mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate
Maintainer antworten meist innerhalb von 3 Tagen
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 30/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- git, node.js, python, typescript
Rechercherichtung
Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Mimosa upstream feedback draft (M1)
Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.
Environment
- Plugin: mimosa@zcode-plugins-official 1.0.3
- Workload: monorepo with a live trading system (~370 source files, py/ts)
- Baseline seals:
scan-2026-09-28T04-25-50.259Z-22d8d1a1af55(62 findings),
scan-2026-09-28T04-39-14.508Z-223908513145(32 findings post-fix)
Five reproducible defects / gaps
-
Sink-wrapped guard not credited.
chainlink_poll.pyalready called
guard_url(url)at URL construction (landed in a reviewed commit); its
urlopenkept being flagged. Movingguard_url(...)inline into the
Request(...)constructor at the sink statement still does not clear the
finding. Expected: a call to a guard function wrapping the URL argument at
or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
all enforced by the guard). -
Same-shaped fix clears one file but not another. A function-entry
urlsplitscheme+hostname allowlist clearedpmracer/pmracer/history.py
andpmracer/scripts/probe_sources.pybut not
pmracer/scripts/backfill_candles_35d.py(byte-for-byte same shape).
Suggest a documented, deterministic recognition contract for guard shapes. -
Helper-mediated guards are opaque.
_safe_join()(containment via
os.path.realpath+commonpath) results still get flagged at every
downstreamopen(). Same for cross-moduleguard_url. Expected: local or
cross-file sanitizer functions be recognized (even via an explicit
allowlist of guard function names configured per project). -
Git gate scans the wrong tree. Committing in
C:\repo-devwhile the
ZCode workspace isC:\repomade the L3 gate report findings with
C:\repo\...paths (stale live tree), blocking every dev-tree commit until
a subprocess bypass was used. Expected: resolve the tree from the git
command itself (-C,cdchains) or the tool payload cwd, and scan only
the committing tree; ideally scan only the commit's staged diff
(focusFiles) instead of the whole project. -
Scan runs are frequently
inconclusivevia node spawnSync ETIMEDOUT.
Five consecutive stop-hook runs in.mimosa/historyareinconclusive
withspawnSync <node.exe> ETIMEDOUTon core files (tail_engine,
shadow_engine, accounts). Expected: configurable timeout, retry, and an
explicit verdictEffect policy when the scanner times out.
Requested sanitizer recognition (would clear our remaining 23 high)
| Pattern id | Shape | Files |
|---|---|---|
| sink-inline-guard | urlopen(Request(guard_url(url), ...)) |
planb feeds/ledger/truth/tail_engine/context (7 sites) |
| entry-allowlist | urlsplit scheme+host allowlist at helper entry |
backfill, datastreams probe, price_history |
| inline-dotdot | explicit '..' in path.parts (or string split) before open() |
identity, calibration, counter_report, segment_analysis_v2 |
| safe-join-inline-dotdot | _safe_join() + re-stated inline check at sink |
regime_lab, segment_analysis |
The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.
- Vorherrschende Sprache
- Python
- Sterne
- 73
- Forks
- 46
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus zai-org/zcode-plugins
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
zai-org/zcode-plugins#14 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 45/100
zai-org/zcode-plugins#58 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 25/100
zai-org/zcode-plugins#57 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 52/100
zai-org/zcode-plugins#54 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 15/100
zai-org/zcode-plugins#53 ·
Maintainer antworten meist innerhalb von 3 Tagen
Alle Issues in zai-org/zcode-plugins
Ähnliche Issues
-
ACK_WAITING HELP_WANTED UPDATE_CS
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
OWASP/CheatSheetSeries#2458 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
BasedHardware/omi#19711 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Qwen3_5MoeModel no longer returns router_logits, breaking aux loss with output_router_logits=TrueOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
huggingface/transformers#49172 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
vllm-project/vllm-metal#885 ·
Maintainer antworten meist innerhalb von 1 Tag