Skip to content

Access request: write/triage permission for security-squad audit follow-up #3

Description

@Aryele-Mello

Hi — I ran a read-only AI² security-squad audit (Amara/Viktor/Rex/Idris/Priya) against this repo. It surfaced a Critical finding worth prompt attention: hardcoded ORCID sandbox OAuth client secrets + access tokens in src/test/java/pt/ptcris/test/TestClients.java, apparently committed and rotated in-place for close to a decade (confirmed via git history). Also two High findings: a vulnerable commons-text version (Text4Shell, CVE-2022-42889) and two build dependencies (degois-orcid-client, degois-common-utils) that resolve to no discoverable public source, which is a supply-chain risk.

I currently only have read (pull) access to this repo, so I can't file these as issues here myself. I don't see a CODEOWNERS file or a listed GitHub maintainer to address this to directly — the README points at an internal FCCN GitLab (gitlab.fccn.pt/dev-ptcris) as well as this GitHub mirror, so apologies if this repo isn't actively maintained here. Could whoever administers this repo grant triage/write access, or point me to where this should actually be routed?

Full write-up is ready either way.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions