ShipShadow

ShipShadow proof

hisopo/elbato

Repository
hisopo/elbato
Head SHA
7a917d1bd8c5fa0d9761063af8d9a4548d5bca73
Branch
dev
Status
completed
Conclusion
failure
Run
run_6c0d62b07370fc80bc1dd618

Gate Results

GateConclusionSummary
ShipShadow / Policy Gate success No blocked workflow or release-evidence policy violations were found.
ShipShadow / Publish Gate failure Publication is blocked by: ShipShadow / Security Gate.
ShipShadow / Secret Gate success Changed-file content passed the ShipShadow secret gate.
ShipShadow / Security Gate failure 17 blocking findings from an earlier commit on this repository have not been resolved: CRITICAL AI03-001 in elbato/objective_cli_executor.py (introduced in c8275fb) CRITICAL H10 in elbato/objective_cli_executor.py (introduced in c8275fb) CRITICAL AI03-001 in tests/test_objective_cli_executor.py (introduced in e9e8235) HIGH AI02-002 in elbato/llm_runner.py (introduced in 5a7e67e) HIGH AI02-003 in elbato/llm_runner.py (introduced in 5a7e67e) HIGH CWE-532-ALL-001 in elbato/llm_runner.py (introduced in 5a7e67e) HIGH AI-FLOW-MODEL in elbato/llm_runner.py (introduced in 5a7e67e) HIGH AI-CONV-UNBOUNDE in elbato/llm_runner.py (introduced in 5a7e67e) CRITICAL AI03-001 in tools/all_exec_objectives_closed_loop_eval.py (introduced in 5a7e67e) HIGH H23 in elbato/llm_runner.py (introduced in 5a7e67e) CRITICAL AI03-001 in elbato/operating_rule_enforcement.py (introduced in b6f904c) HIGH XF05 in siteshadow-finding (introduced in b6f904c) HIGH CWE-676-ALL-008 in tests/test_owner_attestation.py (introduced in b7c66d1) HIGH CWE-215-ALL-001 in tools/owner_attest_request.py (introduced in b7c66d1) HIGH P01-004 in tools/owner_attest_request.py (introduced in b7c66d1) HIGH CWE-394-ALL-001 in tools/theo_control_integrity_monitor.py (introduced in b7c66d1) HIGH XF01 in siteshadow-finding (introduced in b7c66d1) This commit did not change the file, so ShipShadow did not re-scan it and the finding still stands. Resolve it by fixing the file - the next run that changes it will re-scan and clear the finding - or, if it is a confirmed false positive, adjudicate it in the installation FP registry or reproduce a reviewed content-bound override with a fresh scan.