Skip to content
Open-Source Registry

cargo / gnostr-ngit

gnostr-ngit 970378.1846.81338

processes
767
operations
549K
packages
738
compiler runs
9,686
connections
2
job time
10m 06s
capture
3.5 MB
records
808K
bytes / record
4.3

nostr plugin for git

3 detections37 vulnerabilities

3,399 downloads · MIT · source · home page · cargo

git nostr

Release 970378.1846.81338 run 5c9fe057-267b-43c6-8849-d7fe9e42ff89 · built 2026-10-07

Artifact

file · retained · product
3
ChecksDetections
Build behavior
▲ Network activity—
▲ Sensitive data access and transfer—
✓ Cross-process access—
✓ Build file changes—
▲ Build script activity—
✓ Data flow analysis—
✓ Filesystem writes—
✓ Context collection—
Supply chain
▲ Known vulnerabilities—
▲ Build-time dependency advisories—
▲ Dependency advisories—
✓ Declared and observed dependencies—
✓ Dependency and toolchain versions—
Pipeline
✓ Pipeline coverage—

Detections

3
  • Credential store read by build-time code
    gnostr-grammar 970378.1846.81338
    Credential store read by build-time code that does not own it: /home/runner/.netrc
    high
  • Build code opened a network connection
    gnostr-grammar 970378.1846.81338 › github.com:443
    connection to github.com:443, opened by git-remote-http
    high
  • Build script ran git
    gnostr-grammar 970378.1846.81338 › github.com:443
    Tool invocations: 10. Build script: /home/runner/work/gnostr/gnostr/target/release/build/gnostr-grammar-6774b8e99f755627/build-script-build
    medium

Detection

high

Credential store read by build-time code

subject gnostr-grammar 970378.1846.81338

Credential store read by build-time code that does not own it: /home/runner/.netrc

  1. rustup2495
  2. cargo2495
  3. build-script-build21223
  4. git22686
  5. git22659
  6. git-remote-http22661at 19:11:12

witnessed · rule credential-read

Detection

high

Build code opened a network connection

subject gnostr-grammar 970378.1846.81338 · destination github.com:443

connection to github.com:443, opened by git-remote-http

the opener descends from the build script at /home/runner/work/gnostr/gnostr/target/release/build/gnostr-grammar-6774b8e99f755627/build-script-build

  1. rustup2495
  2. cargo2495
  3. build-script-build21223
  4. git21239
  5. git21234
  6. git-remote-http21236at 19:10:44

witnessed · rule egress

Detection

medium

Build script ran git

subject gnostr-grammar 970378.1846.81338 · destination github.com:443

Tool invocations: 10. Build script: /home/runner/work/gnostr/gnostr/target/release/build/gnostr-grammar-6774b8e99f755627/build-script-build

Command: git fetch --depth 1 origin a533cd3c33aea6acb0f9bf9a56f35dcfe6a8eb53

Command: git fetch --depth 1 origin a533cd3c33aea6acb0f9bf9a56f35dcfe6a8eb53

witnessed · gnostr · rule buildscript

Network

2 peers
  • github.com:443 GitHub, Inc.
    git-remote-http · build-test
    flagged
  • static.crates.io:8080
    cargo (gnostr) via crates.io · build-test
    allowed
Vulnerable dependencies37PackageVersionFixSeverityTitleReach
CVE-2021-38195libsecp256k10.3.5>=0.5.0criticalOverflow in libsecp256k1retained
RUSTSEC-2026-0204crossbeam-epoch0.9.18>=0.9.20highInvalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalidretained
CVE-2026-40034gix0.78.0, 0.66.0>=0.83.0highgitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodulesretained
GHSA-fr8x-3vfx-f45hgix0.78.0, 0.66.0>=0.83.0highgix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repositoryretained
GHSA-p3hw-mv63-rf9wgix0.78.0, 0.66.0>=0.83.0highgix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureretained
GHSA-pg4w-g64p-qwhjgix0.78.0, 0.66.0>=0.83.0highgix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repositoryretained
CVE-2026-44471gix-fs0.19.2, 0.11.3>=0.21.1highgix-fs: Symlink prefix-reuse allows worktree escape during checkoutretained
GHSA-x494-mj8g-cj27gix-pack0.65.0, 0.53.0>=0.69.0highgix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack dataretained
RUSTSEC-2026-0258h20.4.13, 0.3.27>=0.4.16highh2 unbounded empty DATA framesretained
RUSTSEC-2026-0216nostr0.44.2>=0.44.5highRemote Denial of Service via malformed NIP‑44 v2 payloadretained
RUSTSEC-2026-0219nostr0.44.2>=0.44.6highRemote Denial of Service via malformed NIP-04 IVretained
RUSTSEC-2026-0225nostr0.44.2>=0.44.7highDebug output exposes NIP-46 and NIP-60 credentialsretained
RUSTSEC-2026-0226nostr0.44.2>=0.44.7highWallet event parsers accept unauthenticated eventsretained
RUSTSEC-2026-0227nostr0.44.2>=0.44.7highNIP-44 v2 decryption permits resource exhaustionretained
RUSTSEC-2026-0228nostr0.44.2>=0.44.7highNIP-04 parsing amplifies malformed ciphertext memory useretained
RUSTSEC-2026-0229nostr0.44.2>=0.44.7highNIP-98 authorization parsing permits resource exhaustionretained
RUSTSEC-2026-0230nostr0.44.2>=0.44.7highEmpty NIP-50 search filters can panicretained
RUSTSEC-2026-0224nostr-relay-pool0.44.0>=0.44.2highVerification cache poisoning allows forged Nostr events to bypass signature validationretained
RUSTSEC-2026-0231nostr-relay-pool0.44.0>=0.44.3highRelay authentication challenges can exhaust memoryretained
RUSTSEC-2026-0232nostr-relay-pool0.44.0>=0.44.3highProcessing of unverified relay eventsretained
CVE-2026-42327openssl0.10.78>=0.10.79highrust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsretained
GHSA-2vh6-hw4j-32wwgix-packetline0.21.2>=0.21.5mediumgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)retained
CVE-2025-24890gix-sec0.13.2, 0.10.12>=0.13.3mediumgix-sec safe.directory protections absent for elevated administratorsretained
GHSA-9857-6mw7-fq2mgix-transport0.53.0>=0.56.0mediumgix-transport: HTTP credentials leaked to redirected host in curl backendretained
CVE-2026-44662openssl0.10.78>=0.10.79mediumrust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-paddingretained
CVE-2026-45784openssl0.10.78>=0.10.80mediumrust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersretained
CVE-2023-49092rsa0.9.10none publishedmediumMarvin Attack: potential key recovery through timing sidechannelsretained
GHSA-2mjx-qc3c-rqvcrustls0.23.39>=0.23.45mediumRustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundariesretained
RUSTSEC-2026-0190anyhow1.0.102>=1.0.103lowUnsoundness in `Error::downcast_mut()`retained
RUSTSEC-2026-0306faster-hex0.10.0, 0.9.0>=0.10.1low`hex_decode_unchecked` AVX2 path reads past `src`retained
RUSTSEC-2026-0183git20.20.4>=0.21.0lowPotential undefined behavior when calling Remote::list()retained
RUSTSEC-2026-0184git20.20.4>=0.21.0lowPotential undefined behavior with Signature from a buffer-created BlameHunkretained
RUSTSEC-2025-0161libsecp256k10.3.5none publishedlowlibsecp256k1 is unmaintainedretained
RUSTSEC-2026-0253lru0.16.4, 0.12.5>=0.18.2lowPotential use-after-free due to lack of panic safety in `LruCache::pop()`retained
RUSTSEC-2026-0186memmap20.9.10>=0.9.11lowUnchecked pointer offset in crate `memmap2`retained
RUSTSEC-2026-0243nostr-relay-pool0.44.0none publishedlow`nostr-relay-pool` is unmaintainedretained
GHSA-cq8v-f236-94qcrand0.7.3>=0.8.6lowRand is unsound with a custom logger using rand::rng()retained

