Conversation
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/d9a92d73-f23d-4da7-b01e-e2120897c92a Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…ang, fix corpus copying Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/a1668967-46ee-418f-96a4-049e1c8cc7bb Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/a1668967-46ee-418f-96a4-049e1c8cc7bb Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…d.sh, Dockerfile, project.yaml Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/af52d22e-2d85-45fc-8730-fb6a7a2c9beb Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
Fix hancock OSS-Fuzz integration: use compile_python_fuzzer, fix build config
…anches Fix hancock OSS-Fuzz project integration
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/8bb39d09-4a6c-4678-9353-a6b31c1412b5 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
Fix hancock project: deduplicate build.sh and project.yaml from overlapping merges
- Create SECURITY.md with vulnerability reporting guidelines - Create .github/dependabot.yml for automated dependency updates (GitHub Actions, pip, npm, gomod, bundler) - Update .github/workflows/codeql-analysis.yml from deprecated v2 to v3 CodeQL actions, add weekly scheduled scan Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/41c406a0-8905-4b19-b9bd-2e71001dc78d Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
Remove email reporting option that lacked a specific address. Address code review feedback. Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/41c406a0-8905-4b19-b9bd-2e71001dc78d Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…n-alerts Set up repository security: policy, Dependabot, and CodeQL v3
Bumps the maven group with 2 updates in the /projects/apache-cxf/project-parent/fuzz-targets directory: org.apache.cxf:cxf-core and org.apache.cxf:cxf-rt-frontend-jaxrs. Bumps the maven group with 1 update in the /projects/async-http-client/project-parent/fuzz-targets directory: org.eclipse.jetty:jetty-server. Bumps the maven group with 1 update in the /projects/avro/project-parent/fuzz-targets directory: org.apache.avro:avro. Bumps the maven group with 1 update in the /projects/eclipse-equinox/equinox-fuzzer directory: [org.eclipse.platform:org.eclipse.core.runtime](https://github.com/eclipse-platform/eclipse.platform). Bumps the maven group with 1 update in the /projects/hadoop/project-parent/fuzz-targets directory: org.apache.hadoop:hadoop-common. Bumps the maven group with 1 update in the /projects/htmlunit/htmlunit-fuzzer directory: [org.htmlunit:htmlunit](https://github.com/HtmlUnit/htmlunit). Bumps the maven group with 3 updates in the /projects/jetty/project-parent/fuzz-targets directory: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-http and org.eclipse.jetty.http2:http2-server. Bumps the maven group with 1 update in the /projects/jose4j/project-parent/fuzz-targets directory: [org.bitbucket.b_c:jose4j](https://bitbucket.org/b_c/jose4j). Bumps the maven group with 1 update in the /projects/nimbus-jwt/nimbus-jwt-fuzzer directory: [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt). Bumps the maven group with 2 updates in the /projects/opencensus-java/project-parent/fuzz-targets directory: [com.google.guava:guava](https://github.com/google/guava) and [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf). Bumps the maven group with 1 update in the /projects/pdfbox/project-parent/fuzz-targets directory: org.apache.logging.log4j:log4j-core. Bumps the maven group with 1 update in the /projects/struts/struts2-fuzzer/webapp directory: org.apache.logging.log4j:log4j-core. Bumps the maven group with 1 update in the /projects/xnio-api/xnio-fuzzer directory: org.jboss.xnio:xnio-api. Bumps the maven group with 1 update in the /projects/yamlbeans/project-parent/fuzz-targets directory: [com.esotericsoftware.yamlbeans:yamlbeans](https://github.com/EsotericSoftware/yamlbeans). Updates `org.apache.cxf:cxf-core` from Fuzzing-SNAPSHOT to 3.5.11 Updates `org.apache.cxf:cxf-rt-frontend-jaxrs` from Fuzzing-SNAPSHOT to 2.6.11 Updates `org.eclipse.jetty:jetty-server` from 11.0.14 to 11.0.24 Updates `org.apache.avro:avro` from Fuzzing-SNAPSHOT to 1.11.4 Updates `org.eclipse.platform:org.eclipse.core.runtime` from 3.26.100 to 3.29.0 - [Commits](https://github.com/eclipse-platform/eclipse.platform/commits) Updates `org.apache.hadoop:hadoop-common` from Fuzzing-SNAPSHOT to 3.4.0 Updates `org.htmlunit:htmlunit` from 2.7.0 to 3.9.0 - [Release notes](https://github.com/HtmlUnit/htmlunit/releases) - [Commits](HtmlUnit/htmlunit@HtmlUnit-2.7...3.9.0) Updates `org.eclipse.jetty:jetty-server` from Fuzzing-SNAPSHOT to 9.4.56.v20240826 Updates `org.eclipse.jetty:jetty-http` from Fuzzing-SNAPSHOT to 12.0.31 Updates `org.eclipse.jetty.http2:http2-server` from Fuzzing-SNAPSHOT to 9.4.53.v20231009 Updates `org.bitbucket.b_c:jose4j` from Fuzzing-SNAPSHOT to 0.9.6 - [Commits](https://bitbucket.org/b_c/jose4j/commits/tag/jose4j-0.9.6) Updates `com.nimbusds:nimbus-jose-jwt` from 9.30.1 to 9.37.4 - [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt) - [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/9.37.4..9.30.1) Updates `com.google.guava:guava` from 31.1-jre to 32.0.0-jre - [Release notes](https://github.com/google/guava/releases) - [Commits](https://github.com/google/guava/commits) Updates `com.google.protobuf:protobuf-java` from 4.0.0-rc-2 to 4.27.5 - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) Updates `org.apache.logging.log4j:log4j-core` from 2.24.3 to 2.25.3 Updates `org.apache.logging.log4j:log4j-core` from 2.24.2 to 2.25.3 Updates `org.jboss.xnio:xnio-api` from 3.8.8.Final to 3.8.14.Final Updates `com.esotericsoftware.yamlbeans:yamlbeans` from Fuzzing-SNAPSHOT to 1.17 - [Release notes](https://github.com/EsotericSoftware/yamlbeans/releases) - [Commits](https://github.com/EsotericSoftware/yamlbeans/commits/1.17) --- updated-dependencies: - dependency-name: org.apache.cxf:cxf-core dependency-version: 3.5.11 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.cxf:cxf-rt-frontend-jaxrs dependency-version: 2.6.11 dependency-type: direct:production dependency-group: maven - dependency-name: org.eclipse.jetty:jetty-server dependency-version: 11.0.24 dependency-type: direct:development dependency-group: maven - dependency-name: org.apache.avro:avro dependency-version: 1.11.4 dependency-type: direct:development dependency-group: maven - dependency-name: org.eclipse.platform:org.eclipse.core.runtime dependency-version: 3.29.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.hadoop:hadoop-common dependency-version: 3.4.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.htmlunit:htmlunit dependency-version: 3.9.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.eclipse.jetty:jetty-server dependency-version: 9.4.56.v20240826 dependency-type: direct:production dependency-group: maven - dependency-name: org.eclipse.jetty:jetty-http dependency-version: 12.0.31 dependency-type: direct:production dependency-group: maven - dependency-name: org.eclipse.jetty.http2:http2-server dependency-version: 9.4.53.v20231009 dependency-type: direct:development dependency-group: maven - dependency-name: org.bitbucket.b_c:jose4j dependency-version: 0.9.6 dependency-type: direct:production dependency-group: maven - dependency-name: com.nimbusds:nimbus-jose-jwt dependency-version: 9.37.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.google.guava:guava dependency-version: 32.0.0-jre dependency-type: direct:production dependency-group: maven - dependency-name: com.google.protobuf:protobuf-java dependency-version: 4.27.5 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.3 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.3 dependency-type: direct:production dependency-group: maven - dependency-name: org.jboss.xnio:xnio-api dependency-version: 3.8.14.Final dependency-type: direct:production dependency-group: maven - dependency-name: com.esotericsoftware.yamlbeans:yamlbeans dependency-version: '1.17' dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] <support@github.com>
…ilure Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/ade44b0d-7838-4de9-a4db-ce88db9bfb71 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…pache-cxf/project-parent/fuzz-targets/maven-77120b2e27 build(deps): bump the maven group across 14 directories with 16 updates
Bumps the maven group with 1 update in the /projects/zt-zip/project-parent/fuzz-targets directory: [org.zeroturnaround:zt-zip](https://github.com/zeroturnaround/zt-zip). Updates `org.zeroturnaround:zt-zip` from Fuzzing-SNAPSHOT to 1.13 - [Changelog](https://github.com/zeroturnaround/zt-zip/blob/master/Changelog.txt) - [Commits](https://github.com/zeroturnaround/zt-zip/commits/zt-zip-1.13) --- updated-dependencies: - dependency-name: org.zeroturnaround:zt-zip dependency-version: '1.13' dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] <support@github.com>
…t-zip/project-parent/fuzz-targets/maven-77d0655455 build(deps): bump org.zeroturnaround:zt-zip from Fuzzing-SNAPSHOT to 1.13 in /projects/zt-zip/project-parent/fuzz-targets in the maven group across 1 directory
…updates Bumps the npm_and_yarn group with 7 updates in the /tools/vscode-extension directory: | Package | From | To | | --- | --- | --- | | [@tootallnate/once](https://github.com/TooTallNate/once) | `1.1.2` | `removed` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.13` | | [flatted](https://github.com/WebReflection/flatted) | `3.2.7` | `3.4.2` | | [minimatch](https://github.com/isaacs/minimatch) | `3.1.2` | `3.1.5` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.1` | `3.14.2` | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.17.23` | | [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` | Bumps the npm_and_yarn group with 1 update in the /infra/cifuzz directory: [brace-expansion](https://github.com/juliangruber/brace-expansion). Removes `@tootallnate/once` Updates `brace-expansion` from 1.1.11 to 1.1.13 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.13) Updates `flatted` from 3.2.7 to 3.4.2 - [Commits](WebReflection/flatted@v3.2.7...v3.4.2) Updates `minimatch` from 3.1.2 to 3.1.5 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) Updates `js-yaml` from 3.14.1 to 3.14.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.1...3.14.2) Updates `lodash` from 4.17.21 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.17.23) Updates `picomatch` from 2.3.1 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...2.3.2) Updates `brace-expansion` from 1.1.11 to 2.0.3 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.13) Updates `minimatch` from 3.1.2 to 5.1.9 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) --- updated-dependencies: - dependency-name: "@tootallnate/once" dependency-version: dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: flatted dependency-version: 3.4.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 3.14.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.23 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 2.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 5.1.9 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/159ce0b5-411b-4b11-967d-f7f944558db0 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…failure Add retry logic to project tests workflow for transient network failures
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/d9eaeee6-c35d-4d0c-94d7-4b57081f4451 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…ls/vscode-extension/npm_and_yarn-136114a06a build(deps): bump the npm_and_yarn group across 2 directories with 7 updates
…dates Bumps the npm_and_yarn group with 1 update in the /infra/cifuzz directory: [@octokit/request-error](https://github.com/octokit/request-error.js). Updates `@octokit/request-error` from 2.1.0 to 7.1.0 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v2.1.0...v7.1.0) Updates `@octokit/plugin-paginate-rest` from 2.21.3 to 14.0.0 - [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases) - [Commits](octokit/plugin-paginate-rest.js@v2.21.3...v14.0.0) Updates `@octokit/request` from 5.6.3 to 10.0.8 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v5.6.3...v10.0.8) Updates `undici` from 5.29.0 to 6.24.1 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.29.0...v6.24.1) --- updated-dependencies: - dependency-name: "@octokit/request-error" dependency-version: 7.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/plugin-paginate-rest" dependency-version: 14.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 10.0.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 6.24.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/05f65760-d077-4251-bcd1-79d0ac164bbf Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…nforcement Add branch protection ruleset with enforcement disabled
…fra/cifuzz/npm_and_yarn-76cca83af0 build(deps): bump the npm_and_yarn group across 1 directory with 4 updates
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/845ca2c7-4e90-4cc2-856c-1eb37a0669a6 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…-installation Fix base-runner-debug: replace compile-from-source GDB with apt-get install
…y-documentation Add SECURITY.md security policy
…ents-issue Fix PR helper: blank comment body and IS_INTERNAL case mismatch
…fra/cifuzz/npm_and_yarn-76cca83af0 build(deps): bump the npm_and_yarn group across 1 directory with 4 updates
…etty build robustness, test path correctness Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/e62a51e3-cc69-4a92-b3a7-0dc134389259 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…ring Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/cfda46ff-a98a-49d2-9520-e8299e7b539d Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…ng and explicit failure checks Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/f411ff68-94e3-46ac-9566-a9d547ff58b6 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
… on persistent failures Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/60c1c52f-5fb7-44ab-b20c-e9acc259d8d4 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
Make the chromium code_coverage clone/fetch section non-fatal so that persistent HTTP errors (403/429) from chromium.googlesource.com don't block ALL base-runner image builds. Only coverage builds are affected when code_coverage setup is skipped. Changes: - Add retry loop for git fetch (5 attempts, like clone) - Skip sleep on final retry attempt to avoid 75s wasted delay - Replace exit 1 with WARNING + skip on persistent failure - Clean up partial clone on fetch failure - Apply consistently to all three base-runner Dockerfiles Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/debe0721-756d-4729-9f71-50e5094ee459 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…coverage-retry Make code_coverage clone/fetch non-fatal to unblock CI when chromium.googlesource.com is down
fix: improve chromium code_coverage clone/fetch retry with 403 handling and explicit failure checks
…ation-oss-fuzz Fix regressions from hancock integration PR #49
…ble with grpcio==1.71.0 Agent-Logs-Url: https://github.com/0ai-Cyberviser/oss-fuzz/sessions/aba5c77b-61ea-468f-928c-5c180a472f63 Co-authored-by: 0ai-Cyberviser <266508493+0ai-Cyberviser@users.noreply.github.com>
…-resolution fix(deps): update Google client libraries to be compatible with grpcio==1.71.0
…ates Bumps the bundler group with 4 updates in the /docs directory: [activesupport](https://github.com/rails/rails), [addressable](https://github.com/sporkmonger/addressable), [faraday](https://github.com/lostisland/faraday) and [nokogiri](https://github.com/sparklemotion/nokogiri). Updates `activesupport` from 7.0.7.2 to 7.2.3.1 - [Release notes](https://github.com/rails/rails/releases) - [Changelog](https://github.com/rails/rails/blob/v8.1.3/activesupport/CHANGELOG.md) - [Commits](rails/rails@v7.0.7.2...v7.2.3.1) Updates `addressable` from 2.8.0 to 2.9.0 - [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md) - [Commits](sporkmonger/addressable@addressable-2.8.0...addressable-2.9.0) Updates `faraday` from 2.4.0 to 2.14.1 - [Release notes](https://github.com/lostisland/faraday/releases) - [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md) - [Commits](lostisland/faraday@v2.4.0...v2.14.1) Updates `nokogiri` from 1.18.9 to 1.19.1 - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.18.9...v1.19.1) --- updated-dependencies: - dependency-name: activesupport dependency-version: 7.2.3.1 dependency-type: indirect dependency-group: bundler - dependency-name: addressable dependency-version: 2.9.0 dependency-type: indirect dependency-group: bundler - dependency-name: faraday dependency-version: 2.14.1 dependency-type: indirect dependency-group: bundler - dependency-name: nokogiri dependency-version: 1.19.1 dependency-type: indirect dependency-group: bundler ... Signed-off-by: dependabot[bot] <support@github.com>
…ndler-f83f3c25ab build(deps-dev): bump the bundler group across 1 directory with 4 updates
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
|
0ai-Cyberviser is a new contributor to projects/nimbus-jwt. The PR must be approved by known contributors before it can be merged. The past contributors are: hunsche, aschaich |
Adds Hancock (AI cybersecurity agent) to OSS-Fuzz with 5 Atheris Python fuzz targets + seed corpora.
Upstream fuzz targets + corpora: https://github.com/0ai-Cyberviser/Hancock/tree/main/fuzz
CIFuzz workflow already enabled in upstream repo.
Submitting for OSS-Fuzz Initial Integration reward (up to $5,000).