cargo / gnostr-legit
gnostr-legit 970378.1846.81338
- processes
- 698
- operations
- 535K
- packages
- 676
- compiler runs
- 4,986
- connections
- 2
- job time
- 9m 24s
- capture
- 3.3 MB
- records
- 785K
- bytes / record
- 4.2
add proof of work to a git commit
Release 970378.1846.81338 run 8c9e2d54-cf2a-4e1d-8577-157b66fcacaf · built 2026-10-07
Artifact
- gnostr-legitbinary · retained · product 29
- libgnostr_legit.rlibfile · retained · product
| Checks | Detections |
|---|---|
| Build behavior | |
| ▲ Network activity | — |
| ▲ Sensitive data access and transfer | — |
| ✓ Cross-process access | — |
| ✓ Build file changes | — |
| ▲ Build script activity | — |
| ✓ Data flow analysis | — |
| ✓ Filesystem writes | — |
| ✓ Context collection | — |
| Supply chain | |
| ▲ Known vulnerabilities | — |
| ▲ Build-time dependency advisories | — |
| ▲ Dependency advisories | — |
| ✓ Declared and observed dependencies | — |
| ✓ Dependency and toolchain versions | — |
| Pipeline | |
| ✓ Pipeline coverage | — |
Detections
3-
highCredential store read by build-time codeCredential store read by build-time code that does not own it: /home/runner/.netrc
-
highBuild code opened a network connectionconnection to github.com:443, opened by git-remote-http
-
mediumBuild script ran gitTool invocations: 10. Build script: /home/runner/work/gnostr/gnostr/target/release/build/gnostr-grammar-6774b8e99f755627/build-script-build
Network
2 peers-
flaggedgithub.com:443 GitHub, Inc.
-
allowedstatic.crates.io:8080
| Vulnerable dependencies29 | Package | Version | Fix | Severity | Title | Reach |
|---|---|---|---|---|---|---|
| CVE-2021-38195 | libsecp256k1 | 0.3.5 | >=0.5.0 | critical | Overflow in libsecp256k1 | retained |
| GHSA-jp3w-3q88-34cf | rust-crypto | 0.2.36 | none published | critical | Miscomputation when performing AES encryption in rust-crypto | retained |
| RUSTSEC-2026-0204 | crossbeam-epoch | 0.9.18 | >=0.9.20 | high | Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid | retained |
| CVE-2026-40034 | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules | retained |
| GHSA-fr8x-3vfx-f45h | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository | retained |
| GHSA-p3hw-mv63-rf9w | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure | retained |
| GHSA-pg4w-g64p-qwhj | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository | retained |
| CVE-2026-44471 | gix-fs | 0.19.2, 0.11.3 | >=0.21.1 | high | gix-fs: Symlink prefix-reuse allows worktree escape during checkout | retained |
| GHSA-x494-mj8g-cj27 | gix-pack | 0.65.0, 0.53.0 | >=0.69.0 | high | gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data | retained |
| RUSTSEC-2026-0258 | h2 | 0.4.13, 0.3.27 | >=0.4.16 | high | h2 unbounded empty DATA frames | retained |
| CVE-2026-42327 | openssl | 0.10.78 | >=0.10.79 | high | rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs | retained |
| GHSA-2vh6-hw4j-32ww | gix-packetline | 0.21.2 | >=0.21.5 | medium | gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) | retained |
| CVE-2025-24890 | gix-sec | 0.13.2, 0.10.12 | >=0.13.3 | medium | gix-sec safe.directory protections absent for elevated administrators | retained |
| GHSA-9857-6mw7-fq2m | gix-transport | 0.53.0 | >=0.56.0 | medium | gix-transport: HTTP credentials leaked to redirected host in curl backend | retained |
| CVE-2026-44662 | openssl | 0.10.78 | >=0.10.79 | medium | rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding | retained |
| CVE-2026-45784 | openssl | 0.10.78 | >=0.10.80 | medium | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | retained |
| CVE-2023-49092 | rsa | 0.9.10 | none published | medium | Marvin Attack: potential key recovery through timing sidechannels | retained |
| GHSA-2226-4v3c-cff8 | rustc-serialize | 0.3.25 | none published | medium | Stack overflow in rustc_serialize when parsing deeply nested JSON | retained |
| GHSA-2mjx-qc3c-rqvc | rustls | 0.23.39 | >=0.23.45 | medium | Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries | retained |
| CVE-2020-26235 | time | 0.1.45 | >=0.2.23 | medium | Segmentation fault in time | retained |
| RUSTSEC-2026-0190 | anyhow | 1.0.102 | >=1.0.103 | low | Unsoundness in `Error::downcast_mut()` | retained |
| RUSTSEC-2026-0306 | faster-hex | 0.10.0, 0.9.0 | >=0.10.1 | low | `hex_decode_unchecked` AVX2 path reads past `src` | retained |
| RUSTSEC-2026-0183 | git2 | 0.20.4 | >=0.21.0 | low | Potential undefined behavior when calling Remote::list() | retained |
| RUSTSEC-2026-0184 | git2 | 0.20.4 | >=0.21.0 | low | Potential undefined behavior with Signature from a buffer-created BlameHunk | retained |
| RUSTSEC-2025-0161 | libsecp256k1 | 0.3.5 | none published | low | libsecp256k1 is unmaintained | retained |
| RUSTSEC-2026-0186 | memmap2 | 0.9.10 | >=0.9.11 | low | Unchecked pointer offset in crate `memmap2` | retained |
| GHSA-cq8v-f236-94qc | rand | 0.7.3 | >=0.8.6 | low | Rand is unsound with a custom logger using rand::rng() | retained |
| RUSTSEC-2016-0005 | rust-crypto | 0.2.36 | none published | low | rust-crypto is unmaintained; switch to a modern alternative | retained |
| RUSTSEC-2025-0025 | rustc-serialize | 0.3.25 | none published | low | rustc-serialize is unmaintained | retained |
1 of 1 jobs captured: build-test success · Generated 2026-10-07 · tarp 0.1.0+20261007022833-g16cc1581f632 · run 8c9e2d54-cf2a-4e1d-8577-157b66fcacaf
