Ali Firasthesmartshadow

I audit open-source software, reproduce security flaws, work with maintainers on remediation, and follow issues through fixes, regression coverage, advisories, releases and downstream distribution updates.

I start with the trust boundary, not a scanner result. I trace how external data reaches file operations, parsers, authorization checks, process execution, shared state, cryptographic buffers, or resource allocation. Severity stays separate from technical validity: some findings are vulnerabilities, some are hardening opportunities, and some should remain ordinary bugs.

Where the work lands

15 findings across 5 package ecosystems and 12 weakness classes. Every one is listed with the source that establishes the credit; nothing on this site rests on self-attestation.

Only 2 of those classes appear more than once: CWE-400 and CWE-59. Every other class accounts for a single finding.

Open the credit index · Read the one finding with a full record

npm
5 findings
Rust (crates.io)
4 findings
Go
3 findings
PyPI
2 findings
RubyGems
1 finding

Credit model

Author
Wrote the published record: the narrative, the structured metadata, and the reference list. Ali Firas
Researcher
Performed the investigation that produced the finding, whether or not they wrote the record. Ali Firas, Ali Alakbar

How this archive is published

One fact, one place.
Every published fact derives from one validated record. Nothing is restated in a second place where the two could drift apart.
Primary sources only.
A reference is the upstream artefact, not an aggregator's projection of it. Where an aggregator is the only surviving copy, that is stated.
Provenance over assertion.
Where a fact could not be independently verified, it is omitted or marked, never inferred. Absence is published as absence.
Identifiers are permanent.
A TSS-R identifier is never reused, renamed, or redirected away. A record that is superseded or retracted keeps its URL and says so on the page.
Limitations are mandatory.
If the result depends on a version, configuration, privilege, or race, that dependency is stated in the record rather than left for the reader to discover.
Disclosure before publication.
Nothing is published that is not already public. The record follows the disclosure; it never leads it.