Open disputes

Recently resolved

Proof the mechanism closes the loop: a flag upheld falsifies the audit and slashes the auditor; a flag rejected leaves the audit standing and penalizes a bad-faith flagger. Nothing is automatic — every resolution is a signed record.

  • upheld · audit falsifiedexpressjs/express @ f60718293a4b5c6d…

    confirmed present:CWE-89

    auditor sha256:b4b7e4b5abbe6fd97 penalized · flag against audit · resolved 2026-07-20 07:49:10.197038

Resolution mutations

Subscribe (Atom) ⤵

The TTL refresh caught a package↔commit mapping changing. A repointed release tag is a possible supply-chain attack; a changed verified mapping means the immutable registry artifact itself changed — registry tampering. Coverage never follows the new commit silently; each detection is recorded here.

  • release tag repointedrubygems/rails@8.0.1

    89012345678901ab… ab12345678901abc…

    detected 2026-08-16 04:33:56.022149 · rails/rails

  • registry tampering · immutable artifact changednpm/event-stream@3.3.6

    f2a4a2bfcb2eb5ea… e3163361fed01384…

    detected 2026-06-17 09:33:56.08787 · dominictarr/event-stream

Advisory candidates (ground truth)

Advisories whose affected ranges include an attested commit. Review each one — if it falsifies a vetted-clean claim, file a signed flag; nothing is slashed automatically.

  • GHSA-9j4c-8p7w-2xq3

    https://github.com/langchain-ai/langchainjs @ a1b2c3d4e5f60718…

    Prompt template interpolation may allow injection when untrusted input is embedded into a system prompt without escaping (affects the audited range).

    first seen 2026-08-16 09:33:55.95177

    Falsifies 1 vetted-clean audit on this commit — flag with:

    signet flag urn:signet:att:sha256:fe9c1c7c7455d58193fb26a07fbfe7ae68a730292ee6a40dec4a5b71c13ea13e \
      --reason incorrect --evidence "GHSA-9j4c-8p7w-2xq3" --key <your-key> --registry <registry>