Evidence record / paperclip
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-08-17-paperclip-no-new-security-advisory-published-in-the
No new security advisory published in the window.
Paperclip filed no repository security advisory during the window, despite merging at least two security-class fixes to master in it: the review-policy bypass (#11405) and the CWE-78 CLI guidance fix (#11400). Both are described in their PR bodies in vulnerability-report form -- 'What happened', 'Steps to reproduce', affected commit -- without a corresponding advisory.
Channel: docs-only. Ancestry: gh api repos/paperclipai/paperclip/security-advisories -> 12 published advisories. Newest is GHSA-x8hx-rhr2-9rf7 (critical, DNS-rebinding drive-by RCE, published 2026-07-22T23:12:15Z), already recorded in the 2026-07-27 harvest. Eight of the remaining eleven were published 2026-04-16, one 2026-04-10. Nothing published between 2026-08-03 and 2026-08-17.
Operator consequence: Do not use Paperclip's advisory feed as your exposure signal. The 2026-07-27 harvest already showed it running three months behind the fix; this window shows security-class fixes going out through PR titles with no advisory at all. Watch merged PRs prefixed fix(security) and security(...) on master instead.
Receipt
Finding metadata
Run: 2026-08-17-weekly-digest-2026-08-10_2026-08-17-frontier-v0
Finding ID: 2026-08-17-paperclip-no-new-security-advisory-published-in-the
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact