GitHub malicious-dependency incident touching protocol deps
Babylon Protocol's assessment for RD-F-160 — scored not_assessed on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Cell re-flagged 2026-05-06 by quality audit wave 3: prior evidence cited a non-existent GHSA advisory (GHSA-h598-3g3g-c67c returns 404 in both GitHub Advisory UI and REST API) and fabricated CometBFT releases (v4.2.5, v4.2.7 do not exist; CometBFT versioning is v0.38.x / v0.39.x). Re-collection required from Babylon's actual go.mod dependencies + GitHub Advisory Database primary sources before this factor can be re-scored.
Sources #
- URLhttps://github.com/advisories/GHSA-h598-3g3g-c67cretrieved 2026-05-06
- https://github.com/cometbft/cometbft/releasesretrieved 2026-05-06
Methodology #
Determine whether a security advisory flags a malicious release in a dependency consumed by this protocol.
See the full factor methodology and distribution across all protocols →