Raw data

40 of 581,645 events
capture
3.5 MB
records
808,113
bytes per record
4.3
TimeOpUserPIDCommandTarget
19:04:25.718 read_write runner 2483 cargo net 10.0.2.15 › index.crates.io:8080
19:04:28.038 read_write runner 2483 cargo net 10.0.2.15 › static.crates.io:8080
19:04:32.108 create runner 2478 cargo namespaceapi.rs
19:04:32.108 create runner 2478 cargo nb30.rs
19:04:32.108 create runner 2478 cargo ncrypt.rs
19:04:32.108 create runner 2478 cargo ntlsa.rs
19:04:32.108 create runner 2478 cargo ntsecapi.rs
19:04:35.041 read_write runner 2483 cargo net 10.0.2.15 › static.crates.io:8080
19:05:33.884 copy runner 4834 build_script_main-d7f7302ecaf4b9e4 sm4-x86_64.pl
19:05:33.884 copy runner 4834 build_script_main-d7f7302ecaf4b9e4 punycode.c
19:05:33.884 copy runner 4834 build_script_main-d7f7302ecaf4b9e4 o_init.c
19:05:33.884 copy runner 4834 build_script_main-d7f7302ecaf4b9e4 dllmain.c
19:05:33.884 copy runner 4834 build_script_main-d7f7302ecaf4b9e4 trace.c
19:07:30.465 rename runner 11522 gnumv libcrypto-lib-ec_err.d
19:07:30.840 rename runner 11432 rustc libpest_meta-36bd7f9a71ad3268.rlib
19:07:30.840 rename runner 11192 rustc libgix_index-1509af49202b07e8.rlib
19:07:30.876 rename runner 11541 gnumv libcrypto-lib-ec_key.d
19:07:30.959 rename runner 11548 rustc librancor-f6eed6a7788cf460.rmeta
19:08:03.236 fork runner 13381 dash dash
19:08:03.238 fork runner 13382 x86_64-linux-gnu-gcc-15 x86_64-linux-gnu-gcc-15
19:08:03.161 fork runner 13373 rustc rustc
19:08:03.217 fork runner 13375 rustc rustc
19:08:03.443 fork runner 13385 x86_64-linux-gnu-gcc-15 x86_64-linux-gnu-gcc-15
19:08:23.121 execute runner 14537 cc1 cc1
19:08:23.222 execute runner 14538 x86_64-linux-gnu-as x86_64-linux-gnu-as
19:08:23.233 execute runner 14539 cat cat
19:08:23.239 execute runner 14540 dash dash
19:08:23.241 execute runner 14541 cmp cmp
19:08:43.817 read runner 15353 rustc libnum_modular-c5204de3a2ba273c.rlib
19:08:43.817 read runner 15453 cc1 dsa.h
19:08:43.817 read runner 15453 cc1 dh.h
19:08:43.817 read runner 15453 cc1 dherr.h
19:08:43.817 read runner 15453 cc1 dsaerr.h
19:09:17.466 truncate runner 17166 cc1 ccnnd0LE.s
19:09:17.799 truncate runner 17185 cc1 cc3a1k3h.s
19:09:18.068 truncate runner 17216 cc1 ccbPcZpl.s
19:09:18.253 truncate runner 17226 cc1 ccTcXhD1.s
19:09:18.561 truncate runner 17257 cc1 ccfCqIox.s
19:09:20.628 write runner 17387 cc1 ccJ5PJYI.s
19:09:20.628 write runner 17391 x86_64-linux-gnu-as libcrypto-lib-t_acert.o

Want to see more? E-mail us at hello@bitbison.io about your use case.

1 of 1 jobs captured: build-test success · Generated 2026-10-07 · tarp 0.1.0+20261007022833-g16cc1581f632 · run 5c9fe057-267b-43c6-8849-d7fe9e42ff89