Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Software
Data sources: ZENODO
addClaim

RepoAuditor: evidence-bounded security review for acquired codebases

Authors: erxxc;

RepoAuditor: evidence-bounded security review for acquired codebases

Abstract

RepoAuditor is a security-review pipeline for acquired codebases. It combines deterministic scanners, bounded architecture and trust-boundary analysis, human-reviewed findings, quantitative evidence summaries, and separate engineering and leadership reports.Evidence boundary: scanner matches and model outputs are review candidates, not proof of exploitability, actionability, compromise, exhaustive coverage, or production readiness. The package-local weak-RNG detectors are syntactic candidate detectors and do not execute PRNG recovery.

Powered by OpenAIRE graph
Found an issue? Give us feedback