cargo / gnostr-ngit
gnostr-ngit 970378.1846.81338
- processes
- 767
- operations
- 549K
- packages
- 738
- compiler runs
- 9,686
- connections
- 2
- job time
- 10m 06s
- capture
- 3.5 MB
- records
- 808K
- bytes / record
- 4.3
nostr plugin for git
Release 970378.1846.81338 run 5c9fe057-267b-43c6-8849-d7fe9e42ff89 · built 2026-10-07
Artifact
- git-remote-nostrbinary · retained · product 37
- libgnostr_ngit.rlibfile · retained · product
- ngitbinary · retained · product 37
| Checks | Detections |
|---|---|
| Build behavior | |
| ▲ Network activity | — |
| ▲ Sensitive data access and transfer | — |
| ✓ Cross-process access | — |
| ✓ Build file changes | — |
| ▲ Build script activity | — |
| ✓ Data flow analysis | — |
| ✓ Filesystem writes | — |
| ✓ Context collection | — |
| Supply chain | |
| ▲ Known vulnerabilities | — |
| ▲ Build-time dependency advisories | — |
| ▲ Dependency advisories | — |
| ✓ Declared and observed dependencies | — |
| ✓ Dependency and toolchain versions | — |
| Pipeline | |
| ✓ Pipeline coverage | — |
Detections
3-
highCredential store read by build-time codeCredential store read by build-time code that does not own it: /home/runner/.netrc
-
highBuild code opened a network connectionconnection to github.com:443, opened by git-remote-http
-
mediumBuild script ran gitTool invocations: 10. Build script: /home/runner/work/gnostr/gnostr/target/release/build/gnostr-grammar-6774b8e99f755627/build-script-build
Network
2 peers-
flaggedgithub.com:443 GitHub, Inc.
-
allowedstatic.crates.io:8080
| Vulnerable dependencies37 | Package | Version | Fix | Severity | Title | Reach |
|---|---|---|---|---|---|---|
| CVE-2021-38195 | libsecp256k1 | 0.3.5 | >=0.5.0 | critical | Overflow in libsecp256k1 | retained |
| RUSTSEC-2026-0204 | crossbeam-epoch | 0.9.18 | >=0.9.20 | high | Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid | retained |
| CVE-2026-40034 | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules | retained |
| GHSA-fr8x-3vfx-f45h | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository | retained |
| GHSA-p3hw-mv63-rf9w | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure | retained |
| GHSA-pg4w-g64p-qwhj | gix | 0.78.0, 0.66.0 | >=0.83.0 | high | gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository | retained |
| CVE-2026-44471 | gix-fs | 0.19.2, 0.11.3 | >=0.21.1 | high | gix-fs: Symlink prefix-reuse allows worktree escape during checkout | retained |
| GHSA-x494-mj8g-cj27 | gix-pack | 0.65.0, 0.53.0 | >=0.69.0 | high | gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data | retained |
| RUSTSEC-2026-0258 | h2 | 0.4.13, 0.3.27 | >=0.4.16 | high | h2 unbounded empty DATA frames | retained |
| RUSTSEC-2026-0216 | nostr | 0.44.2 | >=0.44.5 | high | Remote Denial of Service via malformed NIP‑44 v2 payload | retained |
| RUSTSEC-2026-0219 | nostr | 0.44.2 | >=0.44.6 | high | Remote Denial of Service via malformed NIP-04 IV | retained |
| RUSTSEC-2026-0225 | nostr | 0.44.2 | >=0.44.7 | high | Debug output exposes NIP-46 and NIP-60 credentials | retained |
| RUSTSEC-2026-0226 | nostr | 0.44.2 | >=0.44.7 | high | Wallet event parsers accept unauthenticated events | retained |
| RUSTSEC-2026-0227 | nostr | 0.44.2 | >=0.44.7 | high | NIP-44 v2 decryption permits resource exhaustion | retained |
| RUSTSEC-2026-0228 | nostr | 0.44.2 | >=0.44.7 | high | NIP-04 parsing amplifies malformed ciphertext memory use | retained |
| RUSTSEC-2026-0229 | nostr | 0.44.2 | >=0.44.7 | high | NIP-98 authorization parsing permits resource exhaustion | retained |
| RUSTSEC-2026-0230 | nostr | 0.44.2 | >=0.44.7 | high | Empty NIP-50 search filters can panic | retained |
| RUSTSEC-2026-0224 | nostr-relay-pool | 0.44.0 | >=0.44.2 | high | Verification cache poisoning allows forged Nostr events to bypass signature validation | retained |
| RUSTSEC-2026-0231 | nostr-relay-pool | 0.44.0 | >=0.44.3 | high | Relay authentication challenges can exhaust memory | retained |
| RUSTSEC-2026-0232 | nostr-relay-pool | 0.44.0 | >=0.44.3 | high | Processing of unverified relay events | retained |
| CVE-2026-42327 | openssl | 0.10.78 | >=0.10.79 | high | rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs | retained |
| GHSA-2vh6-hw4j-32ww | gix-packetline | 0.21.2 | >=0.21.5 | medium | gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) | retained |
| CVE-2025-24890 | gix-sec | 0.13.2, 0.10.12 | >=0.13.3 | medium | gix-sec safe.directory protections absent for elevated administrators | retained |
| GHSA-9857-6mw7-fq2m | gix-transport | 0.53.0 | >=0.56.0 | medium | gix-transport: HTTP credentials leaked to redirected host in curl backend | retained |
| CVE-2026-44662 | openssl | 0.10.78 | >=0.10.79 | medium | rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding | retained |
| CVE-2026-45784 | openssl | 0.10.78 | >=0.10.80 | medium | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | retained |
| CVE-2023-49092 | rsa | 0.9.10 | none published | medium | Marvin Attack: potential key recovery through timing sidechannels | retained |
| GHSA-2mjx-qc3c-rqvc | rustls | 0.23.39 | >=0.23.45 | medium | Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries | retained |
| RUSTSEC-2026-0190 | anyhow | 1.0.102 | >=1.0.103 | low | Unsoundness in `Error::downcast_mut()` | retained |
| RUSTSEC-2026-0306 | faster-hex | 0.10.0, 0.9.0 | >=0.10.1 | low | `hex_decode_unchecked` AVX2 path reads past `src` | retained |
| RUSTSEC-2026-0183 | git2 | 0.20.4 | >=0.21.0 | low | Potential undefined behavior when calling Remote::list() | retained |
| RUSTSEC-2026-0184 | git2 | 0.20.4 | >=0.21.0 | low | Potential undefined behavior with Signature from a buffer-created BlameHunk | retained |
| RUSTSEC-2025-0161 | libsecp256k1 | 0.3.5 | none published | low | libsecp256k1 is unmaintained | retained |
| RUSTSEC-2026-0253 | lru | 0.16.4, 0.12.5 | >=0.18.2 | low | Potential use-after-free due to lack of panic safety in `LruCache::pop()` | retained |
| RUSTSEC-2026-0186 | memmap2 | 0.9.10 | >=0.9.11 | low | Unchecked pointer offset in crate `memmap2` | retained |
| RUSTSEC-2026-0243 | nostr-relay-pool | 0.44.0 | none published | low | `nostr-relay-pool` is unmaintained | retained |
| GHSA-cq8v-f236-94qc | rand | 0.7.3 | >=0.8.6 | low | Rand is unsound with a custom logger using rand::rng() | retained |
1 of 1 jobs captured: build-test success · Generated 2026-10-07 · tarp 0.1.0+20261007022833-g16cc1581f632 · run 5c9fe057-267b-43c6-8849-d7fe9e42ff89
