-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
digestDaily digest reportDaily digest report
Description
Daily Digest: 2026-02-18
CI Failures
| Repo | Workflow | Failed At | Link |
|---|---|---|---|
| anombyte93/perplexity-api-simple | CI | 2026-02-18 23:33:51 | View |
| anombyte93/FleetLeaseFlow | CI | 2026-02-18 07:14:51 | View |
PRs Awaiting Review
- anombyte93/atlas-session-lifecycle — #12 feat: complete productization — landing page, Stripe, Cline marketplace, PyPI workflow by @anombyte93
- anombyte93/atlas-session-lifecycle — #11 feat: comprehensive test suite + hostile testing + /sync skill by @anombyte93
New Issues
- anombyte93/atlas-session-lifecycle — #57 [Review] GOVERNANCE_CACHE written to world-writable /tmp
- anombyte93/atlas-session-lifecycle — #56 [Review] Incomplete shell metacharacter blocklist in verifier.py
- anombyte93/atlas-session-lifecycle — #55 [Review] Stripe webhook: license activated before signature verification completes
- anombyte93/atlas-session-lifecycle — #54 [Review] Path traversal: _resolve_project_dir performs no boundary check
- anombyte93/atlas-session-lifecycle — #53 [Review] Hardcoded HMAC secret in license.py and stripe_client.py
- anombyte93/atlas-session-lifecycle — #52 [Review] Cancelled subscriptions are not revoked — webhook no-ops
- anombyte93/atlas-session-lifecycle — #51 [Review] mtime fallback silently bypasses HMAC verification
- anombyte93/atlas-session-lifecycle — #50 [Review] Hardcoded HMAC secret — license validation trivially bypassable
- anombyte93/atlas-session-lifecycle — #49 [Review]
_run_file_exists()allows path traversal via contract criteria - anombyte93/atlas-session-lifecycle — #48 [Review]
_resolve_project_dir()is a stub — path traversal guard not implemented - anombyte93/atlas-session-lifecycle — #47 [Review]
handle_checkout_completed()writes unsigned cache, enabling mtime bypass - anombyte93/atlas-session-lifecycle — #46 [Review] HMAC validation silently bypassed via legacy mtime fallback
- anombyte93/atlas-session-lifecycle — #45 [Review] Hardcoded HMAC secret — license tokens trivially forgeable
- anombyte93/atlas-session-lifecycle — #44 [Review] Path traversal in FILE_EXISTS criterion — no containment check
- anombyte93/atlas-session-lifecycle — #43 [Review] Backward-compat mtime fallback re-introduces the exact bypass HMAC was meant to prevent
- anombyte93/atlas-session-lifecycle — #42 [Review] Hardcoded HMAC secret makes license tokens forgeable
- anombyte93/atlas-session-lifecycle — #41 [Review] Path traversal in FILE_EXISTS criterion — unsanitised user path escapes project_dir
- anombyte93/atlas-session-lifecycle — #40 [Review] Hardcoded HMAC secret — license tokens are forgeable
- anombyte93/atlas-session-lifecycle — #39 [Review] _resolve_project_dir is dead code — path validation never applied
- anombyte93/atlas-session-lifecycle — #38 [Review] Temp file created at module import time — never cleaned up
- anombyte93/atlas-session-lifecycle — #37 [Review] Stripe cache inconsistency — webhook touch() breaks license validation
- anombyte93/atlas-session-lifecycle — #36 [Review] Command allowlist bypass via absolute binary path
- anombyte93/atlas-session-lifecycle — #35 [Review] Path traversal in _run_file_exists — leaks filesystem information
- anombyte93/atlas-session-lifecycle — #34 [Review] Symlink attack on fixed /tmp governance cache path
- anombyte93/atlas-session-lifecycle — #33 [Review] URL path injection via unencoded bounty_id
- anombyte93/atlas-session-lifecycle — #32 [Review] SSRF via unvalidated ATLASCOIN_URL environment variable
- anombyte93/atlas-session-lifecycle — #31 [Review] Hardcoded HMAC secret — license forgery possible
- anombyte93/atlas-session-lifecycle — #30 [Review] World-readable temp file stores governance data in /tmp
- anombyte93/atlas-session-lifecycle — #29 [Review] Path traversal in contract_create — project_dir not validated
- anombyte93/atlas-session-lifecycle — #28 [Review] Shell metacharacter regex misses newline and $() injection
- anombyte93/atlas-session-lifecycle — #27 [Review] Webhook signature verification accepts string, not raw bytes
- anombyte93/atlas-session-lifecycle — #26 [Review] Hardcoded HMAC secret breaks all license signing
- anombyte93/atlas-session-lifecycle — #25 [Review] Temp file created at module-import time and never cleaned up
- anombyte93/atlas-session-lifecycle — #24 [Review] Hardcoded HMAC secret in license.py
- anombyte93/atlas-session-lifecycle — #23 [Review] Unrestricted shell command execution via contract criteria
- anombyte93/atlas-session-lifecycle — #22 [Review] No project_dir validation — path traversal and arbitrary file write
- anombyte93/atlas-session-lifecycle — #21 [Review] install.sh injects unvalidated GitHub API response into inline Python code
- anombyte93/atlas-session-lifecycle — #20 [Review] Predictable /tmp governance cache path — symlink/TOCTOU attack
- anombyte93/atlas-session-lifecycle — #19 [Review] Shell injection via GitHub API response interpolated into Python -c
- anombyte93/atlas-session-lifecycle — #18 [Review] Curl-pipe-bash installer with no integrity verification
- anombyte93/atlas-session-lifecycle — #17 [Review] Sensitive data written to world-readable /tmp with predictable filename
- anombyte93/atlas-session-lifecycle — #16 [Review] License validity determined by file mtime — trivially bypassed
- anombyte93/atlas-session-lifecycle — #15 [Review] Stripe webhook signature bypass via payload re-encoding
- anombyte93/atlas-session-lifecycle — #14 [Review] Path traversal in all project_dir file operations
- anombyte93/atlas-session-lifecycle — #13 [Review] Arbitrary shell command execution via MCP tool parameter
Activity Summary
- Repos with activity: 5
- Total workflow runs: 68
- Total PRs: 17
- Total issues: 45
Repos Without CI
- anombyte93/Hermes-AHK
Generated by copilot
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
digestDaily digest reportDaily digest report