From the GitComet pre-launch security audit (2026-08-16, 8 dimension reviewers + adversarial refutation-review; 53 confirmed findings). The audit report was removed from the repo; findings are tracked as issues.
Finding #47 — severity: LOW
scripts/build-apt-repo.sh:174 [low] build-apt-repo.sh interpolates Package-name from dpkg-deb directly into a filesystem path - malicious .deb filename escapes repo_dir
Status: UNVERIFIED — needs triage.
From the GitComet pre-launch security audit (2026-08-16, 8 dimension reviewers + adversarial refutation-review; 53 confirmed findings). The audit report was removed from the repo; findings are tracked as issues.
Finding #47 — severity: LOW
scripts/build-apt-repo.sh:174[low] build-apt-repo.sh interpolates Package-name from dpkg-deb directly into a filesystem path - malicious .deb filename escapes repo_dirStatus: UNVERIFIED — needs triage.