New version: Excelano.xshape version 0.3.0 - #414647
New version: Excelano.xshape version 0.3.0#414647David M. Anderson (anderix) wants to merge 1 commit into
Conversation
|
Validation Pipeline Run WinGetSvc-Validation-149-414647-20260810-1 |
|
Thanks for running validation on this one. I believe this is another false positive and I'd like to submit it to the Defender team, but the failure on run 385607 didn't publish a detection name or a security intelligence version, and the submission form requires the detection name. Could you post the 'Manual Validation ended with' detail, or the detection name and intel version on their own? I'll open the submission the same day and report the ID back here. Before asking, I re-verified the bytes. The archive the validator fetched, the SHA-256 in this manifest, and the SHA-256 published on the release all agree: File: xshape-x86_64-pc-windows-msvc.zip So nothing here is a mismatch or a stale URL, and I won't be rebuilding or re-tagging the release — whatever hash gets submitted needs to be the hash the analysis runs against. For context, this package has been through this once already. Excelano.xshape 0.1.0 (#406097) was flagged Trojan:Win32/Sprisky.U!cl, went to the Defender team as submission 36c9af76-ca6f-4abe-a024-bdacc7d8afc1, and came back with the detection removed; that PR merged on 2026-08-07. My reading of that outcome is that the removal was scoped to the hash that was submitted rather than to the detection name, so 0.3.0 is new bytes and doesn't inherit it. I'm expecting to file a fresh submission rather than asking you to treat the earlier one as covering this — I just need the detection name to do it. xshape is an open-source CSV/DSV reshaping CLI, built in public CI from https://github.com/excelano/xshape with cargo-dist. The flagged binary is an unsigned Rust executable that reads a delimited file and writes a restructured one: no network I/O, no persistence, no process injection. Sibling packages from the identical pipeline cleared validation this week — Excelano.paxc 3.8.2 (#414645) and Excelano.xled 0.7.0 (#414646) both merged on 2026-08-10. Mainly flagging this so the PR doesn't age out on the feedback clock while I'm waiting on the detection detail. Thanks for staying with it. |
Pull request has been created with komac v2.16.0 🚀
Microsoft Reviewers: Open in CodeFlow