "fingerprint": "5427e02aadb98844", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-4565"]}}, {"ruleId": "scanner-aeb578abb70e4e74", "level": "error", "message": {"text": "CVE-2026-0994: protobuf 3.19.6 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "2747b518a83159fe", "scanner": "scanner-primary", "fingerprint": "aeb578abb70e4e74", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0994"]}}, {"ruleId": "scanner-bb1a9065faf94332", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "ad99b8d9193f9ed2", "scanner": "scanner-primary", "fingerprint": "bb1a9065faf94332", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-3932dd3e079edadb", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "80022a35c1d5c2ab", "scanner": "scanner-primary", "fingerprint": "3932dd3e079edadb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-7a52be80d54ce216", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.18.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "3863257c3ec43b23", "scanner": "scanner-primary", "fingerprint": "7a52be80d54ce216", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-5dfba8434ad46938", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "06bc383f0b28384a", "scanner": "scanner-primary", "fingerprint": "5dfba8434ad46938", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-31d3ec140e04bcf0", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "54521f6f2d6bff29", "scanner": "scanner-primary", "fingerprint": "31d3ec140e04bcf0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-30606b52a1e4127f", "level": "error", "message": {"text": "CVE-2026-1260: sentencepiece 0.1.99 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "897ebbfae949e0f2", "scanner": "scanner-primary", "fingerprint": "30606b52a1e4127f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1260"]}}, {"ruleId": "scanner-f2442c63b95ed8b3", "level": "error", "message": {"text": "CVE-2025-47273: setuptools 75.6.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "55cd7ce640c322f3", "scanner": "scanner-primary", "fingerprint": "f2442c63b95ed8b3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-47273"]}}, {"ruleId": "scanner-543b78eb467b16da", "level": "error", "message": {"text": "CVE-2023-25668: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "30d0e87100298967", "scanner": "scanner-primary", "fingerprint": "543b78eb467b16da", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25668"]}}, {"ruleId": "scanner-d0aa1cc52b3e9ef2", "level": "error", "message": {"text": "CVE-2023-25658: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "cd6f368a3dffe652", "scanner": "scanner-primary", "fingerprint": "d0aa1cc52b3e9ef2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25658"]}}, {"ruleId": "scanner-730bc7eab7e7bf8a", "level": "error", "message": {"text": "CVE-2023-25659: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "72c6b0e08b66e472", "scanner": "scanner-primary", "fingerprint": "730bc7eab7e7bf8a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25659"]}}, {"ruleId": "scanner-17f78c000b28a32d", "level": "error", "message": {"text": "CVE-2023-25660: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "85037230ac51b2a3", "scanner": "scanner-primary", "fingerprint": "17f78c000b28a32d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25660"]}}, {"ruleId": "scanner-e08c1be2c27386ad", "level": "error", "message": {"text": "CVE-2023-25662: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "23c3720447f4e3a1", "scanner": "scanner-primary", "fingerprint": "e08c1be2c27386ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25662"]}}, {"ruleId": "scanner-1577115ba886234f", "level": "error", "message": {"text": "CVE-2023-25663: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4ab5668eacf69160", "scanner": "scanner-primary", "fingerprint": "1577115ba886234f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25663"]}}, {"ruleId": "scanner-28bc439177f9e5d0", "level": "error", "message": {"text": "CVE-2023-25664: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "5342b286969eb0fb", "scanner": "scanner-primary", "fingerprint": "28bc439177f9e5d0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25664"]}}, {"ruleId": "scanner-cf714390d1c3fa0e", "level": "error", "message": {"text": "CVE-2023-25665: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "33dbc6f7e9851ec6", "scanner": "scanner-primary", "fingerprint": "cf714390d1c3fa0e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25665"]}}, {"ruleId": "scanner-0c961e7448b46903", "level": "error", "message": {"text": "CVE-2023-25666: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "f44bb01d02f575d5", "scanner": "scanner-primary", "fingerprint": "0c961e7448b46903", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25666"]}}, {"ruleId": "scanner-d866a51890a86c02", "level": "error", "message": {"text": "CVE-2023-25669: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "e94104b130f46c1c", "scanner": "scanner-primary", "fingerprint": "d866a51890a86c02", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25669"]}}, {"ruleId": "scanner-6086cc1d48ecdd09", "level": "error", "message": {"text": "CVE-2023-25670: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "c72a0ef995a094c2", "scanner": "scanner-primary", "fingerprint": "6086cc1d48ecdd09", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25670"]}}, {"ruleId": "scanner-206e917c776795fa", "level": "error", "message": {"text": "CVE-2023-25671: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "45cd7c277b33d076", "scanner": "scanner-primary", "fingerprint": "206e917c776795fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25671"]}}, {"ruleId": "scanner-c71d95778961e6b1", "level": "error", "message": {"text": "CVE-2023-25672: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "794afcbcad7c01ac", "scanner": "scanner-primary", "fingerprint": "c71d95778961e6b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25672"]}}, {"ruleId": "scanner-c04675bbe3852498", "level": "error", "message": {"text": "CVE-2023-25673: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "f37500722d5c3335", "scanner": "scanner-primary", "fingerprint": "c04675bbe3852498", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25673"]}}, {"ruleId": "scanner-cde483787af19d92", "level": "error", "message": {"text": "CVE-2023-25674: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4008926d294b5a52", "scanner": "scanner-primary", "fingerprint": "cde483787af19d92", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25674"]}}, {"ruleId": "scanner-e86d3e1df75db6ad", "level": "error", "message": {"text": "CVE-2023-25675: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "d83a5929bd6175d4", "scanner": "scanner-primary", "fingerprint": "e86d3e1df75db6ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25675"]}}, {"ruleId": "scanner-eaf32f0b4b0ee169", "level": "error", "message": {"text": "CVE-2023-25676: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "3b140dda994edd51", "scanner": "scanner-primary", "fingerprint": "eaf32f0b4b0ee169", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25676"]}}, {"ruleId": "scanner-6dbd94aad0e78da9", "level": "error", "message": {"text": "CVE-2023-25801: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b1809f140e450bbf", "scanner": "scanner-primary", "fingerprint": "6dbd94aad0e78da9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25801"]}}, {"ruleId": "scanner-ddfb59e680931c75", "level": "error", "message": {"text": "CVE-2023-27579: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "7de3c43ff5b0c55e", "scanner": "scanner-primary", "fingerprint": "ddfb59e680931c75", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-27579"]}}, {"ruleId": "scanner-caf34f269203821f", "level": "error", "message": {"text": "CVE-2023-33976: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "90b602de7f46f104", "scanner": "scanner-primary", "fingerprint": "caf34f269203821f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-33976"]}}, {"ruleId": "scanner-58286366d26b6fac", "level": "warning", "message": {"text": "CVE-2023-25661: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "d35b1aad8c778c6b", "scanner": "scanner-primary", "fingerprint": "58286366d26b6fac", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25661"]}}, {"ruleId": "scanner-b94fb4132b8b2f16", "level": "warning", "message": {"text": "CVE-2023-25667: tensorflow 2.9.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "7f098a03c00ad02b", "scanner": "scanner-primary", "fingerprint": "b94fb4132b8b2f16", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-25667"]}}, {"ruleId": "scanner-da709aa9160d6bde", "level": "error", "message": {"text": "CVE-2025-32434: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "0dd8a84ba76b1103", "scanner": "scanner-primary", "fingerprint": "da709aa9160d6bde", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-32434"]}}, {"ruleId": "scanner-8b8b48cbe5104e30", "level": "warning", "message": {"text": "CVE-2025-2998: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "eb0f17151bf8d688", "scanner": "scanner-primary", "fingerprint": "8b8b48cbe5104e30", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2998"]}}, {"ruleId": "scanner-5aacaec15ecec758", "level": "warning", "message": {"text": "CVE-2025-2999: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "950c9e35acaf9324", "scanner": "scanner-primary", "fingerprint": "5aacaec15ecec758", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2999"]}}, {"ruleId": "scanner-73ec09856b52eba4", "level": "warning", "message": {"text": "CVE-2025-3730: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "812cdbb24c56b859", "scanner": "scanner-primary", "fingerprint": "73ec09856b52eba4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3730"]}}, {"ruleId": "scanner-ed5d9f970373af2a", "level": "note", "message": {"text": "CVE-2025-2148: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "7f5545ad80207d48", "scanner": "scanner-primary", "fingerprint": "ed5d9f970373af2a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2148"]}}, {"ruleId": "scanner-742d4f0a9f3dfd0f", "level": "note", "message": {"text": "CVE-2025-2149: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "112fcc740bc0523e", "scanner": "scanner-primary", "fingerprint": "742d4f0a9f3dfd0f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2149"]}}, {"ruleId": "scanner-d22bcd8582937b9d", "level": "note", "message": {"text": "CVE-2025-2953: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "28b626bb900a69b2", "scanner": "scanner-primary", "fingerprint": "d22bcd8582937b9d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2953"]}}, {"ruleId": "scanner-0941d8c03bb1d46b", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "3bbfe8ce933263df", "scanner": "scanner-primary", "fingerprint": "0941d8c03bb1d46b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-90674d052e5bb5e2", "level": "note", "message": {"text": "CVE-2025-3001: torch 2.3.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "c5d630e89824cc93", "scanner": "scanner-primary", "fingerprint": "90674d052e5bb5e2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3001"]}}, {"ruleId": "scanner-f88456f9af31cecd", "level": "error", "message": {"text": "CVE-2025-47287: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "8799857f608450b5", "scanner": "scanner-primary", "fingerprint": "f88456f9af31cecd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-47287"]}}, {"ruleId": "scanner-02ea0143580dc3ab", "level": "error", "message": {"text": "CVE-2026-31958: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4c1de38d3770fbca", "scanner": "scanner-primary", "fingerprint": "02ea0143580dc3ab", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31958"]}}, {"ruleId": "scanner-44f01b6437162c3f", "level": "error", "message": {"text": "CVE-2026-35536: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "116e72be7e16af6a", "scanner": "scanner-primary", "fingerprint": "44f01b6437162c3f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35536"]}}, {"ruleId": "scanner-1c532cd21270d66c", "level": "error", "message": {"text": "CVE-2026-49853: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "62b1a3120261bbec", "scanner": "scanner-primary", "fingerprint": "1c532cd21270d66c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49853"]}}, {"ruleId": "scanner-1e96f81f98b196e9", "level": "error", "message": {"text": "CVE-2026-49855: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "2f5a440ea4cb3766", "scanner": "scanner-primary", "fingerprint": "1e96f81f98b196e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49855"]}}, {"ruleId": "scanner-4a94dce111c0aea0", "level": "warning", "message": {"text": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "34e680a0eee6dcc0", "scanner": "scanner-primary", "fingerprint": "4a94dce111c0aea0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-78cv-mqj4-43f7"]}}, {"ruleId": "scanner-3bf19a2942f3229e", "level": "warning", "message": {"text": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "844c4565bfeee427", "scanner": "scanner-primary", "fingerprint": "3bf19a2942f3229e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pw6j-qg29-8w7f"]}}, {"ruleId": "scanner-c431028d08ffaee0", "level": "note", "message": {"text": "CVE-2026-49854: tornado 6.4.2 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "ee064e2c1c6023ac", "scanner": "scanner-primary", "fingerprint": "c431028d08ffaee0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49854"]}}, {"ruleId": "scanner-9b1f7a1bbe2b0eb8", "level": "error", "message": {"text": "CVE-2024-11392: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "266713e7954ad404", "scanner": "scanner-primary", "fingerprint": "9b1f7a1bbe2b0eb8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11392"]}}, {"ruleId": "scanner-459135fdc7f50e4e", "level": "error", "message": {"text": "CVE-2024-11393: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "ab77ed07a15be436", "scanner": "scanner-primary", "fingerprint": "459135fdc7f50e4e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11393"]}}, {"ruleId": "scanner-679ba6436192b8b9", "level": "error", "message": {"text": "CVE-2024-11394: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "abfd8bb78c506c91", "scanner": "scanner-primary", "fingerprint": "679ba6436192b8b9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11394"]}}, {"ruleId": "scanner-4232853603e9648c", "level": "warning", "message": {"text": "CVE-2024-12720: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "a7b5c5b8082931d3", "scanner": "scanner-primary", "fingerprint": "4232853603e9648c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-12720"]}}, {"ruleId": "scanner-3240e2f1f3e4d625", "level": "warning", "message": {"text": "CVE-2025-1194: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b8cc227ba7249924", "scanner": "scanner-primary", "fingerprint": "3240e2f1f3e4d625", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-1194"]}}, {"ruleId": "scanner-3397c275d7da3f88", "level": "warning", "message": {"text": "CVE-2025-2099: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "20516b9ee4c1cb72", "scanner": "scanner-primary", "fingerprint": "3397c275d7da3f88", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2099"]}}, {"ruleId": "scanner-40c7857468b6d416", "level": "warning", "message": {"text": "CVE-2025-3263: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "59c0b00489e6fb8e", "scanner": "scanner-primary", "fingerprint": "40c7857468b6d416", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3263"]}}, {"ruleId": "scanner-063cb0fa9a6e6eb0", "level": "warning", "message": {"text": "CVE-2025-3264: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "1d29076be7d103a6", "scanner": "scanner-primary", "fingerprint": "063cb0fa9a6e6eb0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3264"]}}, {"ruleId": "scanner-546ae18803e49fa8", "level": "warning", "message": {"text": "CVE-2025-3933: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "0aba9abb02629014", "scanner": "scanner-primary", "fingerprint": "546ae18803e49fa8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3933"]}}, {"ruleId": "scanner-eef4258f32f9ab96", "level": "warning", "message": {"text": "CVE-2025-5197: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "08e685808fde989e", "scanner": "scanner-primary", "fingerprint": "eef4258f32f9ab96", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5197"]}}, {"ruleId": "scanner-e86bc73a6a385634", "level": "warning", "message": {"text": "CVE-2025-6051: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "30d6eb65f552661f", "scanner": "scanner-primary", "fingerprint": "e86bc73a6a385634", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6051"]}}, {"ruleId": "scanner-d303fe7171b8df3d", "level": "warning", "message": {"text": "CVE-2025-6638: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "9023947435357fa9", "scanner": "scanner-primary", "fingerprint": "d303fe7171b8df3d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6638"]}}, {"ruleId": "scanner-8ca37ed0f50ed76f", "level": "warning", "message": {"text": "CVE-2025-6921: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b84ee5d087837ae0", "scanner": "scanner-primary", "fingerprint": "8ca37ed0f50ed76f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6921"]}}, {"ruleId": "scanner-38dd4012c4153154", "level": "warning", "message": {"text": "CVE-2026-1839: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "ee44e826eb6fb681", "scanner": "scanner-primary", "fingerprint": "38dd4012c4153154", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1839"]}}, {"ruleId": "scanner-2b798d6c660b03c3", "level": "note", "message": {"text": "CVE-2025-3777: transformers 4.47.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "5d59faf335541329", "scanner": "scanner-primary", "fingerprint": "2b798d6c660b03c3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3777"]}}, {"ruleId": "scanner-eaed1713eaec6942", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "4c3ee449570f3860", "scanner": "scanner-primary", "fingerprint": "eaed1713eaec6942", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-658f35537a56e3a0", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "b4bde8011bf14e15", "scanner": "scanner-primary", "fingerprint": "658f35537a56e3a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-0ecb04b67a2b4e25", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "7892ae1cb8816558", "scanner": "scanner-primary", "fingerprint": "0ecb04b67a2b4e25", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-78fc6f96fe07ffa9", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "5518ea8a18125c98", "scanner": "scanner-primary", "fingerprint": "78fc6f96fe07ffa9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-3b800bf06ea74cca", "level": "warning", "message": {"text": "CVE-2025-50181: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "11c1878ceeffbb5d", "scanner": "scanner-primary", "fingerprint": "3b800bf06ea74cca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50181"]}}, {"ruleId": "scanner-09c73185fc35d0b7", "level": "warning", "message": {"text": "CVE-2025-50182: urllib3 2.3.0 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "a2aee5b0a55bd17c", "scanner": "scanner-primary", "fingerprint": "09c73185fc35d0b7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50182"]}}, {"ruleId": "scanner-d1daa02b05bbbd04", "level": "warning", "message": {"text": "CVE-2025-66221: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "588be089da484dcd", "scanner": "scanner-primary", "fingerprint": "d1daa02b05bbbd04", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66221"]}}, {"ruleId": "scanner-f205368149e3b947", "level": "warning", "message": {"text": "CVE-2026-21860: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "c3e00796b92c731c", "scanner": "scanner-primary", "fingerprint": "f205368149e3b947", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21860"]}}, {"ruleId": "scanner-94c4b16c2f37b84e", "level": "warning", "message": {"text": "CVE-2026-27199: werkzeug 3.1.3 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "122ab8138acd839e", "scanner": "scanner-primary", "fingerprint": "94c4b16c2f37b84e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27199"]}}, {"ruleId": "scanner-19a7e502337d9cee", "level": "error", "message": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 v1/poetry.lock"}, "properties": {"repobilityId": "9e2cdb22ead39f1f", "scanner": "scanner-primary", "fingerprint": "19a7e502337d9cee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24049"]}}, {"ruleId": "scanner-fb72c7ff8619c129", "level": "warning", "message": {"text": "SkillSpector AST3 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py"}, "properties": {"repobilityId": "9e2e1663569956f6", "scanner": "scanner-primary", "fingerprint": "fb72c7ff8619c129", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST3", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 362}}}]}, {"ruleId": "scanner-4bd828193dddb420", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py"}, "properties": {"repobilityId": "4d7e4803db08f515", "scanner": "scanner-primary", "fingerprint": "4bd828193dddb420", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-4bd828193dddb420", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in timesfm-forecasting/scripts/check_system.py"}, "properties": {"repobilityId": "4d7e4803db08f515", "scanner": "scanner-primary", "fingerprint": "4bd828193dddb420", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 186}}}]}, {"ruleId": "scanner-c933cc54cd6d3611", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in timesfm-forecasting/SKILL.md"}, "properties": {"repobilityId": "b7717f0b2343f47b", "scanner": "scanner-primary", "fingerprint": "c933cc54cd6d3611", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e8473e5186e0dbdf", "level": "warning", "message": {"text": "SkillSpector EA4 (excessive-agency) in timesfm-forecasting/examples/global-temperature/generate_gif.py"}, "properties": {"repobilityId": "f73ecf817fb1f607", "scanner": "scanner-primary", "fingerprint": "e8473e5186e0dbdf", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/generate_gif.py"}, "region": {"startLine": 238}}}]}, {"ruleId": "scanner-a73c6fc796a6b2cf", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in timesfm-forecasting/scripts/check_system.py"}, "properties": {"repobilityId": "0c5d5deefa2e1585", "scanner": "scanner-primary", "fingerprint": "a73c6fc796a6b2cf", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-a73c6fc796a6b2cf", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in timesfm-forecasting/scripts/check_system.py"}, "properties": {"repobilityId": "0c5d5deefa2e1585", "scanner": "scanner-primary", "fingerprint": "a73c6fc796a6b2cf", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/check_system.py"}, "region": {"startLine": 186}}}]}, {"ruleId": "scanner-e92e28bc852e45e5", "level": "error", "message": {"text": "SkillSpector SC6 (supply-chain) in timesfm-forecasting/references/system_requirements.md"}, "properties": {"repobilityId": "779bb2f7a61e718b", "scanner": "scanner-primary", "fingerprint": "e92e28bc852e45e5", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/references/system_requirements.md"}, "region": {"startLine": 210}}}]}, {"ruleId": "scanner-a943cdefbb0a95ff", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/anomaly-detection/output/anomaly_detection.png"}, "properties": {"repobilityId": "7f580bbb6d0930d4", "scanner": "scanner-primary", "fingerprint": "a943cdefbb0a95ff", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/anomaly-detection/output/anomaly_detection.png"}, "region": {"startLine": 1433}}}]}, {"ruleId": "scanner-893abace1e43f248", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "properties": {"repobilityId": "4a3edfc657ecec56", "scanner": "scanner-primary", "fingerprint": "893abace1e43f248", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "region": {"startLine": 170}}}]}, {"ruleId": "scanner-893abace1e43f248", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "properties": {"repobilityId": "4a3edfc657ecec56", "scanner": "scanner-primary", "fingerprint": "893abace1e43f248", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "region": {"startLine": 1225}}}]}, {"ruleId": "scanner-5a077ab375871ef6", "level": "error", "message": {"text": "SkillSpector TM2 (tool-misuse) in timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "properties": {"repobilityId": "2db15cef9725400c", "scanner": "scanner-primary", "fingerprint": "5a077ab375871ef6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/covariates-forecasting/output/covariates_data.png"}, "region": {"startLine": 1045}}}]}, {"ruleId": "scanner-7cc71d3b6de8d7d2", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "properties": {"repobilityId": "13efeb3bd322adf3", "scanner": "scanner-primary", "fingerprint": "7cc71d3b6de8d7d2", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "region": {"startLine": 416}}}]}, {"ruleId": "scanner-7cc71d3b6de8d7d2", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "properties": {"repobilityId": "13efeb3bd322adf3", "scanner": "scanner-primary", "fingerprint": "7cc71d3b6de8d7d2", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "region": {"startLine": 520}}}]}, {"ruleId": "scanner-7cc71d3b6de8d7d2", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "properties": {"repobilityId": "13efeb3bd322adf3", "scanner": "scanner-primary", "fingerprint": "7cc71d3b6de8d7d2", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "region": {"startLine": 801}}}]}, {"ruleId": "scanner-7cc71d3b6de8d7d2", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "properties": {"repobilityId": "13efeb3bd322adf3", "scanner": "scanner-primary", "fingerprint": "7cc71d3b6de8d7d2", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "region": {"startLine": 1081}}}]}, {"ruleId": "scanner-7cc71d3b6de8d7d2", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "properties": {"repobilityId": "13efeb3bd322adf3", "scanner": "scanner-primary", "fingerprint": "7cc71d3b6de8d7d2", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_animation.gif"}, "region": {"startLine": 4495}}}]}, {"ruleId": "scanner-42a46725d4cf9146", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/examples/global-temperature/output/forecast_visualization.png"}, "properties": {"repobilityId": "d84fed01d553349d", "scanner": "scanner-primary", "fingerprint": "42a46725d4cf9146", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/examples/global-temperature/output/forecast_visualization.png"}, "region": {"startLine": 1051}}}]}, {"ruleId": "scanner-6962a2c713a7a100", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/scripts/forecast_csv.py"}, "properties": {"repobilityId": "b3752fc2f3a891b0", "scanner": "scanner-primary", "fingerprint": "6962a2c713a7a100", "layer": "security", "severity": "high", "confidence": 0.7999999999999999, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/forecast_csv.py"}, "region": {"startLine": 225}}}]}, {"ruleId": "scanner-6962a2c713a7a100", "level": "error", "message": {"text": "SkillSpector TM1 (tool-misuse) in timesfm-forecasting/scripts/forecast_csv.py"}, "properties": {"repobilityId": "b3752fc2f3a891b0", "scanner": "scanner-primary", "fingerprint": "6962a2c713a7a100", "layer": "security", "severity": "high", "confidence": 0.7999999999999999, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "timesfm-forecasting/scripts/forecast_csv.py"}, "region": {"startLine": 247}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-1d7e834080dbebed", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "78217f23d2a126a9", "scanner": "scanner-primary", "fingerprint": "1d7e834080dbebed", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-ba465e5a103a61e1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b8df75024cd00b3b", "scanner": "scanner-primary", "fingerprint": "ba465e5a103a61e1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/manual_publish.yml"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "77563d7862d769bc", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "f5be7f8d573f1164", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "530d0d687cd6279c", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-c71125b1d464b26f", "level": "note", "message": {"text": "Legacy-named symbol `test_replace_creates_independent_copy` in tests/test_configs.py:73"}, "properties": {"repobilityId": "16a313b6a312f9a8", "scanner": "scanner-primary", "fingerprint": "c71125b1d464b26f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3a79e576eb7aafa2", "level": "note", "message": {"text": "Legacy-named symbol `context_dict_v2` in v1/experiments/extended_benchmarks/run_timesfm.py:58"}, "properties": {"repobilityId": "90feaffc50ff5492", "scanner": "scanner-primary", "fingerprint": "3a79e576eb7aafa2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f0c38d0f551b7418", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/scripts/check_system.py:138"}, "properties": {"repobilityId": "de40a92dd5ea256d", "scanner": "scanner-primary", "fingerprint": "f0c38d0f551b7418", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ad13e05a5afd8d91", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 timesfm-forecasting/examples/covariates-forecasting/demo_covariates.py:22"}, "properties": {"repobilityId": "d9f714645e39de04", "scanner": "scanner-primary", "fingerprint": "ad13e05a5afd8d91", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1aeca319ac7a8120", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/timesfm/utils/xreg_lib.py:480"}, "properties": {"repobilityId": "909dbfbb60e88432", "scanner": "scanner-primary", "fingerprint": "1aeca319ac7a8120", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-33a6b62e30ce7ab4", "level": "note", "message": {"text": "Near-duplicate function bodies in 6 places"}, "properties": {"repobilityId": "737298bdd0c7c350", "scanner": "scanner-primary", "fingerprint": "33a6b62e30ce7ab4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "78fea7f72b5363de", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "cfbc0c9c05e50314", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "da900e08dbccbbcd", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "bdc620e7478bed6c", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "8ee437040d0eb085", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "0b2516e3f4038788", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-76a2f6818267a9a8", "level": "note", "message": {"text": "Near-duplicate function bodies in 8 places"}, "properties": {"repobilityId": "563226e79a674495", "scanner": "scanner-primary", "fingerprint": "76a2f6818267a9a8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "7727a91d6a90a92c", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "31c049cb759abc15", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "1348092a539e5cf6", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "ade40026f17a3539", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "6eaeee328a1ab2b9", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "87fc81fcf61fec11", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "156344fe2519a029", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}]}]}