Skip to content

New version: Excelano.xshape version 0.3.0 - #414647

Open
David M. Anderson (anderix) wants to merge 1 commit into
microsoft:masterfrom
anderix:Excelano.xshape-0.3.0-54B97B800D0D42ACA66468D62BD8DC4F
Open

New version: Excelano.xshape version 0.3.0#414647
David M. Anderson (anderix) wants to merge 1 commit into
microsoft:masterfrom
anderix:Excelano.xshape-0.3.0-54B97B800D0D42ACA66468D62BD8DC4F

Conversation

@anderix

@anderix David M. Anderson (anderix) commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Pull request has been created with komac v2.16.0 🚀

Microsoft Reviewers: Open in CodeFlow

@wingetbot

Copy link
Copy Markdown
Collaborator

Validation Pipeline Run WinGetSvc-Validation-149-414647-20260810-1

@anderix

Copy link
Copy Markdown
Contributor Author

Thanks for running validation on this one. I believe this is another false positive and I'd like to submit it to the Defender team, but the failure on run 385607 didn't publish a detection name or a security intelligence version, and the submission form requires the detection name. Could you post the 'Manual Validation ended with' detail, or the detection name and intel version on their own? I'll open the submission the same day and report the ID back here.

Before asking, I re-verified the bytes. The archive the validator fetched, the SHA-256 in this manifest, and the SHA-256 published on the release all agree:

File: xshape-x86_64-pc-windows-msvc.zip
SHA-256: D24EFE5B7E3D104E3A8AE7EBFC3AA4350BCF9DF2355517AF745747C5936945DB
Source: https://github.com/excelano/xshape/releases/tag/v0.3.0

So nothing here is a mismatch or a stale URL, and I won't be rebuilding or re-tagging the release — whatever hash gets submitted needs to be the hash the analysis runs against.

For context, this package has been through this once already. Excelano.xshape 0.1.0 (#406097) was flagged Trojan:Win32/Sprisky.U!cl, went to the Defender team as submission 36c9af76-ca6f-4abe-a024-bdacc7d8afc1, and came back with the detection removed; that PR merged on 2026-08-07. My reading of that outcome is that the removal was scoped to the hash that was submitted rather than to the detection name, so 0.3.0 is new bytes and doesn't inherit it. I'm expecting to file a fresh submission rather than asking you to treat the earlier one as covering this — I just need the detection name to do it.

xshape is an open-source CSV/DSV reshaping CLI, built in public CI from https://github.com/excelano/xshape with cargo-dist. The flagged binary is an unsigned Rust executable that reads a delimited file and writes a restructured one: no network I/O, no persistence, no process injection. Sibling packages from the identical pipeline cleared validation this week — Excelano.paxc 3.8.2 (#414645) and Excelano.xled 0.7.0 (#414646) both merged on 2026-08-10.

Mainly flagging this so the PR doesn't age out on the feedback clock while I'm waiting on the detection detail. Thanks for staying with it.

@microsoft-github-policy-service microsoft-github-policy-service Bot added Needs-Attention This work item needs to be reviewed by a member of the core team. and removed Needs-Author-Feedback This needs a response from the author. labels Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Needs-Attention This work item needs to be reviewed by a member of the core team. New-Manifest Validation-Defender-Error Validation-Guide Something happened during validation. Provide the guide.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants