docs: scan #109 — overwirehq/claude-code-telegram (dependency-currency, post-only) - #156
Merged
Merged
Conversation
…ecution boundary, dependency-currency finding, post-only) Post-only clean-scan write-up. 54 findings at medium+, 0 first-party defects after curation. The one actionable item is dependency currency in transitive poetry.lock pins, split by reachability: 17 opt-in-only (webhook server, token auth, MCP all default-off), 13 unconditionally installed. The write-up's angle is the project's unusually precise security documentation: the can_use_tool boundary is scoped in the docs to exactly six file tools, its gaps (Grep/Glob/LS left to the OS sandbox) are named and tracked (#219 fixed, #221 open), and the pull_request_target workflow carries a full threat-model header. First-party scanner hits were all FP/by-design: sqlalchemy identifier FPs, CI SHA-pin hardening, placeholder + redaction-test secrets. Coverage partial and stated: pip-audit resolved no deps from a dynamic-deps pyproject; Trivy's poetry.lock read carried the run (same blind spot as #108). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scan #109 write-up: overwirehq/claude-code-telegram at
5016aee(v1.8.0).Outcome: post-only. 54 findings at
medium+, 0 first-party defects after curation. The one actionable item is dependency currency in transitivepoetry.lockpins.starlette/python-multipart(webhook serverENABLE_API_SERVER=false),pyjwt(token auth off + documented non-functional docs: 'Work with me' services page + landing CTA (REVIEW before merge) #58), MCP SDK (MCP off).anyio(critical),cryptography/OpenSSL,urllib3,idna,requests,pydantic-settings,python-dotenv— the genuine currency gap.The angle is the project's unusually precise security documentation: the
can_use_toolboundary is scoped in the docs to exactly six file tools, its gaps are named and tracked (#219 fixed, #221 open), and thepull_request_targetworkflow carries a full threat-model header. First-party scanner hits were all FP/by-design (sqlalchemy identifier FPs, CI SHA-pin hardening, placeholder + redaction-test secrets).Strict-norm repo (real SECURITY.md, PVR enabled); no advisory filed because there is no first-party vulnerability. Three files:
docs/scans/…,docs/index.md(row + counts 108→109),docs/scan-log.md.🤖 Generated with Claude Code