Hi — I ran a read-only AI² security-squad audit (Amara/Viktor/Rex/Idris/Priya) against this repo. It surfaced a Critical finding worth prompt attention: hardcoded ORCID sandbox OAuth client secrets + access tokens in src/test/java/pt/ptcris/test/TestClients.java, apparently committed and rotated in-place for close to a decade (confirmed via git history). Also two High findings: a vulnerable commons-text version (Text4Shell, CVE-2022-42889) and two build dependencies (degois-orcid-client, degois-common-utils) that resolve to no discoverable public source, which is a supply-chain risk.
I currently only have read (pull) access to this repo, so I can't file these as issues here myself. I don't see a CODEOWNERS file or a listed GitHub maintainer to address this to directly — the README points at an internal FCCN GitLab (gitlab.fccn.pt/dev-ptcris) as well as this GitHub mirror, so apologies if this repo isn't actively maintained here. Could whoever administers this repo grant triage/write access, or point me to where this should actually be routed?
Full write-up is ready either way.
Hi — I ran a read-only AI² security-squad audit (Amara/Viktor/Rex/Idris/Priya) against this repo. It surfaced a Critical finding worth prompt attention: hardcoded ORCID sandbox OAuth client secrets + access tokens in
src/test/java/pt/ptcris/test/TestClients.java, apparently committed and rotated in-place for close to a decade (confirmed via git history). Also two High findings: a vulnerablecommons-textversion (Text4Shell, CVE-2022-42889) and two build dependencies (degois-orcid-client,degois-common-utils) that resolve to no discoverable public source, which is a supply-chain risk.I currently only have read (
pull) access to this repo, so I can't file these as issues here myself. I don't see a CODEOWNERS file or a listed GitHub maintainer to address this to directly — the README points at an internal FCCN GitLab (gitlab.fccn.pt/dev-ptcris) as well as this GitHub mirror, so apologies if this repo isn't actively maintained here. Could whoever administers this repo granttriage/writeaccess, or point me to where this should actually be routed?Full write-up is ready either way.