Skip to content

E2E test: AIsbom should flag mock_malware.pt#1

Open
lab700xdev wants to merge 4 commits into
mainfrom
test-pr-critical
Open

E2E test: AIsbom should flag mock_malware.pt#1
lab700xdev wants to merge 4 commits into
mainfrom
test-pr-critical

Conversation

@lab700xdev
Copy link
Copy Markdown
Contributor

Smoke test for v1.0.0 of the AIsbom Action. Expecting a CRITICAL finding.

@github-actions
Copy link
Copy Markdown

🛡️ AIsbom Security Scan

Summary: 1 CRITICAL, 1 MEDIUM, 2 LOW across 4 model artifact(s).

Findings

Risk Artifact Format License Issue
🔴 CRITICAL mock_malware.pt PyTorch Unknown RCE Detected: posix.system
🟡 MEDIUM mock_broken.pt PyTorch Unknown Pickle Present
🟢 LOW mock_restricted.gguf GGUF cc-by-nc-sa-4.0 LEGAL RISK (cc-by-nc-sa-4.0)
🟢 LOW mock_restricted.safetensors SafeTensors cc-by-nc-4.0 (Non-Commercial) LEGAL RISK (cc-by-nc-4.0 (Non-Commercial))

View full SBOM in viewer →

📦 Generated by AIsbom · scanned models/ · 4 artifact(s) total

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant