{"asset":{"id":"repoguard","version":"0.9.7"},"evidence":{"exactCommitMatched":true,"htmlUrl":"https://github.com/axios/axios/commit/c3f553c740ebf3dff5e22dae24e9caaafafddd2d","observedCommit":"c3f553c740ebf3dff5e22dae24e9caaafafddd2d","requestedCommit":"c3f553c740ebf3dff5e22dae24e9caaafafddd2d","transport":"git-smart-http"},"limitations":["Static analysis can miss vulnerabilities and can report false positives.","No repository code, build, test, exploit, or package-manager script was executed.","A clear result is not a security certification or guarantee.","OSV findings depend on supported manifests and current upstream advisory data."],"proof":{"algorithm":"sha256","deliveryDigest":"sha256:72bd0a9294362ec5caf326af144c83cc1feca4bbc6f7107d34a1dc703cd9e3d5","generatedAt":"2026-08-01T12:36:43Z"},"protocol":"repoguard.review/v1","purchase":{"alternateUrl":"https://payanagent.com/x402/kh7ccz72h1bszwe1e83a2k2ft98bsm1m","input":{"example":{"repository":"https://github.com/octocat/Hello-World"},"required":["repository"]},"instructions":"POST one public GitHub repository URL. The first response returns x402 payment terms; repeat with a valid payment signature to receive the full report.","method":"POST","price":{"amount":"0.01","currency":"USD","network":"eip155:8453","settlementAsset":"USDC"},"url":"https://oix-repoguard.fly.dev/review"},"request":{"commit":"c3f553c740ebf3dff5e22dae24e9caaafafddd2d","inputDigest":"sha256:e0526132f97471edd229346946e55f7a5274a7f3870657fe6f88fd93c05c4a8a","repository":"https://github.com/axios/axios"},"result":{"decision":"review","durationMs":7256,"scanners":{"gitleaks":{"findings":[{"description":"Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.","fingerprint":"tests/unit/adapters/key.pem:private-key:1","line":1,"path":"tests/unit/adapters/key.pem","ruleId":"private-key","secret":"REDACTED"}],"status":"complete","totalFindings":1},"osv":{"findings":[{"aliases":[],"ecosystem":"npm","id":"GHSA-r28c-9q8g-f849","package":"postcss","source":"docs/package-lock.json","summary":"PostCSS path traversal in previous source-map auto-loading can disclose arbitrary .map files.","version":"8.5.12"},{"aliases":["CVE-2026-39365"],"ecosystem":"npm","id":"GHSA-4w7w-66w2-5vf9","package":"vite","source":"docs/package-lock.json","summary":"Vite path traversal in optimized-dependency source-map handling.","version":"5.4.21"},{"aliases":["CVE-2026-53571"],"ecosystem":"npm","id":"GHSA-fx2h-pf6j-xcff","package":"vite","source":"docs/package-lock.json","summary":"Vite server.fs.deny bypass on Windows alternate paths.","version":"5.4.21"}],"findingsOmittedFromSample":57,"status":"complete","totalFindings":60},"semgrep":{"findings":[],"status":"complete"}},"summary":{"critical":0,"high":1,"low":0,"medium":0,"unknown":60}},"sampleEvidence":{"fullDeliveryDigest":"sha256:6fa7d0278dacd91b4ac7e6a67428928aefe1f0c67f5f97d68b74ef7279d402c1","includedFindings":4,"kind":"redacted-production-excerpt","omittedFindings":57,"sourceExecutionId":"4c39ba58-5800-4bb0-b2f9-f2dd90cc6fd1","sourceGeneratedAt":"2026-08-01T12:36:43Z","warning":"Signals require maintainer review. Test fixtures, unreachable code, and dependency context can produce false positives."},"scope":{"bytes":3439777,"exactCommit":true,"files":460,"publicRepositoryOnly":true,"rawSecretsIncluded":false,"repositoryCodeExecuted":false,"sourceExcerptsIncluded":false,"submodulesFetched":false}}
