Finding ·
A vendor fix driven by the suite: memory-blackbox restart gap, reported and fixed in a day
With the agent process alive, the memory-blackbox memory.md watcher reports all eight edits on scan. With the agent restarted between the edit and the scan, 0.1.0 served all eight: baseline() seeded the watcher from the file bytes, so an edit made while the agent was down became the trusted state. The maintainer was told privately under the project's security policy on the morning of 2 October; the restart row was held back from the scorecard meanwhile. The fix shipped as 0.1.1 the same day: baseline() now takes the ledger's last write for each watched file as the trusted state, a file the ledger has never seen is recorded once so a cold start reads differently from a mismatch, and the maintainer ran the suite against the fix before tagging. Re-measured on 0.1.1, both rows report all eight. The repo now has private vulnerability reporting switched on and credits the report in its release notes and SECURITY.md.