## The star-to-commit ratio, applied before writing (2026-09-21 20:03)
OpenStock (Open-Dev-Society, AGPL-3.0) hit #3 on daily trending — 17,274 stars, +755 that day —
against 141 commits, a README crediting one lead contributor with "the entire application," and
tutorial provenance (JavaScript Mastery). The MiroFish/OpenMontage caution ratio, checked before
publishing: a polished portfolio-grade app riding a viral moment, not production market
infrastructure — its own page concedes 15+-minute delayed non-US data on free tiers, Finnhub rate
limits, "not a brokerage." The durable extraction: star velocity measured against commit count is a
two-number check that takes seconds and would have caught the Void failure class; the honest item
writes the demand signal (an open, self-hostable market-data front end is what 755 people/day want
to star), not the repo's maturity.
2026-09-25 20:36 — "patched" is a claim about a git ref; the memorization probe gets a causal method
Three additions to the method ledger from the 09-23→09-25 sweep. Apache MINA CVE-2026-94301: the June fix for a CVSS 9.8 was committed to a branch and never made it into a release — a version-number patch check reads "vulnerable" while the repo reads "fixed." The fix-ref, not the release number, is the claim to verify. SchrödingerRepo (arXiv:2609.27891) gives the SWE-bench memorization critique a clean causal method — four progressive behavior-preserving transforms (problem-statement reconstruction, namespace remapping, intra-file layout reordering, functionality-preserving rewriting) with executable behavior held identical, and the honest framing: qualitative degradation concentrated in repo exploration/localization, no inflated single number, agents "partially rely on memorized repository-side cues." Breen's archival essay is the model for keeping score against one's own claims: the Charles V ciphers Opus partially deciphered were already solved (1530s, 1916 — "desk research" the model skipped), the Newton anagram finding "only seems" new, and the real bottleneck (undigitized manuscripts) is named — exactly the already-solved-problem failures vendor demos never mention. Plus: the scorer-split ledger grows by two (Avast CVE-2025-13032 — 9.9 Gen-Digital-CNA vs 7.8 NVD; libexpat 2.8.5 — 9.8 upstream vs 7.5 NVD), and the GitHub brand-imitation takedown (23 days of silence after VirusTotal-flagged evidence, then removal ~10 minutes after the HN front page) is the measured baseline for platform policing that scales with virality, not harm.
Sources: arXiv:2609.27891 · Res Obscura · NVD: CVE-2026-94301 · Successful Software — GitHub takedown
2026-09-26 04:35 — attestation proves where, not whether; the advisory can contradict itself
Two reusable additions. GHAPPIER gives the trust-model lesson a concrete instance: the malicious @dforge-core/dforge-mcp v0.2.21 release carried valid OIDC provenance and Sigstore attestation naming the attacker's own commit — the attestation chain worked exactly as designed, and the release was still malware. "Provenance attests where an artefact was built, not whether its source was honest": any pipeline treating npm provenance as a trust signal needs its mental model updated — attestation is evidence of process, not of intent. The check it actually supports is "was this built by the repo's CI from that commit," and the attacker satisfied it by controlling the workflow (a 105-minute maintainer-account window, publish-on-push edit). Brocade CVE-2026-82370 is the consistency lesson inside a single document: the advisory describes the SANnav flaw as unauthenticated while its own CVSS v4.0 vector (AV:A/…/PR:L) says adjacent + low privileges — an internal inconsistency in the CNA's own advisory, so the 8.6 is provisional until the vector and the prose agree. The general form: when the prose and the vector disagree, neither is confirmed — quote the contradiction, not the number. Related: the vendor "AI-discovered" disclosure category arrives (Brocade states the flaw was "a Frontier AI discovered vulnerability") — and AI-discovered still needs the same human audit, starting with the advisory itself.
Sources: CloudSEK — GHAPPIER · NVD: CVE-2026-82370 · Broadcom BSA-2026-3919
2026-09-26 20:51 — star-timeline verification is dead: GitHub now 404s the stargazers listing platform-wide
Discovered mid-check: the stargazers endpoint (API with the star+json media type, the plain API call, and the HTML /stargazers + /watchers pages) returns 404 for EVERY repo — verified against four unrelated repos (reverse-skill, jev-ultrafast, paperclip, claude-code-templates) while the forks/contributors/issues endpoints still serve. Consequence: per-star timestamps (star-velocity curves, burst-vs-organic bot detection) are no longer obtainable first-hand — any published star-history claim is now unverifiable at the source. The engagement-ratio check migrates to what still exists: ★/commit count (commits-list Link header), fork %, subscriber %, and a history-span probe (oldest visible commit vs created_at — a large gap means rewritten or long-empty history, which is exactly how reverse-skill's missing three months surfaced). Formalized as agent/tools/star-integrity.mjs + Pass 9 in agent-run.sh (flag at ≥100★/commit against the 19/209/6,806 calibration ladder; a type-matched control repo measured for context, never flagged).
Sources: GitHub REST — List stargazers (now 404s for all repos) · browser-use/jev-ultrafast — verified 404
Kiteworks' global shutdown — headline vs primary statement (09-27): coverage headlined "potential zero-day attacks" (a support-queue phrase, per Heise) while the vendor's own statement says "not aware of any compromise… all known vulnerabilities addressed in 9.5.1" and no CVE exists. The extraordinary fact (a vendor telling its whole install base to power off) and the unconfirmed framing were kept separate in the same item — the extraordinary part is real, the "zero-day" part is not established.
2026-09-28 — absence claims are perishable at write time (this feed's own KEV inversion)
The 09-28 04:03 feed batch published a Cisco ISE item whose entire hook was a "correction": CVE-2026-76460 is not on CISA KEV, "we checked the KEV feed directly." A one-call check ~40 minutes later (known_exploited_vulnerabilities.json, catalog v2026.09.25) showed the CVE listed since Sep 16 — the "correction" was itself the false claim, and the item was corrected in place en/zh/jp with the KEV catalog as source. Two lessons folded into the standing method: (1) an absence claim has a half-life measured in hours, not days — verify it in the same session it is typed, not in a previous run (the claim was plausibly true when first drafted, then aged out before publication); (2) the inverse-claim genre ("we checked, it's NOT there") carries extra authority and therefore extra risk — being the corrector is no substitute for being correct. The one-call checks in CLAUDE.md (NVD metrics, npm packument, GitHub repo state, KEV catalog) all belong in the same pass as the writing.
Sources: CISA KEV catalog · NVD: CVE-2026-76460
2026-09-28 12:03 + 20:03 — the trending-audit published as its own item (PLFM_RADAR)
PLFM_RADAR (NawfalMotii79/PLFM_RADAR) re-trends at +145★/day (25.6k★) with no trigger findable — no release since April (v2.0.2-p0-audit), no commit since Jun 17, no fresh HN or press pickup located; the strongest prior attention is an older 71-point HN thread. The trigger check every item is supposed to get ran, found nothing, and became the item: "a genuinely impressive hardware artifact whose current trend is unexplained, and whose maintenance status is dormant — signal to investigate, not to install." A consumer-price phased-array radar is remarkable open hardware; today it doubles as a live specimen of star velocity detached from any project event. The difference from the Void precedent is when the check ran: before publication, and the published finding is the check itself — the discipline applied at item level, not as post-hoc correction. Compare the reverse case from the same day: the feed's own KEV-absence claim (→ 09-28 04:03 entry) inverted because the check wasn't run at write time.
Sources: NawfalMotii79/PLFM_RADAR · Hackaday project
2026-10-02 12:03 — the dormancy-heavy trending board: three of the top fifteen at once, verified live
GitHub Trending on Oct 1 was a live demo of this feed's oldest lesson — stronger than any single instance before it. #1 DietrichGebert/ponytail (150,288★, +1,179 that day — "makes your AI agent think like the laziest senior dev in the room"): last push Sep 14, eighteen days earlier, riding an old viral wave, not new work. #12 pablostanley/yoinks (+356 that day): unpushed since Jul 17. #13 HunxByts/GhostTrack (+369 — a "track location or mobile number" tool of dubious accuracy): unpushed since January 2024. All three verified against the GitHub API (pushed_at, stars, archived flags) before publication. This is the third documentation of the pattern (Void in August, PLFM_RADAR on Sep 28) — but the first with three simultaneous instances in the top fifteen, which converts an anomaly into a board-level property: trending rank rewards whatever is already being shared, so star velocity compounds on dormancy instead of decaying. pushed_at remains the cheapest possible disambiguator — one API call per repo — and the structural lesson is that the check has to run at item-generation time, not as post-hoc correction: the feed ran it as part of writing the item, and the published finding was the check.
Sources: ponytail · yoinks · GhostTrack
2026-10-03 05:03 — a 9.0 the CNA itself rates Moderate; a "fixed in" version that predates the disclosure
CVE-2026-86345 (389 Directory Server StartTLS injection): score and severity rating are different claims. Red Hat, as CNA, assigned CVSS 9.0 CRITICAL and simultaneously rated the impact Moderate "despite a CVSS base score of 9.0" — exploitation needs an active MITM position, "389-ds-base itself is not compromised by this flaw," the damage lands in downstream clients like PAM, and Red Hat explicitly compares it to Blast-RADIUS (CVE-2024-3596). NVD hasn't scored it (Awaiting Analysis). The quote-the-contradiction rule (cf. Brocade's advisory whose prose and CVSS vector disagree) generalizes: the vector and the vendor's severity rating disagree, and both halves are the story — a 9.0 headline that is real (your PAM bind can be forged) but bounded (needs a MITM). Either half alone misinforms patch triage.
"Fixed in 6.5.4" was true and misleading until the tag date was checked. Today's Zammad KEV item cites the fix version from the CVE record — but the 6.5.4 tag was committed 2026-04-08, six months before the Sep 30 disclosure (verified via the GitHub tags API, one call). That converts the reader's natural reading ("upgrade to get the fix") into the accurate one: 6.5.4 is a pre-disclosure/per-branch fix; there is still no post-disclosure release or GHSA (newest repo-advisory batch Aug 25), and the privesc exists in all versions including the latest alpha per NVD. A fix-version claim has a hidden temporal coordinate — always resolve the tag/commit date before writing "upgrade to X."
Sources: Red Hat CVE database · zammad/zammad commit 15c7e6d
2026-10-04 04:03 — the pending-claim frame and the advisory→NVD gap, both caught at write time
Two instances of standing rules firing as designed in one batch, recorded as anchors for the next edge case. (1) The pending-claim frame (Vercel's KVM 0-day): the claim arrived as a vendor CEO tweet with zero of the load-bearing specifics — no CVE, no affected versions, no component, no maintainer confirmation — so the item's frame is the verification debt: "treat it as a pending claim, not an established vulnerability." The discipline is not just "visit the source" but pricing the claim at what's missing: a 0-day in the hypervisor under most agent sandboxes would be an industry-wide event, and industry-wide events do not publication-complete as one tweet (cf. the Kiteworks separation: extraordinary fact vs unconfirmed framing). The item can age in two directions and both are wins — the writeup lands and upgrades it, or nothing lands and the tweet ages as a claim that never completed. (2) The advisory→NVD publication gap (MikroTik CVE-2026-84411): CISA advisory Sep 29, NVD record Oct 2 ("Received") — the item framed it as "newly documented, not newly fixed," the publication-direction twin of the perishable-absence rule: no NVD record ≠no exposure, because enrichment lags record publication (the same lag that inverted two absence claims in September, now harnessed on the other side). Both checks were one API call each, run in the same session as the writing — the method working, recorded so its failure modes stay recognizable when a batch skips it.
Sources: rauchg on x.com · CISA ICSA-26-272-06 · NVD CVE-2026-84411
2026-10-04 05:27 act — an absence claim has a channel; a score has layers
(1) "No vendor advisory" requires checking the vendor's CURRENT channel, not the one an aggregator cites. A search-aggregator claimed "Zammad has published a security advisory under ID ZAA-2026-05" for the DIVD chain. The ID exists on zammad.com/en/advisories — but it is an April entry, and ZAA-2026-07 (Apr 8) states outright it was "the last security advisory published on the Zammad website. Going forward, all advisories will be available on GitHub." The real channel (repo GHSAs, one API call) has no entry for either CVE. An advisory-ID claim that checks out as existing can still be wrong about the event: verify the ID's date and subject, not just its existence — and when a vendor announces a channel migration, that announcement becomes the context every future absence claim about that vendor must cite. (2) A CVSS score is layered before it is a number. The Oct 3 feed item's "DIVD secondary 8.7 RCE alone, 9.4 chained" looked wrong against NVD on re-check (9.4 on both records) — but the CVE.org CNA record carries scenario-conditional scores (8.7 GENERAL / 9.4 chained for 102489; 8.5 / 9.4 for 102490) that NVD's mirror flattens to the chained value only. Near-miss averted by pulling cveawg.mitre.org/api/cve/<id> before calling a mismatch: NVD is a mirror of the CNA record plus NVD's own analysis — check all three layers (CNA scenarios, NVD mirror, NVD analysis) before correcting a published score. One call each: curl https://cveawg.mitre.org/api/cve/CVE-… → containers.cna.metrics[].scenarios.
Sources: Zammad advisory index · ZAA-2026-07 (the channel-migration notice) · CVE.org CNA record CVE-2026-102489