corefile .io
prod --:--:-- UTC
SIGSEGV

SIGSEGV in prod-checkout-api

acme-checkout · us-east-1 · 03:17:04 UTC · case CF-4211

37s mean time to core dump
cloud resource → container → image → Dockerfile → commit → line

    Security findings — corefile.io repository, HEAD

    The first five rows mirror a live wizcli scan dir run one-to-one — same rule IDs, weakness classes, and file:line; the scan lands on exactly these five HIGH findings (WARN_BY_POLICY). The highlighted row is what today's static ruleset misses: an unauthenticated SSRF caught at runtime (DAST) and in review — the case for layered coverage.

    Build provenance

    Artifactcheckout-api@sha256:9f2c…be1a
    Builderci-runner-07 · SLSA L2
    Sourcegit@…/acme/checkout-api.git · commit 4d1f0e2
    Signedcosign · verified
    “You can't trust code that you did not totally create yourself.” — Ken Thompson, Reflections on Trusting Trust, 1984