Ali Firasthesmartshadow
I audit open-source software, reproduce security flaws, work with maintainers on remediation, and follow issues through fixes, regression coverage, advisories, releases and downstream distribution updates.
I start with the trust boundary, not a scanner result. I trace how external data reaches file operations, parsers, authorization checks, process execution, shared state, cryptographic buffers, or resource allocation. Severity stays separate from technical validity: some findings are vulnerabilities, some are hardening opportunities, and some should remain ordinary bugs.
Where the work lands
15 findings across 5 package ecosystems and 12 weakness classes. Every one is listed with the source that establishes the credit; nothing on this site rests on self-attestation.
Only 2 of those classes appear more than once: CWE-400 and CWE-59. Every other class accounts for a single finding.
Open the credit index · Read the one finding with a full record
- npm
- 5 findings
- Rust (crates.io)
- 4 findings
- Go
- 3 findings
- PyPI
- 2 findings
- RubyGems
- 1 finding
Credit model
- Author
- Wrote the published record: the narrative, the structured metadata, and the reference list. Ali Firas
- Researcher
- Performed the investigation that produced the finding, whether or not they wrote the record. Ali Firas, Ali Alakbar
How this archive is published
- One fact, one place.
- Every published fact derives from one validated record. Nothing is restated in a second place where the two could drift apart.
- Primary sources only.
- A reference is the upstream artefact, not an aggregator's projection of it. Where an aggregator is the only surviving copy, that is stated.
- Provenance over assertion.
- Where a fact could not be independently verified, it is omitted or marked, never inferred. Absence is published as absence.
- Identifiers are permanent.
- A TSS-R identifier is never reused, renamed, or redirected away. A record that is superseded or retracted keeps its URL and says so on the page.
- Limitations are mandatory.
- If the result depends on a version, configuration, privilege, or race, that dependency is stated in the record rather than left for the reader to discover.
- Disclosure before publication.
- Nothing is published that is not already public. The record follows the disclosure; it never leads it.