You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Lookback: 2026-07-20 → 2026-07-27 | Commits: 328 (106 security-signal) | Open scanning alerts: 4 | Open security issues: 45
The repository is operationally active with strong SDLC controls. The highest-priority unresolved risks are: (1) unpatched Critical/High CVEs in deployed container images with no upstream fix yet, and (2) open Sighthound CWE-78 command-injection findings that require formal review/dismissal against existing #nosec justifications. No secret exposure, no evidence of supply-chain compromise.
Query actually uses variables (-f login=+owner via gh CLI), not raw interpolation; fmt.Sprintf only in nearby logging lines; likely false positive requiring dismissal
scripts/ensure-docs-slide-pdf.js network-to-file
B
CodeQL medium alert open since June 2026; review and dismiss or fix
MCP gateway / auth token scope
B
Recently hardened; env forwarding deliberate; no active exploit signal
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
Lookback: 2026-07-20 → 2026-07-27 | Commits: 328 (106 security-signal) | Open scanning alerts: 4 | Open security issues: 45
The repository is operationally active with strong SDLC controls. The highest-priority unresolved risks are: (1) unpatched Critical/High CVEs in deployed container images with no upstream fix yet, and (2) open Sighthound CWE-78 command-injection findings that require formal review/dismissal against existing
#nosecjustifications. No secret exposure, no evidence of supply-chain compromise.Asset Graph Summary (Recent-Change Scoped)
pkg/cli/— CLI commandsactions/setup/js/— MCP gateway / safe-outputs.github/workflows/— CI/CDscripts/ensure-docs-slide-pdf.jspkg/)Tier Classification Table
pkg/cli/CWE-78 exec.Command findings#nosec G204with written justifications; requires formal review and either dismissal or remediation-f login=+owner via gh CLI), not raw interpolation;fmt.Sprintfonly in nearby logging lines; likely false positive requiring dismissalscripts/ensure-docs-slide-pdf.jsnetwork-to-fileControl Verification
@dsyme@eaftan@pelikhan@krzysztof-cieslak.github/zizmor.yml), PR review activeupgrade_command.go), audit trails in workflow runsRisk Scoring Table
Scores 1–5 (5 = highest risk). Overall = mean.
Remediation Queue
#noseccoverage#nosec G204justifications; dismiss with documented rationale or fixscripts/ensure-docs-slide-pdf.js:149Exception Register
Operational Metrics Baseline
@dsyme@eaftan@pelikhan@krzysztof-cieslakNext Actions
pkg/cli/with documented#nosecrationale audit — see Issue #aw_cwe78_auditscripts/ensure-docs-slide-pdf.jsReferences:
All reactions