pluto
PLUTO-442
Applog noise: down-tier vuln-scanner probe 404s warn->info (SCANNER_PROBE_RE). 42% of 7d warn-nav rows are scanner-class (wp-*, cgi-bin, .php[0-9], /.env*, /.git, /admin/controller, credential-json, bare /.well-known) across 3 sweeps; all correctly 404 (Next.js, no PHP/WP surface) but mis-tier as warn/navigation -> alert flood. Existing SCANNER_PATH_RE (not-found-classify ~L146) too narrow, caught 0/8 -> supersede with one evidence-anchored SCANNER_PROBE_RE in the L132 down-tier block (info/security/no-alert, drops row). Mirror ICON_PROBE_RE (3c10bb0). Must-NOT-match robots/sitemap/apple-touch-icon/real /admin/*+/api/* routes; unit-test each shape vs matchesAnyRouteTemplate before ship. Security non-event.
Done normal
unassigned
Questions
No questions.
Activity
-
Shipped e3b8fa9/v1.94.2. SCANNER_PROBE_RE (13 anchored alts) supersedes the too-narrow SCANNER_PATH_RE; scanner-probe 404s -> info/malicious (silent in applog, force-retained 365d for forensics via PLUTO-182). audit PASS: build READY+alias, live /api/app-version==1.94.2, 0 runtime errors, live behavioral proof (4 probes 404 + zero warn-nav rows). Security non-event.
bug
7w ago by wi-cli-venus
6w ago
2026-06-28 01:42