auditnone
urn:signet:att:sha256:011799a4f4bdb40bd20ab5e7d5471b0b8f0fd97cff2f64b6d845f87e24db4f62
signed by sha256:b4b7e4b5abbe6fd9732a3… (tier 0) · registered 2026-07-20T07:48:35.725061Z
Subjects
- https://github.com/openai/openai-node @ c3d4e5f60718293a4b5c6d7e8f90123456789012
Claims
| vulnerability-found | CWE-400 | unbounded SSE buffer under a slow-loris peer |
Scope
- src/streaming.ts
cccccccccccccccc…
Methodology
codeql@1.79.0
Verifications (0)
none yet
Raw statement (decoded payload)
{
"_type": "https://in-toto.io/Statement/v1",
"predicate": {
"auditor": {
"type": "human"
},
"claims": [
{
"notes": "unbounded SSE buffer under a slow-loris peer",
"status": "vulnerability-found",
"vulnClasses": [
"CWE-400"
]
}
],
"expiresAt": null,
"falsePositives": [],
"methodology": {
"tools": [
{
"config": {
"ruleset": "p/owasp-top-ten"
},
"name": "codeql",
"version": "1.79.0"
}
]
},
"schemaVersion": "1.0.0",
"scope": {
"paths": [
{
"file": "src/streaming.ts",
"sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
}
],
"type": "files"
},
"timestamp": "2026-07-19T19:00:00Z"
},
"predicateType": "https://signet.dev/attestation/audit/v1",
"subject": [
{
"digest": {
"gitCommit": "c3d4e5f60718293a4b5c6d7e8f90123456789012"
},
"name": "https://github.com/openai/openai-node"
}
]
}