High rhodium-standard-repositories/examples/rhodium-minimal/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in rhodium-standar
High flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in flake.nix
High k9-svc/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/flake.ni
High k9-svc/actions/validate/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/actions/
High k9-svc/editors/vscode/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/editors/
High k9-svc/pandoc/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/pandoc/f
High k9-svc/bindings/deno/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/bindings
High k9-svc/bindings/rust/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/bindings
High k9-svc/bindings/haskell/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in k9-svc/bindings
High a2ml/actions/validate/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/actions/va
High a2ml/editors/vscode/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/editors/vs
High a2ml/pandoc/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/pandoc/fla
High a2ml/bindings/deno/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/bindings/d
High a2ml/bindings/rust/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/bindings/r
High a2ml/bindings/haskell/flake.nix:? flake.nix declares inputs without narHash, rev pinning, or sibling flake.lock — dependency revision is unpinned in a2ml/bindings/h
panic-attack estate sweep — Track C tracking issue
panic-attack assailflagged the findings below in this repo on 2026-05-26. They are aggregated here for human triage rather than as individual PRs because each requires judgement (supply-chain pin choice, schema-design call, mutation-test gap, etc.).PA001/PA007 UnsafeCode/UnsafeFFI findings are NOT in this list. Findings already suppressed in
audits/assail-classifications.a2mlare also excluded.Estate tracker: hyperpolymath/panic-attack#32.
CommandInjection(6 findings)file:line list
file:line list
file:line list
file:line list
🤖 Discovered during the panic-attack estate sweep (2026-05-26). See hyperpolymath/panic-attack#32 for campaign tracker.