Skip to content

multiple manifests - #2

Closed
tpericin wants to merge 24 commits into
mainfrom
pr-test-1
Closed

multiple manifests#2
tpericin wants to merge 24 commits into
mainfrom
pr-test-1

Conversation

@tpericin

@tpericin tpericin commented May 3, 2026

Copy link
Copy Markdown
Owner

No description provided.

@github-actions

github-actions Bot commented May 3, 2026

Copy link
Copy Markdown

Spectra Assure Community Scan: ❌ FAIL

Scanned: requirements.txt — 3 rejected · 2 warnings

❌ Rejected packages

📦 pkg:pypi/lightning@2.6.3 — REJECT (1 of 3) [REMOVED]

📅 Released 3 days ago

Caution

Malware
🛑 Threat detected: Archive-ZIP.Trojan.SupplyChain
🛑 Threat detected: Script-JS.Trojan.ShaiWorm

Caution

Assessment
❌ Malware: 1 analyst-vetted malware found

Warning

Assessment
⚠️ Vulnerabilities: 1 severe vulnerabilities exploited † overridden from FAIL by rl-protect

Vulnerabilities: 🟠 1 high

CVE/GHSA CVSS Summary Signals
CVE-2024-8020 🟠 7.50 PyTorch Lightning is vulnerable to a denial of service via unexpected POST requests to the /api/v1/state endpoint. ⚡ exploit

Policy violations: ❌ 2 failed · ⚠️ 1 warning

Policy Description Count
SQ30110 ❌ Detected presence of malicious files through file reputation or third-party scanners. 1
SQ30109 ❌ Detected presence of malicious files through analyst-vetted file reputation. 1
SQ31102 ⚠️ Detected presence of severe vulnerabilities with active exploitation.
† overridden from FAIL by rl-protect
1

Full report →


📦 pkg:pypi/pillow@8.0.0 — REJECT (2 of 3)

📅 Released 5 years ago

Caution

Assessment
❌ Vulnerabilities: 1 patch mandated vulnerabilities

Vulnerabilities: 🔴 5 critical · 🟠 24 high · 🟡 16 medium

CVE/GHSA CVSS Summary Signals
CVE-2022-37434 🔴 9.80 zlib has a heap-based buffer over-read or buffer overflow in inflate via a large gzip header extra field. ⚡ exploit
CVE-2023-50447 🔴 9.30 Pillow allows arbitrary code execution via the environment parameter in PIL.ImageMath.eval. ⚡ exploit
CVE-2023-4863 🟠 8.80 Google Chrome's libwebp is vulnerable to a heap buffer overflow, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page. ⚡ exploit
📋 mandate
☠️ malware
CVE-2022-3970 🟠 8.80 LibTIFF's TIFFReadRGBATileExt function is vulnerable to integer overflow, allowing remote exploitation. ⚡ exploit
CVE-2021-23437 🟠 8.70 Pillow is vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. ⚡ exploit

and 40 more vulnerabilities — see full report →

Policy violations: ❌ 4 failed

Policy Description Count
SQ31104 ❌ Detected presence of critical severity vulnerabilities. 2
SQ31102 ❌ Detected presence of severe vulnerabilities with active exploitation. 2
SQ31103 ❌ Detected presence of malware-exploited vulnerabilities. 1
SQ31101 ❌ Detected presence of patch mandated vulnerabilities. 1

Full report →


📦 pkg:pypi/cryptography@3.0 — REJECT (3 of 3)

📅 Released 5 years ago

Warning

Assessment
⚠️ Vulnerabilities: 2 severe vulnerabilities exploited † overridden from FAIL by rl-protect

Vulnerabilities: 🔴 2 critical · 🟠 12 high · 🟡 15 medium

CVE/GHSA CVSS Summary Signals
CVE-2024-5535 🔴 9.10 OpenSSL's SSL_select_next_proto function may cause a crash or memory contents to be sent to the peer when called with an empty supported client protocols buffer. ⚡ exploit
CVE-2022-0778 🟠 7.50 OpenSSL's BN_mod_sqrt function contains a bug that can cause an infinite loop when parsing certificates with invalid explicit curve parameters, leading to a denial of service attack. ⚡ exploit
CVE-2023-23931 🟡 6.90 Cryptography's Cipher.update_into function allows mutation of immutable objects, violating Python rules. ⚡ exploit
CVE-2021-3449 🟡 5.90 OpenSSL TLS server may crash due to a NULL pointer dereference when handling a maliciously crafted renegotiation ClientHello message. ⚡ exploit
CVE-2021-3711 🔴 9.80 OpenSSL's EVP_PKEY_decrypt function is vulnerable to a buffer overflow when decrypting SM2 encrypted data, potentially allowing an attacker to alter application behavior or cause a crash.

and 24 more vulnerabilities — see full report →

Policy violations: ❌ 1 failed · ⚠️ 1 warning

Policy Description Count
SQ31104 ❌ Detected presence of critical severity vulnerabilities. 1
SQ31102 ⚠️ Detected presence of severe vulnerabilities with active exploitation.
† overridden from FAIL by rl-protect
1

Full report →


@github-actions

github-actions Bot commented May 3, 2026

Copy link
Copy Markdown

Spectra Assure Community Scan: ❌ FAIL

Scanned: package.json — 8 rejected · 6 warnings

❌ Rejected packages

📦 pkg:npm/plain-crypto-js@4.2.1 — REJECT (1 of 8) [REMOVED]
  🔗 axios@0.30.4 → plain-crypto-js@4.2.1

📅 Released 1 month ago
⚖️ Permissive (MIT)

Caution

Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain
🛑 Threat detected: Script-JS.Downloader.SupplyChain
🛑 Threat detected: Text.PUA.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain

Caution

Governance
🚫 Blocked by governance: Package published 34 day(s) ago

Caution

Assessment
❌ Malware: 4 analyst-vetted malware found

Full report →


📦 pkg:npm/axios@0.30.4 — REJECT (2 of 8) [REMOVED]

📅 Released 1 month ago
⚖️ Permissive (MIT)

Caution

Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain

Caution

Assessment
❌ Malware: 3 analyst-vetted malware found

Full report →


📦 pkg:npm/ua-parser-js@0.7.29 — REJECT (3 of 8) [REMOVED]

📅 Released 4 years ago

Caution

Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Script-Shell.Downloader.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain
🛑 Threat detected: Script-JS.Downloader.SupplyChain
🛑 Threat detected: Script-BAT.Downloader.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain

Caution

Assessment
❌ Malware: 6 supply chain attack artifacts
❌ Tampering: 1 malware-like behaviors found

Warning

Assessment
⚠️ Vulnerabilities: 1 high severity vulnerabilities

Vulnerabilities: 🟠 1 high

CVE/GHSA CVSS Summary Signals
CVE-2021-4229 🟠 8.80 ua-parser-js contains a backdoor in its crypto mining component, allowing for potential malicious activity.

Full report →


📦 pkg:npm/express@4.18.2 — REJECT (4 of 8)

📅 Released 3 years ago
⚖️ Permissive (MIT)

Caution

Assessment
❌ Vulnerabilities: 1 severe vulnerabilities exploited

Vulnerabilities: 🟠 3 high · 🟡 4 medium · 🔵 3 low

CVE/GHSA CVSS Summary Signals
CVE-2024-45590 🟠 8.70 body-parser is vulnerable to denial of service when url encoding is enabled, allowing a malicious actor to flood the server with a large number of requests. ⚡ exploit
CVE-2025-15284 🟡 6.30 qs is vulnerable to a denial-of-service attack via memory exhaustion due to improper input validation in its bracket notation. ⚡ exploit
CVE-2026-2391 🟡 6.30 qs is vulnerable to Denial of Service (DoS) via memory exhaustion due to a bypass of the array limit enforcement when the comma option is enabled. ⚡ exploit
CVE-2024-45296 🟠 7.70 path-to-regexp is vulnerable to a Regular Expression Denial of Service (ReDoS) due to inefficient regular expression patterns.
CVE-2024-52798 🟠 7.70 path-to-regexp is vulnerable to a regular expression denial of service (ReDoS) due to incomplete fix for CVE-2024-45296.

and 5 more vulnerabilities — see full report →

Full report →


📦 pkg:npm/lodash@4.17.20 — REJECT (5 of 8)

📅 Released 5 years ago
⚖️ Permissive (MIT)

Caution

Assessment
❌ Vulnerabilities: 1 severe vulnerabilities exploited

Vulnerabilities: 🟠 1 high · 🟡 2 medium

CVE/GHSA CVSS Summary Signals
CVE-2021-23337 🟠 7.20 Lodash is vulnerable to Command Injection via the template function. ⚡ exploit
CVE-2020-28500 🟡 5.30 Lodash is vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. ⚡ exploit
CVE-2025-13465 🟡 6.90 Lodash is vulnerable to prototype pollution in the _.unset and _.omit functions.

Full report →


Important

3 more rejected packages
📦 pkg:npm/moment@2.29.1 — ❌ Vulnerabilities: 2 severe vulnerabilities exploited
📦 pkg:npm/vue@0.8.6 — ❌ Repository: Caution: Package removed!
📦 pkg:npm/body-parser@1.20.1 — ❌ Vulnerabilities: 1 severe vulnerabilities exploited
  🔗 express@4.18.2 → body-parser@1.20.1


⚠️ Scan Warnings

Packages with issues that did not meet the rejection threshold.

📦 pkg:npm/path-to-regexp@0.1.7 — WARN (1 of 6)
  🔗 express@4.18.2 → path-to-regexp@0.1.7

📅 Released 10 years ago
⚖️ Permissive (MIT)

Warning

Assessment
⚠️ Vulnerabilities: 3 high severity vulnerabilities

Vulnerabilities: 🟠 3 high

CVE/GHSA CVSS Summary Signals
CVE-2024-45296 🟠 7.70 path-to-regexp is vulnerable to a Regular Expression Denial of Service (ReDoS) due to inefficient regular expression patterns.
CVE-2024-52798 🟠 7.70 path-to-regexp is vulnerable to a regular expression denial of service (ReDoS) due to incomplete fix for CVE-2024-45296.
CVE-2026-4867 🟠 7.50 path-to-regexp is vulnerable to Regular Expression Denial of Service via multiple route parameters, allowing for catastrophic backtracking.

Full report →


📦 pkg:npm/cookie@0.5.0 — WARN (2 of 6)
  🔗 express@4.18.2 → cookie@0.5.0

📅 Released 4 years ago
⚖️ Permissive (MIT)

Warning

Assessment
⚠️ Vulnerabilities: 1 medium severity vulnerabilities

Vulnerabilities: 🟡 1 medium

CVE/GHSA CVSS Summary Signals
CVE-2024-47764 🟡 6.90 Cookie, an HTTP cookie parser and serializer for HTTP servers, is vulnerable to unexpected cookie values due to inadequate validation of name, path, and domain fields.

Full report →


📦 pkg:npm/qs@6.11.0 — WARN (3 of 6)
  🔗 express@4.18.2 → qs@6.11.0

📅 Released 3 years ago
⚖️ Permissive (BSD-3-Clause)

Warning

Assessment
⚠️ Vulnerabilities: 2 medium severity vulnerabilities

Vulnerabilities: 🟡 2 medium

CVE/GHSA CVSS Summary Signals
CVE-2025-15284 🟡 6.30 qs is vulnerable to a denial-of-service attack via memory exhaustion due to improper input validation in its bracket notation. ⚡ exploit
CVE-2026-2391 🟡 6.30 qs is vulnerable to Denial of Service (DoS) via memory exhaustion due to a bypass of the array limit enforcement when the comma option is enabled. ⚡ exploit

Full report →


📦 pkg:npm/node-fetch@2.6.1 — WARN (4 of 6)

📅 Released 5 years ago
⚖️ Permissive (MIT)

Warning

Assessment
⚠️ Vulnerabilities: 1 medium severity vulnerabilities

Vulnerabilities: 🟡 1 medium

CVE/GHSA CVSS Summary Signals
CVE-2022-0235 🟡 6.10 node-fetch exposes sensitive information to an unauthorized actor when forwarding secure headers during redirects. ⚡ exploit

Full report →


📦 pkg:npm/send@0.18.0 — WARN (5 of 6)
  🔗 express@4.18.2 → send@0.18.0

📅 Released 4 years ago
⚖️ Permissive (MIT)

Warning

Assessment
⚠️ Vulnerabilities: 1 low severity vulnerabilities

Vulnerabilities: 🔵 1 low

CVE/GHSA CVSS Summary Signals
CVE-2024-43799 🔵 2.30 Send library is vulnerable to code execution due to passing untrusted user input to SendStream.redirect.

Full report →


Important

1 more warning
📦 pkg:npm/serve-static@1.15.0⚠️ Vulnerabilities: 2 low severity vulnerabilities
  🔗 express@4.18.2 → serve-static@1.15.0

@github-actions

github-actions Bot commented May 3, 2026

Copy link
Copy Markdown

Spectra Assure Community Scan: ❌ FAIL

Scanned: projects/package.json — 1 warning


⚠️ Scan Warnings

Packages with issues that did not meet the rejection threshold.

📦 pkg:npm/debug@4.4.3 — WARN (1 of 1)
  🔗 express@5.2.1 → debug@4.4.3 (4 paths)

📅 Released 7 months ago
⚖️ Permissive (MIT)

Assessment Result
Malware ✅ No evidence of malware inclusion
Tampering ⚠️ 1 components with malware history
Vulnerabilities ✅ No known vulnerabilities detected
Secrets ✅ No sensitive information found
Hardening ✅ No application hardening issues
Licenses ✅ No license compliance issues

Full report →


@tpericin tpericin closed this May 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant