• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

rtmx-ai / rtmx / 23602336398
79%

Build:
DEFAULT BRANCH: main
Ran 26 Mar 2026 03:20PM UTC
Jobs 1
Files 52
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

26 Mar 2026 03:19PM UTC coverage: 80.444% (+0.07%) from 80.376%
23602336398

push

github

rhino11
security: Add 10 attack replication tests for audit findings (REQ-SEC-001..010)

Proves the following vulnerabilities are exploitable:

CRITICAL:
- TestResultsTampering: crafted results.json flips MISSING to COMPLETE
- TestSyncProtocolAttacks: unauthenticated status override, replay, injection
- TestGrantEnforcementBypass: grants decorative, never checked during sync

HIGH:
- TestActionPinning: 41/41 GitHub Actions use mutable tags
- TestInstallScriptGPGVerification: checksums verified, signatures not
- TestMandatoryGPGSigning: GPG signing conditional on secret existence
- TestInputInjection: GitHub URL traversal, Jira SSRF, JQL injection
- TestPathTraversal: shadow resolver escapes to arbitrary paths
- TestCIPipelineSafety: auto-commit doesn't validate modified files

MEDIUM:
- TestAtomicDatabaseWrite: truncate-then-write loses data on interrupt

All tests PASS (attack succeeds). They will FAIL once vulnerabilities
are remediated, serving as regression tests.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

7063 of 8780 relevant lines covered (80.44%)

26.38 hits per line

Jobs
ID Job ID Ran Files Coverage
1 23602336398.1 26 Mar 2026 03:20PM UTC 52
80.44
GitHub Action Run
Source Files on build 23602336398
  • Tree
  • List 52
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #23602336398
  • 1975bf91 on github
  • Prev Build on main (#23574297744)
  • Next Build on main (#23607163627)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc