Skip to content

rl-protect comment testing - #3

Open
tpericin wants to merge 40 commits into
mainfrom
pr-test-1
Open

rl-protect comment testing#3
tpericin wants to merge 40 commits into
mainfrom
pr-test-1

Conversation

@tpericin

@tpericin tpericin commented May 3, 2026

Copy link
Copy Markdown
Owner

No description provided.

@github-actions

github-actions Bot commented May 3, 2026

Copy link
Copy Markdown

Spectra Assure Community Scan: ❌ FAIL

Scanned: requirements.txt — 4 rejected · 1 warning

Package Status Assessment
📦 pkg:pypi/pillow@8.0.0 ❌ REJECT ❌ 1 patch mandated vulnerabilities
📦 pkg:pypi/cryptography@3.0 ❌ REJECT ❌ 2 severe vulnerabilities exploited
📦 pkg:pypi/lightning@2.5.0 ❌ REJECT ❌ 2 severe vulnerabilities exploited
📦 pkg:pypi/scrapy@2.15.2 ❌ REJECT ❌ 2 severe vulnerabilities exploited
📦 pkg:pypi/requests@2.25.0 ⚠️ WARN ⚠️ 5 high severity vulnerabilities

@github-actions

github-actions Bot commented May 14, 2026

Copy link
Copy Markdown

Spectra Assure Community Scan: ❌ FAIL

Scanned: projects/package.json — 3 rejected · 1 warning · 54 passed

❌ Rejected packages

📦 pkg:npm/axios@0.30.4 — REJECT (1 of 3) [REMOVED]

📅 Released 4 months ago
⚖️ Permissive (MIT)

Caution

Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain

Caution

SAFE Assessment
❌ Malware: 3 supply chain attack artifacts

Warning

SAFE Assessment
⚠️ Vulnerabilities: 8 severe vulnerabilities exploited

Vulnerabilities: 🔴 1 critical · 🟠 8 high · 🟡 8 medium · 🔵 1 low

CVE/GHSA CVSS Summary Signals
CVE-2026-42043 🔴 10.00 Axios is vulnerable to a NO_PROXY protection bypass via RFC 1122 loopback subnet (127.0.0.0/8) due to an incomplete fix for CVE-2025-62718. ⚡ exploit
CVE-2026-44492 🟠 8.60 Axios does not properly normalize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass. ⚡ exploit
CVE-2026-44487 🟠 8.20 Axios's Node.js HTTP adapter may leak Proxy-Authorization credentials to the origin server during specific proxy-to-direct redirect flows. ⚡ exploit
CVE-2026-42038 🟠 7.50 Axios is vulnerable to a no_proxy bypass, allowing SSRF attacks due to incomplete hostname normalization. ⚡ exploit
CVE-2026-44486 🟠 7.50 Axios leaks proxy credentials to a redirect target when using an authenticated proxy configuration with automatic redirects enabled. ⚡ exploit

and 13 more vulnerabilities — see full report →

Full report →


📦 pkg:npm/plain-crypto-js@4.2.1 — REJECT (2 of 3) [REMOVED] [QUARANTINED]
  🔗 axios@0.30.4 → plain-crypto-js@4.2.1

📅 Released 4 months ago
⚖️ Permissive (MIT)

Caution

Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Text.PUA.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain
🛑 Threat detected: Script-JS.Downloader.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain

Caution

SAFE Assessment
❌ Tampering: 1 quarantined components found
❌ Malware: 4 supply chain attack artifacts

Full report →


📦 pkg:npm/qs@6.15.3 — REJECT (3 of 3)
  🔗 express@5.2.1 → qs@6.15.3 (2 paths)

📅 Released 1 month ago
⚖️ Permissive (BSD-3-Clause)

Caution

Policy violations
❌ TH17127 — Detected presence of files containing URLs that link to raw files on GitHub.

Full report →


Repository owner deleted a comment from github-actions Bot May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant