Skip to content

security: PARTIAL auto-remediation — manual review required - #119

Open
Ndevu12 wants to merge 1 commit into
mainfrom
security/auto-clean
Open

security: PARTIAL auto-remediation — manual review required#119
Ndevu12 wants to merge 1 commit into
mainfrom
security/auto-clean

Conversation

@Ndevu12

@Ndevu12 Ndevu12 commented Aug 22, 2026

Copy link
Copy Markdown
Owner

⚠ PARTIAL remediation for Ndevu12/RichTextEditor by StayAwakeBot Security Sentinel — this branch applies what is provably safe but is NOT a clean tree (see below).

Changes applied

  • strip-gitignore.gitignore

🚨 Still infected — confirmed indicators NOT auto-fixed (manual action required)

1 confirmed finding(s) could not be safely auto-remediated and remain in this tree. Do NOT merge this as a completed fix — the security gate stays red. Resolve each, then re-run saw fix --pr:

  • 8acf0688f2evil-merge-loader (evil-merge): Worm payload smuggled via this merge COMMIT (a history finding, not a file edit; files: .gitignore, eslint.config.js). ʼsaw fixʼ never rewrites history — it breaks clones/forks/tags. If the payload is gone from your working tree the tree is clean but the commit persists; verify no fork/tag still shi

⚠ Still needs review (not auto-fixed)

These are suspicious (heuristic) matches — possibly a legitimate inlined asset/minified file, possibly a payload the confirmed signatures didn't name. Review each; allowlist if legitimate, or remove if not.

  • evil-merge222e2c763c
  • whitespace-concealmenteslint.config.js:66
  • oversized-config-lineeslint.config.js:66
  • obfuscated-source-fileeslint.config.js

Originals are recoverable from git history. Evil-merge findings (if any) are reported separately and need a manual history rewrite.

Review and merge if correct. This is a single rolling PR — re-runs update it rather than opening duplicates.

- strip-gitignore: .gitignore
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant