Skip to content

chore: sync bundled rules + intel snapshot to 2026.04.30.1#216

Closed
kurtpayne wants to merge 2 commits into
mainfrom
chore/sync-bundled-snapshot-20260430-f823
Closed

chore: sync bundled rules + intel snapshot to 2026.04.30.1#216
kurtpayne wants to merge 2 commits into
mainfrom
chore/sync-bundled-snapshot-20260430-f823

Conversation

@kurtpayne
Copy link
Copy Markdown
Owner

Daily sync of canonical rules + intel from kurtpayne/skillscan-rules. Picks up the latest pattern-update + intel-refresh commits.

Rulepack: 2026.04.29.3 → 2026.04.30.1

  • PSV-057: GitHub Enterprise Server RCE via X-Stat push option injection (CVE-2026-3854, GHSA-64fw-jx9p-5j24, CVSS 8.7)
  • Vuln DB: @openwebconcept/design-tokens 1.0.1–1.0.3 and @openwebconcept/theme-owc 1.0.1–1.0.3 (CanisterSprawl); github-enterprise-server <3.19.4 (CVE-2026-3854)
  • IOC DB: intel-refresh cron commits since last sync

CI requires: test (3.12), test (3.13), Detect website rule drift, Cross-tool recall vs Cisco skill-scanner fixtures. Do NOT merge with --admin — if CI fails, investigate and fix.


Generated by Claude Code

claude added 2 commits April 30, 2026 12:35
Daily sync of canonical rules + intel from kurtpayne/skillscan-rules.
Picks up pattern update 2026-04-30 (PSV-057 CVE-2026-3854 GHES RCE,
@OpenWebconcept vuln DB additions) plus any intel-refresh commits
that accumulated since the last sync.

https://claude.ai/code/session_01AVcY2ku3YHk1uyMi92HZGV
…n bundled snapshot

PSV-054, PSV-055, PSV-056, and SUP-047 were added in yesterday's pattern
updates (2026.04.29.x) without the required metadata.techniques field,
causing test_rule_metadata_guard.py to fail. Add the missing techniques
blocks to each rule in the bundled snapshot.

https://claude.ai/code/session_01AVcY2ku3YHk1uyMi92HZGV
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 30, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 75.90%. Comparing base (31826c9) to head (90e50e9).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #216   +/-   ##
=======================================
  Coverage   75.90%   75.90%           
=======================================
  Files          41       41           
  Lines        5994     5994           
=======================================
  Hits         4550     4550           
  Misses       1444     1444           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@kurtpayne
Copy link
Copy Markdown
Owner Author

Closing — superseded by #243 which brought the bundled snapshot to 2026.05.19.1 in a single catch-up sync on 2026-05-20. Stale daily-agent sync that hit the prior 30-min CI timeout; #242 bumped the timeout to 45 min.

@kurtpayne kurtpayne closed this May 20, 2026
@kurtpayne kurtpayne deleted the chore/sync-bundled-snapshot-20260430-f823 branch May 20, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants