js-yaml loaded inline; may be missed by some SBOM scanners
Finding PUB-F009 · c5774919ed7e · discovered by pentest-public-51classes-20260611
LOWconfirmedsupply-chain-failuresopus48artifact backed
- Target
- OhanaSec/jc-pentest-harness
- Target URL
- not recorded
- Run status
- completed · api-multi-model
- Framework
- owasp-top-10
- Priority score
- 0.1600
- Reachability
- unknown
- Chain depth
- 1
- PoC available
- no
- Asset
- not recorded
- Discovered
- Jun 11, 2026, 02:20 PM
Description
js-yaml is required inline rather than at module top, so some SBOM scanners may not detect the dependency.
Validation
No validation rationale recorded.
Remediation
Hoist the import to module scope so SBOM tooling captures it.
Evidence Boundary
This page shows persisted finding evidence, validator rationale, target context, and run linkage. Raw prompts, raw target responses, provider payloads, secrets, cookies, and authorization headers are not rendered publicly. Use the linked run page for class execution evidence, run logs, cost events, and pipeline errors.