auditnone
urn:signet:att:sha256:9fb42ca0ad1b67061549e2a32a6933c3fa13b4aa6d059758ad174076902700d6
signed by sha256:0e2f8c7616079f540a68f… (tier 0) · registered 2026-07-20T07:48:40.945343Z
Subjects
- https://github.com/fastapi/fastapi @ 5c6d7e8f90123456789012345678901abcde2345
Claims
| vetted-clean | CWE-287 | bearer parsing is spec-correct |
Scope
- fastapi/security/oauth2.py
5555555555555555…
Methodology
manual-code-review@1.79.0
Verifications (1)
- reviewed by sha256:bb191f402807de578… 2026-07-20T07:49:08.035226Z
Raw statement (decoded payload)
{
"_type": "https://in-toto.io/Statement/v1",
"predicate": {
"auditor": {
"type": "human"
},
"claims": [
{
"notes": "bearer parsing is spec-correct",
"status": "vetted-clean",
"vulnClasses": [
"CWE-287"
]
}
],
"expiresAt": null,
"falsePositives": [],
"methodology": {
"tools": [
{
"config": {
"ruleset": "p/owasp-top-ten"
},
"name": "manual-code-review",
"version": "1.79.0"
}
]
},
"schemaVersion": "1.0.0",
"scope": {
"paths": [
{
"file": "fastapi/security/oauth2.py",
"sha256": "5555555555555555555555555555555555555555555555555555555555555555"
}
],
"type": "files"
},
"timestamp": "2026-07-19T12:00:00Z"
},
"predicateType": "https://signet.dev/attestation/audit/v1",
"subject": [
{
"digest": {
"gitCommit": "5c6d7e8f90123456789012345678901abcde2345"
},
"name": "https://github.com/fastapi/fastapi"
}
]
}