Skip to content

[pkg-vet-test][do-not-merge] S2c reachable [email protected] (calls ini.parse)#29

Open
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s2c-ini-reachable
Open

[pkg-vet-test][do-not-merge] S2c reachable [email protected] (calls ini.parse)#29
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s2c-ini-reachable

Conversation

@Gldywn

@Gldywn Gldywn commented May 29, 2026

Copy link
Copy Markdown
Owner

Throwaway fixture: [email protected] (GHSA-qqgx-2p2h-9c37 prototype pollution) added as a runtime dependency AND its vulnerable parse() called from an exported function, so the vuln is reachable. Tests whether Aikido flags a reachable dependency vulnerability. DO NOT MERGE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant