ShipShadow

ShipShadow proof

hisopo/monthly-move

Repository
hisopo/monthly-move
Head SHA
7bf754bb150ebd0806824352abf0575d27069f4a
Branch
dependabot/npm_and_yarn/multi-0ed55918c9
Status
completed
Conclusion
failure
Run
run_a680943f12d3d78935355b9a

Gate Results

GateConclusionSummary
ShipShadow / CR Routing Gate success An advisory CR routing exemption matched this pull request.
ShipShadow / Change Request Gate success An advisory change request exemption matched this pull request.
ShipShadow / Policy Gate action_required Protected release paths changed (package-lock.json, package.json). Add .shipshadow/release-evidence.md with the verification evidence for this publication.
ShipShadow / Publish Gate failure Publication is blocked by: ShipShadow / Security Gate, ShipShadow / Policy Gate.
ShipShadow / Secret Gate success Changed-file content passed the ShipShadow secret gate.
ShipShadow / Security Gate failure 8 blocking findings from an earlier commit on this repository have not been resolved: CRITICAL CWE-798-021 in .env.example (introduced in 94808ab) CRITICAL I01-013 in app/page.tsx (introduced in 94808ab) HIGH CWE-326-ALL-005 in lib/geocode.ts (introduced in 94808ab) HIGH CWE-326-ALL-005 in lib/mock-listings.ts (introduced in 94808ab) HIGH CWE-601-ALL-002 in lib/storage.ts (introduced in 94808ab) HIGH CWE-601-ALL-002 in lib/types.ts (introduced in 94808ab) HIGH H10 in lib/sources/airbnb.ts (introduced in 94808ab) HIGH H10 in lib/sources/furnished-finder.ts (introduced in 94808ab) This commit did not change the file, so ShipShadow did not re-scan it and the finding still stands. Resolve it by fixing the file - the next run that changes it will re-scan and clear the finding - or, if it is a confirmed false positive, adjudicate it in the installation FP registry or reproduce a reviewed content-bound override with a fresh scan.