Open disputes
colinhacks/zod @
0718293a4b5c6d7e…disputes vetted-clean:CWE-1333
flag urn:signet:att:sha256:008a8402343fe7bd6e480b… against urn:signet:att:sha256:943b5b7ff3d659d9ebe5f8…
by sha256:dfa4d8db59a4d6315… at 2026-07-20 07:49:09.485561
signet resolve urn:signet:att:sha256:008a8402343fe7bd6e480be54782eda9f18a1aa2962d9d5650bed1fcc0759ce4 \ --outcome upheld|rejected --key <your-key> --registry <registry>
Recently resolved
Proof the mechanism closes the loop: a flag upheld falsifies the audit and slashes the auditor; a flag rejected leaves the audit standing and penalizes a bad-faith flagger. Nothing is automatic — every resolution is a signed record.
Resolution mutations
Subscribe (Atom) ⤵The TTL refresh caught a package↔commit mapping changing. A repointed release tag is a possible supply-chain attack; a changed verified mapping means the immutable registry artifact itself changed — registry tampering. Coverage never follows the new commit silently; each detection is recorded here.
- release tag repointedrubygems/rails@8.0.1
89012345678901ab…→ab12345678901abc…detected 2026-08-16 04:33:56.022149 · rails/rails
- registry tampering · immutable artifact changednpm/event-stream@3.3.6
f2a4a2bfcb2eb5ea…→e3163361fed01384…detected 2026-06-17 09:33:56.08787 · dominictarr/event-stream
Advisory candidates (ground truth)
Advisories whose affected ranges include an attested commit. Review each one — if it falsifies a vetted-clean claim, file a signed flag; nothing is slashed automatically.
GHSA-9j4c-8p7w-2xq3
https://github.com/langchain-ai/langchainjs @
a1b2c3d4e5f60718…Prompt template interpolation may allow injection when untrusted input is embedded into a system prompt without escaping (affects the audited range).
first seen 2026-08-16 09:33:55.95177
Falsifies 1 vetted-clean audit on this commit — flag with:
signet flag urn:signet:att:sha256:fe9c1c7c7455d58193fb26a07fbfe7ae68a730292ee6a40dec4a5b71c13ea13e \ --reason incorrect --evidence "GHSA-9j4c-8p7w-2xq3" --key <your-key> --registry <registry>