Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate

Offen
#52 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 3 Tagen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Anfängerfreundlichkeit
30/100
Issue-Typ
Bug
Klarheit
Größtenteils klar
Aktivitätsstatus
Aktiv
Tech-Stack
git, node.js, python, typescript

Rechercherichtung

Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Mimosa upstream feedback draft (M1)

Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.

Environment

  • Plugin: mimosa@zcode-plugins-official 1.0.3
  • Workload: monorepo with a live trading system (~370 source files, py/ts)
  • Baseline seals: scan-2026-09-28T04-25-50.259Z-22d8d1a1af55 (62 findings),
    scan-2026-09-28T04-39-14.508Z-223908513145 (32 findings post-fix)

Five reproducible defects / gaps

  1. Sink-wrapped guard not credited. chainlink_poll.py already called
    guard_url(url) at URL construction (landed in a reviewed commit); its
    urlopen kept being flagged. Moving guard_url(...) inline into the
    Request(...) constructor at the sink statement still does not clear the
    finding. Expected: a call to a guard function wrapping the URL argument at
    or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
    all enforced by the guard).

  2. Same-shaped fix clears one file but not another. A function-entry
    urlsplit scheme+hostname allowlist cleared pmracer/pmracer/history.py
    and pmracer/scripts/probe_sources.py but not
    pmracer/scripts/backfill_candles_35d.py (byte-for-byte same shape).
    Suggest a documented, deterministic recognition contract for guard shapes.

  3. Helper-mediated guards are opaque. _safe_join() (containment via
    os.path.realpath + commonpath) results still get flagged at every
    downstream open(). Same for cross-module guard_url. Expected: local or
    cross-file sanitizer functions be recognized (even via an explicit
    allowlist of guard function names configured per project).

  4. Git gate scans the wrong tree. Committing in C:\repo-dev while the
    ZCode workspace is C:\repo made the L3 gate report findings with
    C:\repo\... paths (stale live tree), blocking every dev-tree commit until
    a subprocess bypass was used. Expected: resolve the tree from the git
    command itself (-C, cd chains) or the tool payload cwd, and scan only
    the committing tree; ideally scan only the commit's staged diff
    (focusFiles) instead of the whole project.

  5. Scan runs are frequently inconclusive via node spawnSync ETIMEDOUT.
    Five consecutive stop-hook runs in .mimosa/history are inconclusive
    with spawnSync <node.exe> ETIMEDOUT on core files (tail_engine,
    shadow_engine, accounts). Expected: configurable timeout, retry, and an
    explicit verdictEffect policy when the scanner times out.

Requested sanitizer recognition (would clear our remaining 23 high)

Pattern id Shape Files
sink-inline-guard urlopen(Request(guard_url(url), ...)) planb feeds/ledger/truth/tail_engine/context (7 sites)
entry-allowlist urlsplit scheme+host allowlist at helper entry backfill, datastreams probe, price_history
inline-dotdot explicit '..' in path.parts (or string split) before open() identity, calibration, counter_report, segment_analysis_v2
safe-join-inline-dotdot _safe_join() + re-stated inline check at sink regime_lab, segment_analysis

The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.

Vorherrschende Sprache
Python
Sterne
73
Forks
46
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus zai-org/zcode-plugins

Alle Issues in zai-org/zcode-plugins

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.